AI
AI

April Patch Tuesday Update: Exploited Windows Zero-Day and Major Vulnerability Found in Two SAP Applications

Photo credit: www.csoonline.com

The security landscape remains a pivotal concern for organizations as they navigate potential threats. In a recent assessment, experts highlighted that the necessary privileges for exploitation are categorized as Low, indicating that a standard account login is sufficient for attackers to initiate an injection attack. This method potentially allows for significant compromises following a successful account takeover.

CISOs are particularly urged to review SAP Security Note #3572688, which has been assigned a critical CVSS score of 9.8. This note addresses a serious authentication bypass vulnerability found in SAP Financial Consolidation. Because of deficiencies in the authentication framework, unauthorized users could exploit this flaw to assume the Admin account, posing severe risks to the application’s confidentiality, integrity, and availability.

Google Android Fixes

In a related development, Malwarebytes has reported that Google has addressed a total of 62 vulnerabilities in its Android operating systems, specifically versions 13, 14, and 15. Device manufacturers were informed of these issues at least a month in advance to ensure timely rollout of updates to their users. Notably, among the vulnerabilities patched are two that have been actively exploited by cyber adversaries.

Source
www.csoonline.com

Related by category

Cybersecurity Leaders Condemn ‘Political Persecution’ of Chris Krebs in Letter to the President

Photo credit: www.csoonline.com In November 2018, President Trump appointed Chris...

Broadcom-Supported SAN Devices Vulnerable to Code Injection Attacks Due to Critical Fabric OS Flaw

Photo credit: www.csoonline.com Critical Vulnerability Found in Broadcom’s Brocade Fabric...

Cyberattack on berlin.de | CSO Online

Photo credit: www.csoonline.com Cyberangriff auf Berlins Info- und Serviceportal berlin.de Ende...

Latest news

Firefly’s Rocket Experiences One of the Most Unusual Launch Failures in History

Photo credit: arstechnica.com Firefly Aerospace's Alpha Rocket: Navigating a Niche...

Saskatchewan Students Experience Hands-On Automotive Training

Photo credit: globalnews.ca On Tuesday, April 29th, the Saskatchewan Distance...

NASA Assembles Specialists to Explore Advancements in Astrophysics Technologies

Photo credit: www.nasa.gov The Future of Astrophysics: Harnessing Emerging Technologies The...

Breaking news