NVD disclosure day

Published threat advisories for June 3, 2019

CVE advisoryCRITICAL

CVE-2017-14851

Orpak SiteOmat SQL Injection Authentication Bypass.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability affects Orpak SiteOmat, allowing authentication bypass through its login page. This creates a risk of unauthorized access to systems, potentially impacting data confidentiality and integrity. The business risk centers on compromised system access and data security.

CVE advisoryCRITICAL

CVE-2017-14728

SiteOmat Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability in SiteOmat software allows unauthorized access to systems, potentially exposing operational data and disrupting business processes. This presents a significant business risk due to the potential for data compromise and system disruption.

CVE advisoryKnown Exploit

CVE-2019-11580

Atlassian Crowd Allows Remote Code Execution Via Plugin Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Atlassian Crowd and Crowd Data Center are affected by a vulnerability allowing arbitrary plugin installation and remote code execution. This poses a business risk by potentially compromising systems, data, and operations. Organizations should apply vendor-provided updates.

• CISA KEV