<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:18:27.135282+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0010</id>
    <title>certfr-2024-avi-0010 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-02T23:18:27.189229+00:00</updated>
    <content>certfr-2024-avi-0010</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2017-36700</id>
    <title>cnvd-2017-36700</title>
    <updated>2026-10-02T23:18:27.189268+00:00</updated>
    <content>cnvd-2017-36700</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2017-36700"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-182717</id>
    <title>EUVD-2026-182717</title>
    <updated>2026-10-02T23:18:27.189284+00:00</updated>
    <content>EUVD-2026-182717</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-182717"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-15708</id>
    <title>fkie_cve-2017-15708</title>
    <updated>2026-10-02T23:18:27.189296+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects. And the presence of Apache Commons Collections 3.2.1 (commons-collections-3.2.1.jar) or previous versions in Synapse distribution makes this exploitable. To mitigate the issue, we need to limit RMI access to trusted users only. Further upgrading to 3.0.1 version will eliminate the risk of having said Commons Collection version. In Synapse 3.0.1, Commons Collection has been updated to 3.2.2 version.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-15708"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p694-23q3-rvrc</id>
    <title>GHSA-p694-23q3-rvrc — Remote Code Execution in Apache Synapse</title>
    <updated>2026-10-02T23:18:27.189325+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.synapse:synapse-core</p>
<p>In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects. And the presence of Apache Commons Collections 3.2.1 (commons-collections-3.2.1.jar) or previous versions in Synapse distribution makes this exploitable. To mitigate the issue, we need to limit RMI access to trusted users only. Further upgrading to 3.0.1 version will eliminate the risk of having said Commons Collection version. In Synapse 3.0.1, Commons Collection has been updated to 3.2.2 version.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p694-23q3-rvrc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-15708</id>
    <title>gsd-2017-15708</title>
    <updated>2026-10-02T23:18:27.189350+00:00</updated>
    <content>gsd-2017-15708</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-15708"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2017-15708</id>
    <title>msrc_CVE-2017-15708 — In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse…</title>
    <updated>2026-10-02T23:18:27.189361+00:00</updated>
    <content>msrc_CVE-2017-15708</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2017-15708"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1738</id>
    <title>WID-SEC-W-2022-1738 — IBM InfoSphere Information Server: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:18:27.189378+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM InfoSphere Information Server ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1738"/>
  </entry>
</feed>
