top of page
  • White Facebook Icon
  • White Twitter Icon
  • White Instagram Icon
  • White YouTube Icon

CVE-2020-2655 – JSSE Unauthenticated Attack via HTTPS on Java SE

vamenrotekapack


This Critical Patch Update contains 12 new security patches for the Oracle Database Server. 3 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. None of these patches are applicable to client-only installations, i.e., installations that do not have the Oracle Database Server installed. The English text form of this Risk Matrix can be found here.




CVE-2020-2655 – JSSE Client Authentication Bypass




This Critical Patch Update contains 50 new security patches for Oracle Enterprise Manager. 10 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. None of these patches are applicable to client-only installations, i.e., installations that do not have Oracle Enterprise Manager installed. The English text form of this Risk Matrix can be found here.


An intresting mix of issues from crypto (Psychic Signatures), to a bad vulnerability patching service (patching log4shell), and bad logic leading to authentication bypassing and leaking sensitive keys.


Some easy vulnerabilities this week, a directory traversal due to a bad regex, a simply yet somewhat mysterious authentication bypass, arbitrary file read in GitLab thanks to archives with symlinks, and a PHP filter_var bypass.


2ff7e9595c


 
 
 

Recent Posts

See All

Comments


With all the latest concerts and events. Sign up to get our newsletter

STAY UP TO DATE

LIVE LOCAL MUSIC, FOOD & DRINKS ©2023 BY THE LAUNCH. PROUDLY CREATED WITH WIX.COM

bottom of page