<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Security Advisories on CIRCL</title>
		<link>https://www.circl.lu/advisory/</link>
		<description>Recent content in Security Advisories on CIRCL</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
		
			<atom:link href="https://www.circl.lu/advisory/rss.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>CVE-2015-1035 - Vulnerability in HRIS software (HRMS product) - Reflective XSS</title>
				<link>https://www.circl.lu/advisory/CVE-2015-1035/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/advisory/CVE-2015-1035/</guid>
				<description>&lt;h2 id=&#34;reflective-cross-site-scripting-in-hris-software-hrms-product&#34;&gt;Reflective Cross Site Scripting in HRIS software (HRMS product)&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the HRIS software (HRMS product) leads to a reflective cross site scripting.&lt;/p&gt;&#xA;&lt;h2 id=&#34;details-about-vulnerability&#34;&gt;Details about vulnerability&lt;/h2&gt;&#xA;&lt;p&gt;There is an improper neutralization of input during web page generation in the F_NavForm parameter.&lt;/p&gt;&#xA;&lt;h2 id=&#34;version-vulnerable&#34;&gt;Version vulnerable&lt;/h2&gt;&#xA;&lt;p&gt;Versions belows 4.17 are vulnerable. This vulnerability is fixed in version 4.17.&lt;/p&gt;&#xA;&lt;h2 id=&#34;fixes&#34;&gt;Fixes&lt;/h2&gt;&#xA;&lt;p&gt;We are not aware of any fixes. The vendor was contacted the 9th January 2015 for more information.&lt;/p&gt;</description>
			</item>
			<item>
				<title>CVE-2015-1036 - Vulnerability in HRIS software (HRMS product) - SQL injection (as an authenticated user)</title>
				<link>https://www.circl.lu/advisory/CVE-2015-1036/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/advisory/CVE-2015-1036/</guid>
				<description>&lt;h2 id=&#34;improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection&#34;&gt;Improper Neutralization of Special Elements used in an SQL Command (&amp;lsquo;SQL Injection&amp;rsquo;)&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the HRIS software (HRMS product) leads to an SQL injection, if the user is authenticated.&lt;/p&gt;&#xA;&lt;h2 id=&#34;details-about-vulnerability&#34;&gt;Details about vulnerability&lt;/h2&gt;&#xA;&lt;p&gt;Input elements used by /WrkFlw.aspx are not neutralized or incorrectly neutralizes the input that can sent unwanted SQL commands to the downstream component.&lt;/p&gt;&#xA;&lt;h2 id=&#34;version-vulnerable&#34;&gt;Version vulnerable&lt;/h2&gt;&#xA;&lt;p&gt;Versions belows 4.17 are vulnerable. This vulnerability is fixed in version 4.17.&lt;/p&gt;</description>
			</item>
			<item>
				<title>CVE-2015-4099 - SysAid &#34;Service Desk&#34; - Improper Neutralization of Special Elements in Output Used by a Downstream Component (&#39;Injection&#39;)</title>
				<link>https://www.circl.lu/advisory/CVE-2015-4099/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/advisory/CVE-2015-4099/</guid>
				<description>&lt;h2 id=&#34;improper-neutralization-of-special-elements-in-output-used-by-a-downstream-component-injection&#34;&gt;Improper Neutralization of Special Elements in Output Used by a Downstream Component (&amp;lsquo;Injection&amp;rsquo;)&lt;/h2&gt;&#xA;&lt;p&gt;SysAid &amp;ldquo;Service Desk&amp;rdquo; can be instrumented to gain access to the underlying database, which usually means accessing the MSSQL server with the&#xA;Administrator account (&amp;lsquo;sa&amp;rsquo;).&lt;/p&gt;&#xA;&lt;h2 id=&#34;details-about-vulnerability&#34;&gt;Details about vulnerability&lt;/h2&gt;&#xA;&lt;p&gt;The &amp;ldquo;dir&amp;rdquo; parameter while posting to &amp;ldquo;/EndUserActions.jsp&amp;rdquo; is prone to a blind SQL injection.&lt;/p&gt;&#xA;&lt;h2 id=&#34;version-vulnerable&#34;&gt;Version vulnerable&lt;/h2&gt;&#xA;&lt;p&gt;SysAid &amp;ldquo;Service Desk&amp;rdquo; cloud versions prior to 15.1.70 are affected by this vulnerability.&#xA;SysAid &amp;ldquo;Service Desk&amp;rdquo; on-premise versions prior to 15.2 are affected by this vulnerability.&lt;/p&gt;</description>
			</item>
			<item>
				<title>CVE-2015-5719 - Vulnerability in MISP - Incorrect validation of temporary filenames</title>
				<link>https://www.circl.lu/advisory/CVE-2015-5719/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/advisory/CVE-2015-5719/</guid>
				<description>&lt;h2 id=&#34;incorrect-validation-of-temporary-filenames&#34;&gt;Incorrect validation of temporary filenames&lt;/h2&gt;&#xA;&lt;p&gt;A bug in MISP introduces an unsafe temporary file creation vulnerability.&lt;/p&gt;&#xA;&lt;h2 id=&#34;fixes&#34;&gt;Fixes&lt;/h2&gt;&#xA;&lt;p&gt;MISP versions below 2.3.92 are vulnerable. This vulnerability is &lt;a href=&#34;https://github.com/MISP/MISP/commit/27cc167c3355ec76292235d7f5f4e0016bfd7699&#34;&gt;fixed in version 2.3.92&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;cve&#34;&gt;CVE&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2015-5719&lt;/p&gt;&#xA;&lt;h2 id=&#34;acknowledgement&#34;&gt;Acknowledgement&lt;/h2&gt;&#xA;&lt;p&gt;CIRCL would like to thank the reporter (Davy Stoffel from Conostix) for his security review.&lt;/p&gt;&#xA;&lt;h2 id=&#34;classification-of-this-document&#34;&gt;Classification of this document&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.circl.lu/pub/traffic-light-protocol/&#34;&gt;TLP:CLEAR&lt;/a&gt; information may be distributed without restriction, subject to copyright controls.&lt;/p&gt;&#xA;&lt;h2 id=&#34;revision&#34;&gt;Revision&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Version 1.0 - TLP:CLEAR - First version (20150804)&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>CVE-2015-5720 - Vulnerability in MISP - XSS in template creation</title>
				<link>https://www.circl.lu/advisory/CVE-2015-5720/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/advisory/CVE-2015-5720/</guid>
				<description>&lt;h2 id=&#34;incorrect-validation-of-temporary-filenames&#34;&gt;Incorrect validation of temporary filenames&lt;/h2&gt;&#xA;&lt;p&gt;A bug in MISP introduces a potential XSS (Cross-site scripting) in the template creation.&lt;/p&gt;&#xA;&lt;h2 id=&#34;fixes&#34;&gt;Fixes&lt;/h2&gt;&#xA;&lt;p&gt;MISP versions below 2.3.90 are vulnerable. This vulnerability is &lt;a href=&#34;https://github.com/MISP/MISP/commit/812ac878c3645c02e2a599287117418424cbd4cf&#34;&gt;fixed in version 2.3.90&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;cve&#34;&gt;CVE&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2015-5720&lt;/p&gt;&#xA;&lt;h2 id=&#34;acknowledgement&#34;&gt;Acknowledgement&lt;/h2&gt;&#xA;&lt;p&gt;CIRCL would like to thank the reporter (Davy Stoffel from Conostix) for his security review.&lt;/p&gt;&#xA;&lt;h2 id=&#34;classification-of-this-document&#34;&gt;Classification of this document&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.circl.lu/pub/traffic-light-protocol/&#34;&gt;TLP:CLEAR&lt;/a&gt; information may be distributed without restriction, subject to copyright controls.&lt;/p&gt;&#xA;&lt;h2 id=&#34;revision&#34;&gt;Revision&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Version 1.0 - TLP:CLEAR - First version (20150804)&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>CVE-2015-5721 - Vulnerability in MISP - potential PHP Object injection vulnerability</title>
				<link>https://www.circl.lu/advisory/CVE-2015-5721/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/advisory/CVE-2015-5721/</guid>
				<description>&lt;h2 id=&#34;incorrect-validation-of-temporary-filenames&#34;&gt;Incorrect validation of temporary filenames&lt;/h2&gt;&#xA;&lt;p&gt;A bug in MISP introduces a potential PHP Object injection vulnerability from a user input.&lt;/p&gt;&#xA;&lt;h2 id=&#34;fixes&#34;&gt;Fixes&lt;/h2&gt;&#xA;&lt;p&gt;MISP versions below 2.3.90 are vulnerable. This vulnerability is &lt;a href=&#34;https://github.com/MISP/MISP/commit/415d85102d5aa5f96f4f11a17c86b59bb9cc0d56&#34;&gt;fixed in version 2.3.90&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;cve&#34;&gt;CVE&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2015-5721&lt;/p&gt;&#xA;&lt;h2 id=&#34;acknowledgement&#34;&gt;Acknowledgement&lt;/h2&gt;&#xA;&lt;p&gt;CIRCL would like to thank the reporter (Davy Stoffel from Conostix) for his security review.&lt;/p&gt;&#xA;&lt;h2 id=&#34;classification-of-this-document&#34;&gt;Classification of this document&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.circl.lu/pub/traffic-light-protocol/&#34;&gt;TLP:CLEAR&lt;/a&gt; information may be distributed without restriction, subject to copyright controls.&lt;/p&gt;&#xA;&lt;h2 id=&#34;revision&#34;&gt;Revision&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Version 1.0 - TLP:CLEAR - First version (20150804)&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>CVE-2017-13671 - Vulnerability in MISP and Threat Sharing - potential persistent cross site scripting vulnerability in the comments</title>
				<link>https://www.circl.lu/advisory/CVE-2017-13671/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/advisory/CVE-2017-13671/</guid>
				<description>&lt;h2 id=&#34;cross-site-scripting-vulnerability-in-the-comments&#34;&gt;Cross site scripting vulnerability in the comments&lt;/h2&gt;&#xA;&lt;p&gt;In MISP 2.4.78 (and below), a MISP user having access to a MISP instance can inject JavaScript in a comment field, aka XSS.&lt;/p&gt;&#xA;&lt;p&gt;The comment field is not part of the MISP synchronisation and only impacts the users of the same instance.&lt;/p&gt;&#xA;&lt;h2 id=&#34;fixes&#34;&gt;Fixes&lt;/h2&gt;&#xA;&lt;p&gt;MISP versions below 2.4.79 are vulnerable. This vulnerability is &lt;a href=&#34;https://github.com/MISP/MISP/commit/6eba658d4a648b41b357025d864c19a67412b8aa&#34;&gt;fixed in version 2.4.79&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;cve&#34;&gt;CVE&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://cve.circl.lu/cve/CVE-2017-13671&#34;&gt;CVE-2017-13671&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;acknowledgement&#34;&gt;Acknowledgement&lt;/h2&gt;&#xA;&lt;p&gt;CIRCL would like to thank the reporters Jurgen Jans and Cedric Van Bockhaven from Deloitte.&lt;/p&gt;</description>
			</item>
			<item>
				<title>CVE-2017-14337 - Vulnerability in MISP and Threat Sharing - Vulnerability in CertAuth module when used with external user management API</title>
				<link>https://www.circl.lu/advisory/CVE-2017-14337/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www.circl.lu/advisory/CVE-2017-14337/</guid>
				<description>&lt;h2 id=&#34;vulnerability-in-certauth-module-when-used-with-external-user-management-api&#34;&gt;Vulnerability in CertAuth module when used with external user management API&lt;/h2&gt;&#xA;&lt;p&gt;When MISP is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST&#xA;API, if an external user provides X.509 certificate authentication and this API returns an empty value, the unauthenticated&#xA;user can be granted access as an arbitrary user.&lt;/p&gt;&#xA;&lt;h2 id=&#34;impact&#34;&gt;Impact&lt;/h2&gt;&#xA;&lt;p&gt;The impact of this vulnerability is very low as the vulnerability highly depends of the external user-management used in conjunction with the X.509 certificate authentication.&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
