The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently added two security flaws to its Known Exploited Vulnerabilities Catalog, as evidence of active exploitation has been found. The first of these is CVE-2022-21587, a critical issue that affects Oracle Web Applications Desktop Integrator versions 12.2.3 to 12.2.11. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Oracle addressed this issue in October 2022 as part of its Critical Patch Update. The second vulnerability is CVE-2023-22952, which is related to a missing input validation in SugarCRM that could lead to the injection of arbitrary PHP code. This bug has been fixed in SugarCRM versions 11.0.5 and 12.0.2. Last week, CISA also added CVE-2017-11357, a severe security vulnerability in Telerik UI that could enable arbitrary file uploads or remote code execution. Federal Civilian Executive Branch agencies in the U.S. must apply the patches by February 23, 2023 due to the active exploitation attempts.
This Cyber News was published on thehackernews.com. Publication date: Fri, 03 Feb 2023 07:35:02 +0000