Hotfixes are available for both a hardcoded credential flaw and a deserialization remote code execution flaw in SolarWinds Web Help Desk.
Ivanti has fixed a critical-severity flaw in its Virtual Traffic Manager (vTM), which if exploited could enable attackers to bypass authentication and create a user with administrator privileges.
The most severe flaw stems from password requirements not being checked in some features of SAP’s NetWeaver Java User Management Engine.
At the time of disclosure, Ivanti said it is not currently aware of the flaw being exploited.
QNAP is warning of three new vulnerabilities in QTS, QuTS hero, QuTScloud and myQNAPcloud.