[FD] [SYSS-2019-039] Smartbear ReadyAPI/SoapUI Pro/jProductivity Licensing Unsafe Deserialization

2020-05-19 Thread Moritz Bechler
Level: High Solution Status: Open Manufacturer Notification: 2019-09-02 Public Disclosure: 2020-05-18 CVE Reference: CVE-2020-12835 Author of Advisory: Moritz Bechler, SySS GmbH Overview: jProductivity Protection

[FD] [SYSS-2021-061] Oracle Database - NNE Connection Hijacking

2021-12-10 Thread Moritz Bechler
Solution Status: Fixed Manufacturer Notification: 2021-03-17 Solution Date: 2021-08-07 Public Disclosure: 2021-12-10 CVE Reference: CVE-2021-2351 Author of Advisory:Moritz Bechler, SySS GmbH

[FD] [SYSS-2021-062] Oracle Database - Weak NNE Integrity Key Derivation

2021-12-10 Thread Moritz Bechler
Solution Status: Fixed Manufacturer Notification: 2021-03-17 Solution Date: 2021-08-07 Public Disclosure: 2021-12-10 CVE Reference: CVE-2021-2351 Author of Advisory:Moritz Bechler, SySS GmbH

[FD] [SYSS-2022-041] Remote Code Execution due to unsafe JMX default configuration in JasperReports Server

2022-09-12 Thread Moritz Bechler
Status: Fixed Manufacturer Notification: 2022-06-10 Solution Date: 2022-08-10 Public Disclosure: 2022-09-09 CVE Reference: None assigned Author of Advisory:Moritz Bechler, SySS GmbH