Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-28803PUBLISHED: 2022-06-29In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR).
CVE-2022-29269PUBLISHED: 2022-06-29In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
CVE-2022-29270PUBLISHED: 2022-06-29In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
CVE-2022-29271PUBLISHED: 2022-06-29In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.
CVE-2022-29272PUBLISHED: 2022-06-29In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
User Rank: Ninja
12/17/2012 | 3:11:19 PM
I
am pretty sure that monitoring and logging are out into place for
this particular reason right here. They are studied and learned from
in the event to better protect themselves f or a future attack. It is
to bad that these logs are usually not used unless an incident occurs
that requires them to see what happened. With a 7 billion dollar hit
someone is going to be very upset and looking for measure so it does
not happen again.
Paul
Sprague
InformationWeek
Contributor
-á