Information disclosure in urllib3 - CVE-2023-45803
Published: November 10, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to urllib3 does not remove the HTTP request body when redirecting HTTP response using status codes 301, 302, or 303, after the request had its method changed from one that could accept a request body (e.g. from POST to GET). A remote attacker can gain access to potentially sensitive information.
Affected software
IBM AIX
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Workstation Extension 12
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
IBM VIOS
IBM Cloud Pak for Data System
IBM Concert Software
Migration Toolkit for Runtimes
Service Telemetry Framework
Cryostat
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Splunk User Behavior Analytics (UBA)
IBM Observability with Instana
Multicluster GlobalHub
IBM Process Mining
IBM MQ Operator
IBM Spectrum Conductor
IBM Cloud Object Storage Systems
Splunk Add-on for Google Cloud Platform
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Connect:Direct Web Services
IBM Spectrum Symphony
IBM Maximo Application Suite
IBM Workload Scheduler
IBM Spectrum Protect Plus
Dell NetWorker Virtual Edition
IBM Robotic Process Automation
IBM Cloud Pak for Business Automation
Migration Toolkit for Containers
QRadar Suite
Juniper Secure Analytics (JSA)
Splunk Enterprise
Intel In-Band Manageability
IBM Security Verify Access
Juniper Junos Space
Dell EMC PowerProtect Data Protection
Guardium Data Security Center (GDSC)
SmartFabric OS10
Business Automation Insights
IBM Application Suite - IBM Asset Data Dictionary Component
Storage Sentinel Anomaly Scan Engine
ObjectScale
QRadar Deployment Intelligence App
OpenManage Network Integration (OMNI)
EMC ECS
Security QRadar EDR
Platform Automation Toolkit
Storage Resource Manager
SOAR QRadar Plugin App
Storage Ceph
IBM QRadar Incident Forensics
Maximo Application Suite - IoT Component
Maximo Application Suite - Predict Component
IBM supplied MQ Advanced container images
IBM Netezza for Cloud Pak for Data
NetWorker Management Console (NMC)
Robotic Process Automation for Cloud Pak
Python for Scientific Computing
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
python3-urllib3 (Ubuntu package)
python-urllib3 (Ubuntu package)
python3-pip (Ubuntu package)
python-pip (Ubuntu package)
python-pip-whl (Ubuntu package)
toolbox
toolbox-tests
udica
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo
skopeo-tests
python-urllib3
python-urllib3 (Red Hat package)
python3-urllib3
python2-urllib3
python3.11-urllib3 (Red Hat package)
python3.11-urllib3
python3-urllib3-doc
buildah
buildah-tests
containers-common
conmon
container-selinux
criu-libs
criu-devel
criu
crit
python3-criu
fence-agents (Red Hat package)
libslirp
libslirp-devel
python3-podman
resource-agents-gcp
resource-agents-aliyun
resource-agents-paf
resource-agents
resource-agents (Red Hat package)
podman-tests
podman-remote
podman-plugins
podman-gvproxy
podman-catatonit
podman
podman-docker
fence-agents-rhevm
fence-agents-kdump
fence-agents-all
fence-agents-lpar
fence-agents-kubevirt
fence-agents-scsi
fence-agents-sbd
fence-virtd-cpg
fence-agents-mpath
fence-agents-aws
fence-agents-rsa
fence-agents-rsb
fence-agents-redfish
fence-virtd
fence-virt
fence-agents-aliyun
fence-agents-gce
fence-agents-azure-arm
fence-agents-heuristics-ping
fence-agents-intelmodular
fence-virtd-libvirt
fence-agents-wti
fence-agents-cisco-mds
fence-agents-cisco-ucs
fence-agents-common
fence-agents-drac5
fence-agents-eaton-snmp
fence-agents-emerson
fence-agents-eps
fence-agents-vmware-soap
fence-agents-hpblade
fence-agents-ilo2
fence-agents-ibm-powervs
fence-agents-ibm-vpc
fence-agents-ibmblade
fence-agents-ifmib
fence-agents-ilo-moonshot
fence-agents-ilo-mp
fence-agents-ilo-ssh
fence-agents-vmware-rest
fence-virtd-multicast
fence-virtd-serial
fence-virtd-tcp
ha-cloud-support
fence-agents-amt-ws
fence-agents-virsh
fence-agents-brocade
fence-agents-apc
fence-agents-ipmilan
fence-agents-ipdu
fence-agents-apc-snmp
fence-agents-bladecenter
python3-pip
python2-pip
python-pip-wheel
python-pip-help
python-pip
python3-pip-whl (Ubuntu package)
cockpit-podman
IBM Integrated Analytics System
Red Hat OpenShift GitOps
Dell EMC Storage Monitoring and Reporting (SMR)
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Spectrum Scale
Dell EMC VxRail Appliance
How to mitigate CVE-2023-45803
IBM Cloud Pak for Data System - update to 1.0.9.0
IBM Concert Software - update to 1.0.5
Migration Toolkit for Runtimes - update to 1.2.5
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
QRadar Suite - update to 1.10.18.0
Intel In-Band Manageability - update to 4.2.0
Dell EMC PowerProtect Data Protection - update to 2.7.8
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.5, 2.9.3
Guardium Data Security Center (GDSC) - update to 3.6.1
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.1.6, 4.2.4
Python for Scientific Computing - update to 4.2.1
Splunk User Behavior Analytics (UBA) - update to 5.4.2
IBM Qradar SIEM - addressed in versions 7.5.0 Update Pack 8 IF01, 7.5.0 Update Pack 9 IF01, 7.5.0 Update Pack 10
Juniper Secure Analytics (JSA) - addressed in versions 7.5.0 UP8 IF03, 7.5.0 UP9 IF02
Splunk Enterprise - addressed in versions 9.0.9, 9.1.4, 9.1.6, 9.2.1, 9.2.3, 9.3.1
SmartFabric OS10 - addressed in versions 10.5.4.11, 10.5.6.1
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Observability with Instana - update to 279
python3-urllib3 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.25.8-2ubuntu0.3, 1.26.5-1~exp1ubuntu0.1, 1.26.12-1ubuntu0.1, 1.26.16-1ubuntu0.1
python-urllib3 (Ubuntu package) - update to Ubuntu Pro
python3-pip (Ubuntu package) - addressed in versions Ubuntu Pro, 20.0.2-5ubuntu1.10, 22.0.2+dfsg-1ubuntu0.4, 23.0.1+dfsg-1ubuntu0.2, 23.2+dfsg-1ubuntu0.1
python-pip (Ubuntu package) - addressed in versions Ubuntu Pro, 22.0.2+dfsg-1ubuntu0.7, 24.0+dfsg-1ubuntu1.3, 25.0+dfsg-1ubuntu0.2
python-pip-whl (Ubuntu package) - addressed in versions Ubuntu Pro, 20.0.2-5ubuntu1.10
toolbox - update to 0.0.99.5-2.0.1
toolbox-tests - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
Multicluster GlobalHub - update to 1.0.2
IBM Integrated Analytics System - update to 1.0.30.0
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.6
Storage Sentinel Anomaly Scan Engine - update to 1.1.6
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
ObjectScale - update to 1.4.0
containernetworking-plugins - update to 1.4.0-2.0.1
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.11
aardvark-dns - update to 1.10.0-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
IBM Process Mining - update to 1.14.3
crun - update to 1.14.3-2
skopeo - update to 1.14.3-2.0.1
skopeo-tests - update to 1.14.3-2.0.1
python-urllib3 - addressed in versions 1.23-3.25.1, 1.25.10-3.37.1, 1.25.10-5.25.1
python-urllib3 (Red Hat package) - addressed in versions 1.24.2-5.el8_6.1, 1.24.2-5.el8_8.1, 1.25.10-6.el8ost
python3-urllib3 - addressed in versions 1.24.2-7, 1.26.18-1
python2-urllib3 - update to 1.25.9-10
python3-urllib3 - update to 1.25.9-10
python-urllib3 - update to 1.25.9-10
python3-urllib3 - addressed in versions 1.25.10-3.37.1, 1.25.10-150300.4.9.1
python3.11-urllib3 (Red Hat package) - addressed in versions 1.26.12-1.el8_8.2, 1.26.12-2.el9_5.2, 1.26.12-5.el8_10
python3.11-urllib3 (Red Hat package) - addressed in versions 1.26.12-1.el9_2.1, 1.26.12-2.el9_4.2
python3.11-urllib3 - update to 1.26.12-5
python3-urllib3-doc - update to 1.26.18-1
python-urllib3 - addressed in versions 1.26.18-1.fc37, 1.26.18-1.fc38, 1.26.18-1.fc39
buildah - update to 1.33.7-1
buildah-tests - update to 1.33.7-1
containers-common - update to 1-81.0.1
IBM MQ Operator - addressed in versions 2.0.18, 2.4.7, 3.0.1
conmon - update to 2.1.10-1
IBM Spectrum Conductor - update to 2.5.1 Fix 601861
container-selinux - update to 2.229.0-2
QRadar Deployment Intelligence App - update to 3.0.16
OpenManage Network Integration (OMNI) - update to 3.7
EMC ECS - update to 3.8.0.6
Security QRadar EDR - update to 3.12.8
IBM Cloud Object Storage Systems - update to 3.17.5.100
criu-libs - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
fence-agents (Red Hat package) - addressed in versions 4.2.1-129.el8, 4.10.0-20.el9_0.11, 4.10.0-62.el9
Splunk Add-on for Google Cloud Platform - update to 4.3.0
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
Platform Automation Toolkit - addressed in versions 4.4.19, 5.0.13
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.4
python3-podman - update to 4.9.0-1
resource-agents-gcp - update to 4.9.0-54
resource-agents-aliyun - update to 4.9.0-54
resource-agents-paf - update to 4.9.0-54
resource-agents - update to 4.9.0-54
resource-agents (Red Hat package) - update to 4.9.0-54.el8
podman-tests - update to 4.9.4-1.0.1
podman-remote - update to 4.9.4-1.0.1
podman-plugins - update to 4.9.4-1.0.1
podman-gvproxy - update to 4.9.4-1.0.1
podman-catatonit - update to 4.9.4-1.0.1
podman - update to 4.9.4-1.0.1
podman-docker - update to 4.9.4-1.0.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.3
Storage Resource Manager - update to 4.10.0.3
fence-agents-rhevm - update to 4.10.0-62.0.1
fence-agents-kdump - update to 4.10.0-62.0.1
fence-agents-all - update to 4.10.0-62.0.1
fence-agents-lpar - update to 4.10.0-62.0.1
fence-agents-kubevirt - update to 4.10.0-62.0.1
fence-agents-scsi - update to 4.10.0-62.0.1
fence-agents-sbd - update to 4.10.0-62.0.1
fence-virtd-cpg - update to 4.10.0-62.0.1
fence-agents-mpath - update to 4.10.0-62.0.1
fence-agents-aws - update to 4.10.0-62.0.1
fence-agents-rsa - update to 4.10.0-62.0.1
fence-agents-rsb - update to 4.10.0-62.0.1
fence-agents-redfish - update to 4.10.0-62.0.1
fence-virtd - update to 4.10.0-62.0.1
fence-virt - update to 4.10.0-62.0.1
fence-agents-aliyun - update to 4.10.0-62.0.1
fence-agents-gce - update to 4.10.0-62.0.1
fence-agents-azure-arm - update to 4.10.0-62.0.1
fence-agents-heuristics-ping - update to 4.10.0-62.0.1
fence-agents-intelmodular - update to 4.10.0-62.0.1
fence-virtd-libvirt - update to 4.10.0-62.0.1
fence-agents-wti - update to 4.10.0-62.0.1
fence-agents-cisco-mds - update to 4.10.0-62.0.1
fence-agents-cisco-ucs - update to 4.10.0-62.0.1
fence-agents-common - update to 4.10.0-62.0.1
fence-agents-drac5 - update to 4.10.0-62.0.1
fence-agents-eaton-snmp - update to 4.10.0-62.0.1
fence-agents-emerson - update to 4.10.0-62.0.1
fence-agents-eps - update to 4.10.0-62.0.1
fence-agents-vmware-soap - update to 4.10.0-62.0.1
fence-agents-hpblade - update to 4.10.0-62.0.1
fence-agents-ilo2 - update to 4.10.0-62.0.1
fence-agents-ibm-powervs - update to 4.10.0-62.0.1
fence-agents-ibm-vpc - update to 4.10.0-62.0.1
fence-agents-ibmblade - update to 4.10.0-62.0.1
fence-agents-ifmib - update to 4.10.0-62.0.1
fence-agents-ilo-moonshot - update to 4.10.0-62.0.1
fence-agents-ilo-mp - update to 4.10.0-62.0.1
fence-agents-ilo-ssh - update to 4.10.0-62.0.1
fence-agents-vmware-rest - update to 4.10.0-62.0.1
fence-virtd-multicast - update to 4.10.0-62.0.1
fence-virtd-serial - update to 4.10.0-62.0.1
fence-virtd-tcp - update to 4.10.0-62.0.1
ha-cloud-support - update to 4.10.0-62.0.1
fence-agents-amt-ws - update to 4.10.0-62.0.1
fence-agents-virsh - update to 4.10.0-62.0.1
fence-agents-brocade - update to 4.10.0-62.0.1
fence-agents-apc - update to 4.10.0-62.0.1
fence-agents-ipmilan - update to 4.10.0-62.0.1
fence-agents-ipdu - update to 4.10.0-62.0.1
fence-agents-apc-snmp - update to 4.10.0-62.0.1
fence-agents-bladecenter - update to 4.10.0-62.0.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.15.0
IBM Spectrum Scale - addressed in versions 5.1.2.15, 5.1.9.1
SOAR QRadar Plugin App - update to 5.4.0
IBM Sterling Connect:Direct Web Services - update to 6.3.0.11 ifix001
Storage Ceph - update to 7.1
IBM Spectrum Symphony - update to 7.3.2 Fix 601860
IBM QRadar Incident Forensics - update to 7.5.0.10
Maximo Application Suite - IoT Component - addressed in versions 8.7.21, 8.8.17, 9.0.7
IBM Maximo Application Suite - update to 8.8.4
Maximo Application Suite - Predict Component - update to 8.9.1
Dell EMC VxRail Appliance - update to 8.320
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.15-r1, 9.3.3.3-r1, 9.3.4.1-r1
IBM Security Verify Access - update to 10.0.9
IBM Workload Scheduler - addressed in versions 10.1.0.5, 10.2.3
IBM Spectrum Protect Plus - update to 10.1.16
IBM Netezza for Cloud Pak for Data - update to 11.2.3.3
Dell NetWorker Virtual Edition - update to 19.11
NetWorker Management Console (NMC) - update to 19.11
python3-pip - addressed in versions 20.2.2-9, 20.2.2-10, 20.2.2-12, 20.2.2-14, 20.2.2-15, 21.3.1-6, 21.3.1-8, 21.3.1-9, 21.3.1-10, 21.3.1-11, 21.3.1-13, 21.3.1-14, 23.3.1-2, 23.3.1-4, 23.3.1-7, 23.3.1-9
python2-pip - addressed in versions 20.2.2-9, 20.2.2-10, 20.2.2-12, 20.2.2-14, 20.2.2-15
python-pip-wheel - addressed in versions 20.2.2-9, 20.2.2-10, 20.2.2-12, 20.2.2-14, 20.2.2-15, 21.3.1-6, 21.3.1-8, 21.3.1-9, 21.3.1-10, 21.3.1-11, 21.3.1-13, 21.3.1-14, 23.3.1-2, 23.3.1-4, 23.3.1-7, 23.3.1-9
python-pip-help - addressed in versions 20.2.2-9, 20.2.2-10, 20.2.2-12, 20.2.2-14, 20.2.2-15, 21.3.1-6, 21.3.1-8, 21.3.1-9, 21.3.1-10, 21.3.1-11, 21.3.1-13, 21.3.1-14, 23.3.1-2, 23.3.1-4, 23.3.1-7, 23.3.1-9
python-pip - addressed in versions 20.2.2-9, 20.2.2-10, 20.2.2-12, 20.2.2-14, 20.2.2-15, 21.3.1-6, 21.3.1-8, 21.3.1-9, 21.3.1-10, 21.3.1-11, 21.3.1-13, 21.3.1-14, 23.3.1-2, 23.3.1-4, 23.3.1-7, 23.3.1-9
IBM Robotic Process Automation - update to 21.0.7.19
Robotic Process Automation for Cloud Pak - update to 21.0.7.19
python3-pip-whl (Ubuntu package) - addressed in versions 22.0.2+dfsg-1ubuntu0.4, 23.0.1+dfsg-1ubuntu0.2, 23.2+dfsg-1ubuntu0.1
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001
Juniper Junos Space - update to 26.1R1 Patch V1
cockpit-podman - update to 84.1-1
External References
- https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4
- https://www.rfc-editor.org/rfc/rfc9110.html#name-get
- https://github.com/urllib3/urllib3/commit/4e98d57809dacab1cbe625fddeec1a290c478ea9
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5/
Related Security Bulletins
- Information disclosure in urllib3
- Ubuntu update for python-urllib3
- SUSE update for python-urllib3
- SUSE update for python-urllib3
- Fedora 39 update for python-urllib3
- Fedora 38 update for python-urllib3
- Fedora 37 update for python-urllib3
- Ubuntu update for python-pip
- Multiple vulnerabilities in IBM Cloud Object System
- SUSE update for python-urllib3
- SUSE update for python-urllib3
- Multiple vulnerabilities in Splunk Add-on for Google Cloud Platform
- VMware Tanzu Platform Automation Toolkit update for pip
- IBM Storage Sentinel Anomaly Scan Engine update for urllib3
- IBM Process Mining update for urllib3
- Red Hat Enterprise Linux 8.6 Extended Update Support update for python-urllib3
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.1
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.2
- Multiple vulnerabilities in Intel In-Band Manageability Framework
- Multiple vulnerabilities in Red Hat build of Cryostat 2 on RHEL 8
- Red Hat Enterprise Linux 8.8 Extended Update Support update for python-urllib3
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Information disclosure in IBM Maximo Application Suite - IoT Component
- Information disclosure in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Spectrum Protect Plus File Systems Agent
- Multiple vulnerabilities in IBM Spectrum Scale
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.8
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in Red Hat Multicluster GlobalHub
- Multiple vulnerabilities in IBM Spectrum Symphony
- Information disclosure in IBM Spectrum Conductor
- Information disclosure in IBM Maximo Application Suite - Predict Component
- openEuler update for python-urllib3
- Red Hat Enterprise Linux 9.0 Extended Update Support update for fence-agents
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.15
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Information disclosure in IBM Maximo Application Suite
- Information disclosure in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.9
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Migration Toolkit for Runtimes 1.2
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Multiple vulnerabilities in Dell Networking OS10
- Red Hat Enterprise Linux 9 update for fence-agents
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in IBM SOAR QRadar Plugin App
- Red Hat Enterprise Linux 8 update for resource-agents
- Red Hat Enterprise Linux 8 update for fence-agents
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Information disclosure in Dell ECS
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Information disclosure in Red Hat OpenStack 17 packages
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Splunk Enterprise update for third-party components
- openEuler 24.03 LTS update for python-pip
- openEuler 22.03 LTS SP4 update for python-pip
- openEuler 22.03 LTS SP1 update for python-pip
- openEuler 22.03 LTS SP3 update for python-pip
- openEuler 20.03 LTS SP4 update for python-pip
- Multiple vulnerabilities in Dell SmartFabric OS10
- Multiple vulnerabilities in Dell NetWorker Virtual Edition and Dell NetWorker Management Console
- Multiple vulnerabilities in Dell ObjectScale
- Splunk Python for Scientific Computing update for third-party packages
- Multiple vulnerabilities in IBM AIX and IBM VIOS
- Multiple vulnerabilities in IBM Security QRadar EDR
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Storage Ceph
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Splunk Enterprise update for third-party components
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in QRadar Incident Forensics
- IBM Integrated Analytics System update for urllib3
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Red Hat Enterprise Linux 8 update for python3.11-urllib3
- Red Hat Enterprise Linux 9 update for python3.11-urllib3
- IBM Sterling Connect:Direct Web Service update for urllib3
- Red Hat Enterprise Linux 8 update for python3.11-urllib3
- Multiple vulnerabilities in IBM Netezza for Cloud Pak for Data (on Cloud)
- Multiple vulnerabilities in Dell OpenManage Network Integration (OMNI)
- Multiple vulnerabilities in IBM Workload Scheduler component of IBM Workload Automation
- Multiple vulnerabilities in Guardium Data Security Center
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in IBM QRadar Deployment Intelligence App
- Red Hat Enterprise Linux 9 update for python3.11-urllib3
- Red Hat Enterprise Linux 9 update for python3.11-urllib3
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Concert Software
- Anolis OS update for python-urllib3
- Anolis OS update for python-urllib3
- Anolis OS update for resource-agents
- Anolis OS update for python3.11-urllib3
- Anolis OS update for container-tools:an8 module
- Anolis OS update for fence-agents
- Multiple vulnerabilities in Dell VxRail Appliance
- PowerProtect Data Protection software update for third-party components
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Splunk User Behavior Analytics (UBA) update for third-party components
- IBM Cloud Pak for Data System 1.0 update for urllib3
- openEuler 22.03 LTS SP4 update for python-pip
- openEuler 20.03 LTS SP4 update for python-pip
- openEuler 24.03 LTS SP2 update for python-pip
- openEuler 24.03 LTS SP1 update for python-pip
- openEuler 22.03 LTS SP3 update for python-pip
- openEuler 24.03 LTS update for python-pip
- openEuler update for python-pip
- Ubuntu update for python-pip
- openEuler 22.03 LTS SP4 update for python-pip
- openEuler 22.03 LTS SP3 update for python-pip
- openEuler 20.03 LTS SP4 update for python-pip
- Multiple vulnerabilities in IBM Business Automation Insights
- openEuler 24.03 LTS SP1 update for python-pip
- openEuler 20.03 LTS SP4 update for python-pip
- openEuler 24.03 LTS update for python-pip
- openEuler 24.03 LTS SP2 update for python-pip
- openEuler 22.03 LTS SP4 update for python-pip
- openEuler 20.03 LTS SP4 update for python-pip
- openEuler 24.03 LTS SP1 update for python-pip
- openEuler 24.03 LTS update for python-pip
- openEuler 22.03 LTS SP4 update for python-pip
- openEuler 24.03 LTS SP3 update for python-pip
- openEuler 24.03 LTS SP2 update for python-pip
- Multiple vulnerabilities in Junos Space