Vulnerabilities & PatchesEmerging1 src
Issue 177: Vulnerabilities in Veeam product, RCE in Parse Server module, insecure API threat to mobile apps
This week, we have news of two critical vulnerabilities patched in the Veeam data backup solution, a remote code execution (RCE) vulnerability in the popular Parse Server API server module, views on how insecure APIs threaten mobile application security, and how attackers are increasingly focusing on APIs as the attack vector of choice.
Vulnerability: Two critical vulnerabilities in Veeam data backup solution
Veeam recently announced two critical vulnerabilities in their Backup and Replication product for backups of virtual environments. The vulnerabilities are tracked as CVE-2022-26500 and CVE-2022-26501, both with a CVSS score of 9. 8, and could allow an attacker to remotely execute code. All versions of their product are affected but patches have already been released for versions 10 and 11.
Users on version 9 are advised to upgrade to a supported version.