CVE-2022-21449
published 2022-04-19CVE-2022-21449: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected…
PriorityP263high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
48.23%
98.7th percentile
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.2 and 18; Oracle GraalVM Enterprise Edition: 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| azul | zulu | — | — |
| azul | zulu | — | — |
| azul | zulu | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjdk-17 | < openjdk-17 17.0.3+7-1 (bookworm) | openjdk-17 17.0.3+7-1 (bookworm) |
| netapp | e-series_santricity_os_controller | — | — |
| oracle | graalvm | — | — |
| oracle | graalvm | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle_corporation | java_se_jdk_and_jre | — | — |
| oracle_corporation | java_se_jdk_and_jre | — | — |
| oracle_corporation | java_se_jdk_and_jre | — | — |
| oracle_corporation | java_se_jdk_and_jre | — | — |
| paloalto | pan-os | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-21449 ('Psychic Signatures') allows ECDSA signature bypass in Java 17/18 and GraalVM 21.3.1/22.0.0.2. An attacker can forge a valid ES256 JWT by supplying a blank/zeroed DER-encoded ECDSA signature (e.g., MAYCAQACAQA in base64url). Detect JWT tokens where the signature component decodes to a near-zero or all-zero DER ECDSA structure (r=0, s=0 or r=1, s=1). ↗
- →Affected Oracle Java SE versions: 17.0.2 and 18; Oracle GraalVM Enterprise Edition: 21.3.1 and 22.0.0.2. Flag deployments running these JVM versions using ECDSA signature verification (e.g., ES256/ES384/ES512 JWT algorithms) as high-priority patching targets. ↗
- →The vulnerability is in the Libraries component (bug 8277233) of Oracle Java SE. Inspect ECDSA signature verification code paths in Java 17/18 for missing or improper validation of r and s values in the signature. ↗
- ·The vulnerability can be exploited both via sandboxed Java Web Start/applet contexts AND directly through APIs (e.g., web services supplying data to the Libraries API), broadening the attack surface beyond browser-based deployments. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2010-1622 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2022-08-04·CVSS 5.3
CVE-2022-21434 [MEDIUM] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
USN-5546-1 fixed vulnerabilities in OpenJDK.
This update provides the corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
Neil Madden discovered that OpenJDK did not properly verify ECDSA
signatures. A remote attacker could possibly use this issue to insert,
edit or obtain sensitive information. This issue only affected OpenJDK
17 and OpenJDK 18. (CVE-2022-21449)
It was discovered that OpenJDK incorrectly limited memory when compiling a
specially crafted XPath expression. An attacker could possibly use this
issue to cause a denial of service. This issue was fixed in OpenJDK 8 and
OpenJDK 18. USN-5388-1 and USN-5388-2 addressed this issue in OpenJDK 11
and OpenJDK 17. (CVE-2022
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2022-08-04·CVSS 5.3
CVE-2022-21541 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
Neil Madden discovered that OpenJDK did not properly verify ECDSA
signatures. A remote attacker could possibly use this issue to insert,
edit or obtain sensitive information. This issue only affected OpenJDK
17 and OpenJDK 18. (CVE-2022-21449)
It was discovered that OpenJDK incorrectly limited memory when compiling a
specially crafted XPath expression. An attacker could possibly use this
issue to cause a denial of service. This issue was fixed in OpenJDK 8 and
OpenJDK 18. USN-5388-1 and USN-5388-2 addressed this issue in OpenJDK 11
and OpenJDK 17. (CVE-2022-21426)
It was discovered that OpenJDK incorrectly handled converting certain
object arguments into their textual representations. An attacker cou
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2022-04-26·CVSS 5.3
CVE-2022-21476 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
It was discovered that OpenJDK incorrectly verified ECDSA signatures. An
attacker could use this issue to bypass the signature verification process.
(CVE-2022-21449)
It was discovered that OpenJDK incorrectly limited memory when compiling a
specially crafted XPath expression. An attacker could possibly use this
issue to cause a denial of service. (CVE-2022-21426)
It was discovered that OpenJDK incorrectly handled converting certain
object arguments into their textual representations. An attacker could
possibly use this issue to cause a denial of service. (CVE-2022-21434)
It was discovered that OpenJDK incorrectly validated the encoded length of
certain object identifiers. An attacker could possibly
Red Hat
OpenJDK: Improper ECDSA signature verification (Libraries, 8277233)
vendor_redhat·2022-04-19·CVSS 7.5
CVE-2022-21449 [HIGH] CWE-347 OpenJDK: Improper ECDSA signature verification (Libraries, 8277233)
OpenJDK: Improper ECDSA signature verification (Libraries, 8277233)
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.2 and 18; Oracle GraalVM Enterprise Edition: 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start
Oracle
Oracle Oracle Java SE Risk Matrix: Libraries — CVE-2022-21449
vendor_oracle·2022-04-15·CVSS 7.5
CVE-2022-21449 [HIGH] Oracle Oracle Java SE Risk Matrix: Libraries — CVE-2022-21449
Oracle Oracle Java SE Risk Matrix: Libraries vulnerability
CVE: CVE-2022-21449
CVSS: 7.5
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Debian
CVE-2022-21449: openjdk-17 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...
vendor_debian·2022·CVSS 7.5
CVE-2022-21449 [HIGH] CVE-2022-21449: openjdk-17 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.2 and 18; Oracle GraalVM Enterprise Edition: 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted c
OSV
openjdk-8, openjdk-lts, openjdk-17, openjdk-18 vulnerabilities
osv·2022-08-04·CVSS 5.3
CVE-2022-21449 [MEDIUM] openjdk-8, openjdk-lts, openjdk-17, openjdk-18 vulnerabilities
openjdk-8, openjdk-lts, openjdk-17, openjdk-18 vulnerabilities
Neil Madden discovered that OpenJDK did not properly verify ECDSA
signatures. A remote attacker could possibly use this issue to insert,
edit or obtain sensitive information. This issue only affected OpenJDK
17 and OpenJDK 18. (CVE-2022-21449)
It was discovered that OpenJDK incorrectly limited memory when compiling a
specially crafted XPath expression. An attacker could possibly use this
issue to cause a denial of service. This issue was fixed in OpenJDK 8 and
OpenJDK 18. USN-5388-1 and USN-5388-2 addressed this issue in OpenJDK 11
and OpenJDK 17. (CVE-2022-21426)
It was discovered that OpenJDK incorrectly handled converting certain
object arguments into their textual representations. An attacker could
possibly use this issu
OSV
openjdk-8 vulnerabilities
osv·2022-08-04·CVSS 5.3
CVE-2022-21449 [MEDIUM] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
USN-5546-1 fixed vulnerabilities in OpenJDK.
This update provides the corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
Neil Madden discovered that OpenJDK did not properly verify ECDSA
signatures. A remote attacker could possibly use this issue to insert,
edit or obtain sensitive information. This issue only affected OpenJDK
17 and OpenJDK 18. (CVE-2022-21449)
It was discovered that OpenJDK incorrectly limited memory when compiling a
specially crafted XPath expression. An attacker could possibly use this
issue to cause a denial of service. This issue was fixed in OpenJDK 8 and
OpenJDK 18. USN-5388-1 and USN-5388-2 addressed this issue in OpenJDK 11
and OpenJDK 17. (CVE-2022-21426)
It was discovered that OpenJDK incorrectly handled conver
OSV
openjdk-17 vulnerabilities
osv·2022-04-26·CVSS 5.3
CVE-2022-21449 [MEDIUM] openjdk-17 vulnerabilities
openjdk-17 vulnerabilities
It was discovered that OpenJDK incorrectly verified ECDSA signatures. An
attacker could use this issue to bypass the signature verification process.
(CVE-2022-21449)
It was discovered that OpenJDK incorrectly limited memory when compiling a
specially crafted XPath expression. An attacker could possibly use this
issue to cause a denial of service. (CVE-2022-21426)
It was discovered that OpenJDK incorrectly handled converting certain
object arguments into their textual representations. An attacker could
possibly use this issue to cause a denial of service. (CVE-2022-21434)
It was discovered that OpenJDK incorrectly validated the encoded length of
certain object identifiers. An attacker could possibly use this issue to
cause a denial of service. (CVE-2022-21443)
GHSA
GHSA-cj8x-r9fp-q656: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries)
ghsa_unreviewed·2022-04-20
CVE-2022-21449 [HIGH] GHSA-cj8x-r9fp-q656: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries)
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, t
OSV
CVE-2022-21449: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries)
osv·2022-04-19·CVSS 7.5
CVE-2022-21449 [HIGH] CVE-2022-21449: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries)
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.2 and 18; Oracle GraalVM Enterprise Edition: 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted c
Suricata
ET EXPLOIT [ConnectWise CRU] Java ECDSA (Psychic) TLS Signature (CVE-2022-21449)
suricata·2022-04-26·CVSS 7.5
CVE-2022-21449 [HIGH] ET EXPLOIT [ConnectWise CRU] Java ECDSA (Psychic) TLS Signature (CVE-2022-21449)
ET EXPLOIT [ConnectWise CRU] Java ECDSA (Psychic) TLS Signature (CVE-2022-21449)
Rule: alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT [ConnectWise CRU] Java ECDSA (Psychic) TLS Signature (CVE-2022-21449)"; flow:established,to_client; tls.certs; content:"|04 03 00 08 30 06 02 01 00 02 01 00|"; tag:session,5,packets; reference:url,github.com/thack1/CVE-2022-21449; reference:cve,2022-21449; classtype:targeted-activity; sid:2036377; rev:3; metadata:created_at 2022_04_26, cve CVE_2022_21449, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_04_25;)
No public exploits indexed.
arXiv
KryptoPilot: An Open-World Knowledge-Augmented LLM Agent for Automated Cryptographic Exploitation
arxiv_fulltext·2026-01-14
KryptoPilot: An Open-World Knowledge-Augmented LLM Agent for Automated Cryptographic Exploitation
KryptoPilot: An Open-World Knowledge-Augmented LLM Agent for Automated Cryptographic Exploitation
Xiaonan Liu
These authors contributed equally to this work.
Independent Researcher
Beijing
China
[email protected]
Zhihao Li
[1]
Sichuan University
Chengdu
China
[email protected]
Xiao Lan
Corresponding author.
Sichuan University
Chengdu
China
[email protected]
Hao Ren
Sichuan University
Chengdu
China
[email protected]
Haizhou Wang
Sichuan University
Chengdu
China
[email protected]
Xingshu Chen
Sichuan University
Chengdu
China
[email protected]
## Abstract
Capture-the-Flag (CTF) competitions play a central role in modern cybersecurity, serving as a primary platform for training security practitioners and evaluating offensive and defensive techniques derived f
arXiv
CryptoScope: Utilizing Large Language Models for Automated Cryptographic Logic Vulnerability Detection
arxiv_fulltext·2025-08-15·CVSS 7.5
[HIGH] CryptoScope: Utilizing Large Language Models for Automated Cryptographic Logic Vulnerability Detection
## Abstract
Cryptographic algorithms are fundamental to modern security, yet their implementations frequently harbor subtle logic flaws that are hard to detect. We introduce , a novel framework for automated cryptographic vulnerability detection powered by Large Language Models (LLMs). combines Chain-of-Thought (CoT) prompting with Retrieval-Augmented Generation (RAG), guided by a curated cryptographic knowledge base containing over 12,000 entries. We evaluate on LLM-CLVA, a benchmark of 92 cases primarily derived from real-world CVE vulnerabilities, complemented by cryptographic challenges from major Capture The Flag (CTF) competitions and synthetic examples across 11 programming languages. consistently improves performance over strong LLM baselines, boosting DeepSeek-V3 by 11.62%, GPT-4
CTF
jalyboy-jalygirl / README
ctf_writeups·2024
jalyboy-jalygirl / README
# jalyboy-jalygirl:Web:100pts
It's almost spring. Do you like Java?
[http://34.85.123.82:10001/](http://34.85.123.82:10001/)
[jalyboy-jalygirl_2df1a2ce1e35d8c9cd97cf59436ec135.zip](jalyboy-jalygirl_2df1a2ce1e35d8c9cd97cf59436ec135.zip)
# Solution
URLとソースが渡される。
[jalyboy-baby](../jalyboy-baby)の続き問題のようだ。
URLクエリは以下であった。
```
http://34.85.123.82:10001/?j=eyJhbGciOiJFUzI1NiJ9.eyJzdWIiOiJndWVzdCJ9.QZcJ_5i4ODRj9Vzf0BOWCPlrg4vPaVQeFuKm6yTCxWj1NqK5icY9LdOr1i44AIeufkF9nW7NANjEZfrx3p2M9A
```
ソースの主要部分は以下のように変更されていた。
```java
~~~
@Controller
public class JwtController {
public static final String ADMIN = "admin";
public static final String GUEST = "guest";
public static final String UNKNOWN = "unknown";
public static final String FLAG = System.getenv("FLAG");
KeyPair keyPair = Keys.keyPairFor(Signatur
CTF
web-jalboy / readme
ctf_writeups·2024·CVSS 7.5
CVE-2022-21449 [HIGH] web-jalboy / readme
# baby
- JWT algorithm none attack
# jalygirl
- CVE-2022-21449
- Shout out to Toshiki Sasazaki!
> We'd also like to thank Toshiki Sasazaki, a member of LINE Corporation's Application Security Team as the first person to report the concern directly to the JJWT team, as well as for working with us during testing leading to our conclusions and subsequent 0.11.3 patch release.
- **Flag: `LINECTF{abaa4d1cb9870fd25776a81bbd278932}`**
Tenable
Mind the Gap: A Closer Look at the Vulnerabilities Disclosed in 2022
blogs_tenable·2023-05-09
Mind the Gap: A Closer Look at the Vulnerabilities Disclosed in 2022
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle April 2022 Critical Patch Update Addresses 221 CVEs
blogs_tenable·2022-04-20
Oracle April 2022 Critical Patch Update Addresses 221 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://www.openwall.com/lists/oss-security/2022/04/28/2http://www.openwall.com/lists/oss-security/2022/04/28/3http://www.openwall.com/lists/oss-security/2022/04/28/4http://www.openwall.com/lists/oss-security/2022/04/28/5http://www.openwall.com/lists/oss-security/2022/04/28/6http://www.openwall.com/lists/oss-security/2022/04/28/7http://www.openwall.com/lists/oss-security/2022/04/29/1http://www.openwall.com/lists/oss-security/2022/04/30/1http://www.openwall.com/lists/oss-security/2022/04/30/2http://www.openwall.com/lists/oss-security/2022/04/30/3http://www.openwall.com/lists/oss-security/2022/04/30/4http://www.openwall.com/lists/oss-security/2022/05/01/1http://www.openwall.com/lists/oss-security/2022/05/01/2http://www.openwall.com/lists/oss-security/2022/05/02/1https://security.netapp.com/advisory/ntap-20220429-0006/https://www.debian.org/security/2022/dsa-5128https://www.debian.org/security/2022/dsa-5131https://www.oracle.com/security-alerts/cpuapr2022.htmlhttp://www.openwall.com/lists/oss-security/2022/04/28/2http://www.openwall.com/lists/oss-security/2022/04/28/3http://www.openwall.com/lists/oss-security/2022/04/28/4http://www.openwall.com/lists/oss-security/2022/04/28/5http://www.openwall.com/lists/oss-security/2022/04/28/6http://www.openwall.com/lists/oss-security/2022/04/28/7http://www.openwall.com/lists/oss-security/2022/04/29/1http://www.openwall.com/lists/oss-security/2022/04/30/1http://www.openwall.com/lists/oss-security/2022/04/30/2http://www.openwall.com/lists/oss-security/2022/04/30/3http://www.openwall.com/lists/oss-security/2022/04/30/4http://www.openwall.com/lists/oss-security/2022/05/01/1http://www.openwall.com/lists/oss-security/2022/05/01/2http://www.openwall.com/lists/oss-security/2022/05/02/1https://security.netapp.com/advisory/ntap-20220429-0006/https://www.debian.org/security/2022/dsa-5128https://www.debian.org/security/2022/dsa-5131https://www.oracle.com/security-alerts/cpuapr2022.html
2022-04-19
Published