Ivanti has fixed a critical-severity flaw in its Virtual Traffic Manager (vTM), which if exploited could enable attackers to bypass authentication and create a user with administrator privileges.
The most severe flaw stems from password requirements not being checked in some features of SAP’s NetWeaver Java User Management Engine.
At the time of disclosure, Ivanti said it is not currently aware of the flaw being exploited.
QNAP is warning of three new vulnerabilities in QTS, QuTS hero, QuTScloud and myQNAPcloud.
The flaws, which exist in all TeamCity on-premises versions through 2023.11.3, have been fixed in version 2023.11.4.