[FD] [Onapsis Security Advisory 2014-020] SAP SLD Information Tampering

2014-06-06 Thread Onapsis Research Labs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Onapsis Security Advisory 2014-020: SAP SLD Information Tampering 1. Impact on Business = By exploiting this vulnerability, a remote unauthenticated attacker might be able to modify technical information about the SAP

[FD] [Onapsis Security Advisories] Multiple Hard-coded Usernames in SAP Components

2014-06-06 Thread Onapsis Research Labs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Onapsis Security Advisories:Multiple Hard-coded Usernames (CWE-798) have been found and patched in a variety of SAP components. Summaries of the advisories with links to full versions follow: 1. ONAPSIS-2014-011-SAP Project System Structures and Proje

[FD] SEC Consult SA-20140606-0 :: Multiple critical vulnerabilities in WebTitan

2014-06-06 Thread SEC Consult Vulnerability Lab
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SEC Consult Vulnerability Lab Security Advisory < 20140606-0 > === title: Multiple critical vulnerabilities product: WebTitan vulnerable version

Re: [FD] More OpenSSL issues

2014-06-06 Thread P Vixie
This does not appear to be the same panic level as the previous patch. In other words the previous openssl vuln was worse than the instability of all-night patching. This one is not. Take time to roll out right. On June 5, 2014 7:51:50 AM PDT, Jordan Urie wrote: >Ladies and Gentlemen, > >https: