Security News > 2024 > July > Progress warns of critical RCE bug in Telerik Report Server
Progress Software has warned customers to patch a critical remote code execution security flaw in the Telerik Report Server that can be used to compromise vulnerable devices.
As a server-based reporting platform, Telerik Report Server provides centralized storage for reports and the tools needed to create, deploy, deliver, and manage them across an organization.
The vulnerability impacts Report Server 2024 Q2 and earlier and was patched in version 2024 Q2. "Updating to Report Server 2024 Q2 or later is the only way to remove this vulnerability," the business software maker warned in a Wednesday advisory.
Go to your Report Server web UI and log in using an account with administrator rights.
In 2022, a U.S. federal agency's Microsoft Internet Information Services web server was hacked by exploiting the CVE-2019-18935 critical Progress Telerik UI vulnerability, which is included in the FBI's list of top targeted vulnerabilities and the NSA's top 25 security bugs abused by Chinese hackers.
New regreSSHion OpenSSH RCE bug gives root on Linux servers.
News URL
Related news
- Broadcom fixes critical RCE bug in VMware vCenter Server (source)
- Critical Zimbra RCE flaw exploited to backdoor servers using emails (source)
- SolarWinds fixes critical RCE bug affecting all Web Help Desk versions (source)
- Critical RCE bug in SolarWinds Web Help Desk fixed (CVE-2024-28986) (source)
- CISA warns critical SolarWinds RCE bug is exploited in attacks (source)
- SOCI Act 2024: Thales Report Reveals Critical Infrastructure Breaches in Australia (source)
- GitHub Enterprise Server vulnerable to critical auth bypass flaw (source)
- You probably want to patch this critical GitHub Enterprise Server bug now (source)
- GitHub Patches Critical Security Flaw in Enterprise Server Granting Admin Privileges (source)
- Critical GitHub Enterprise Server auth bypass flaw fixed (CVE-2024-6800) (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-12-11 | CVE-2019-18935 | Deserialization of Untrusted Data vulnerability in Telerik UI for Asp.Net Ajax Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. | 9.8 |