Security Updates#

The Melissa Security Update site shows security vulnerabilities affecting Melissa products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.

Please submit a Vulnerability Inquiry if you have any questions.

Identifier Number

Title

Status

Attestation Date

CVE-2024-4577

CVE-2024-4577 PHP Zero-day

Resolved

Aug 22, 2024

MD-2024-0822

MD-2024-0822 Pollyfill.io JavaScript

Resolved

Aug 22, 2024

MD-2024-0719

MD-2024-0719 CrowdStrike Outage

Resolved

Jul 19, 2024

CVE-2024-5806

CVE-2024-5806 MOVEit Transfer Bug

Resolved

Jul 01, 2024

CISA-2024-0603

CISA-2024-0603 Snowflake Cyber Security Threat

Resolved

Jun 10, 2024

CISA-2024-0523

CISA-2024-0523 Compromise of Sisense Customer Data

Resolved

May 23, 2024

CVE-2024-4040

CVE-2024-4040 CrushFTP Zero-day

Resolved

May 10, 2024

CVE-2024-3094

CVE-2024-3094 XZ Utils Vulnerability

Resolved

Apr 23, 2024

CVE-2024-21626

CVE-2024-21626 Leaky Vessels Vulnerability

Resolved

Mar 27, 2024

CVE-2023-39336

CVE-2023-39336 Ivanti Juniper SonicWall

Resolved

Jan 29, 2024

MD-2023-1221

MD-2023-1221 Apache Struts Critical Vulnerability

Resolved

Dec 21, 2023

MD-2023-1114

MD-2023-1114 ServiceNow Security Vulnerability

Resolved

Nov 14, 2023

MD-2023-1018

MD-2023-1018 Curl, Libcurl Vulnerability

Resolved

Oct 18, 2023

CVE-2023-4966

CVE-2023-4966 Citrix Information Disclosure

Resolved

Oct 10, 2023

MD-2023-0811

MD-2023-0811 Microsoft Azure Breach

Resolved

Aug 11, 2023

CVE-2023-35708

CVE-2023-35708 MOVEit Vulnerability

Resolved

Jun 28, 2023

CVE-2023-35036

CVE-2023-35036 MOVEit Vulnerability

Resolved

CVE-2023-34362

CVE-2023-34362 MOVEit Vulnerability

Resolved

MD-2023-0124

MD-2023-0124 CircleCI Vulnerability

Resolved

Jan 24, 2023

CVE-2022-3602

CVE-2022-3602 OpenSSL v3.0 Vulnerability

Resolved

Nov 27, 2022

CVE-2022-42889

CVE-2022-42889 Text4Shell Vulnerability

Resolved

Oct 26, 2022

CVE-2022-26134

CVE-2022-26134 OGNL Injection Vulnerability

Resolved

Jun 27, 2022

CVE-2022-22973

CVE-2022-22973 VMware Vulnerabilities

Resolved

Jul 15, 2022

CVE-2022-22972

CVE-2022-22972 VMware Vulnerabilities

Resolved

CVE-2022-22960

CVE-2022-22960 VMware Vulnerabilities

Resolved

CVE-2022-22954

CVE-2022-22954 VMware Vulnerabilities

Resolved

CVE-2022-1388

CVE-2022-1388 F5 BIG-IP Vulnerability

Resolved

May 27, 2022

CVE-2022-22965

CVE-2022-22965 Spring4Shell Vulnerability

Resolved

Apr 29, 2022

CVE-2021-44228

CVE-2021-44228 Apache Log4j2

Resolved

Dec 13, 2021

CVE-2021-27065

CVE-2021-27065 MS Exchange Vulnerability

Resolved

Mar 2, 2021

CVE-2021-26858

CVE-2021-26858 MS Exchange Vulnerability

Resolved

CVE-2021-26857

CVE-2021-26857 MS Exchange Vulnerability

Resolved

CVE-2021-26855

CVE-2021-26855 MS Exchange Vulnerability

Resolved

CVE-2021-27078

CVE-2021-27078 MS Exchange Vulnerability

Resolved

Mar 2, 2021

CVE-2021-26854

CVE-2021-26854 MS Exchange Vulnerability

Resolved

CVE-2021-26412

CVE-2021-26412 MS Exchange Vulnerability

Resolved

CVE-2020-10148

CVE-2021-10148 SolarWinds Orion API Vulnerability

Resolved

Jan 14, 2021