2022年10月7日星期五

思科產品多個漏洞

發佈日期: 2022年10月06日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

在思科產品發現多個漏洞,遠端攻擊者可利用這些漏洞在目標系統觸發繞過保安限制、遠端執行程式碼、篡改、權限提升及跨網站指令碼。


影響

  • 繞過保安限制
  • 權限提升
  • 遠端執行程式碼
  • 篡改
  • 跨網站指令碼

受影響之系統或技術

  • Cisco Enterprise NFV Infrastructure Software
  • Cisco Expressway Series and Cisco TelePresence Video Communication Server
  • Cisco Touch 10 Devices
  • Cisco Secure Web Appliance Content Encoding Filter
  • Cisco BroadWorks Hosted Thin Receptionist
  • Cisco ATA 190 Series Analog Telephone Adapter Software
  • Cisco Smart Software Manager On-Prem
  • Cisco Jabber Client Software Extensible Messaging and Presence Protocol

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Cisco Products Multiple Vulnerabilities

Release Date: 6 Oct 2022

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities were identified in Cisco Products. A remote attacker could exploit some of these vulnerabilities to security restriction bypass, remote code execution, data manipulation, elevation of privilege and cross-site scripting the targeted system.


Impact

  • Security Restriction Bypass
  • Elevation of Privilege
  • Remote Code Execution
  • Data Manipulation
  • Cross-Site Scripting

System / Technologies affected

  • Cisco Enterprise NFV Infrastructure Software
  • Cisco Expressway Series and Cisco TelePresence Video Communication Server
  • Cisco Touch 10 Devices
  • Cisco Secure Web Appliance Content Encoding Filter
  • Cisco BroadWorks Hosted Thin Receptionist
  • Cisco ATA 190 Series Analog Telephone Adapter Software
  • Cisco Smart Software Manager On-Prem
  • Cisco Jabber Client Software Extensible Messaging and Presence Protocol

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2022年10月5日星期三

Android多個漏洞

發佈日期: 2022年10月05日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於 Android 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務、權限提升及洩露敏感資料。


Android Multiple Vulnerabilities

Release Date: 5 Oct 2022

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Android. A remote attacker could exploit some of these vulnerabilities to trigger denial of service, elevation of privilege and sensitive information disclosure on the targeted system.


Aruba 產品多個漏洞

發佈日期: 2022年10月05日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

在Aruba產品發現多個漏洞,遠端攻擊者可利用這些漏洞在目標系統觸發繞過保安限制、遠端執行程式碼 及 跨網站指令碼。


影響

  • 跨網站指令碼
  • 阻斷服務
  • 遠端執行程式碼

受影響之系統或技術

  • Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 及以前版本
  • Aruba InstantOS 6.5.x: 6.5.4.23 及以前版本
  • Aruba InstantOS 8.6.x: 8.6.0.18 及以前版本
  • Aruba InstantOS 8.7.x: 8.7.1.9 及以前版本
  • Aruba InstantOS 8.10.x: 8.10.0.1 及以前版本
  • ArubaOS 10.3.x: 10.3.1.0 及以前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Aruba Product Multiple Vulnerabilities

Release Date: 5 Oct 2022

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities were identified in Aruba Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service, remote code execution and cross site scripting.


Impact

  • Cross-Site Scripting
  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below
  • Aruba InstantOS 6.5.x: 6.5.4.23 and below
  • Aruba InstantOS 8.6.x: 8.6.0.18 and below
  • Aruba InstantOS 8.7.x: 8.7.1.9 and below
  • Aruba InstantOS 8.10.x: 8.10.0.1 and below
  • ArubaOS 10.3.x: 10.3.1.0 and below

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

ChromeOS 多個漏洞

發佈日期: 2022年10月05日

風險: 中度風險

類型: 操作系統 - 其他操作系統

類型: 其他操作系統

於 ChromeOS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及篡改。


影響

  • 遠端執行程式碼
  • 篡改

受影響之系統或技術

  • 102.0.5005.182 之前的版本(平台版本:14695.135.0)

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

 


漏洞識別碼

  • CVE-2022-3038
  • CVE-2022-3044
  • CVE-2022-3200
  • CVE-2022-3201
  • CVE-2022-3041
  • CVE-2022-3043
  • CVE-2022-2858
  • CVE-2022-2613
  • CVE-2022-3051
  • CVE-2022-3052
  • CVE-2022-3050
  • CVE-2022-3049
  • CVE-2022-3048

資料來源


相關連結

ChromeOS Multiple Vulnerabilities

Release Date: 5 Oct 2022

RISK: Medium Risk

TYPE: Operating Systems - Others OS

TYPE: Others OS

Multiple vulnerabilities were identified in . A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and data manipulation on the targeted system.


Impact

  • Remote Code Execution
  • Data Manipulation

System / Technologies affected

  • Version prior to 102.0.5005.182 ( Platform version: 14695.135.0 )

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

 


Vulnerability Identifier

  • CVE-2022-3038
  • CVE-2022-3044
  • CVE-2022-3200
  • CVE-2022-3201
  • CVE-2022-3041
  • CVE-2022-3043
  • CVE-2022-2858
  • CVE-2022-2613
  • CVE-2022-3051
  • CVE-2022-3052
  • CVE-2022-3050
  • CVE-2022-3049
  • CVE-2022-3048

Source


Related Link

F5 產品多個漏洞

發佈日期: 2022年10月05日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 F5 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行程式碼。

 


影響

  • 遠端執行程式碼

受影響之系統或技術

詳情請參閱以下連結﹕

https://support.f5.com/csp/article/K21600298


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

F5 Products Multiple Vulnerabilities

Release Date: 5 Oct 2022

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in F5 Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

Please refer to the link below for detail:

https://support.f5.com/csp/article/K21600298


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Linux 內核多個漏洞

發佈日期: 2022年10月05日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼、洩露敏感資料及資料篡改。


影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼
  • 資料洩露
  • 篡改

受影響之系統或技術

  • Debian 10 buster version prior to 4.19.260-1
  • SUSE Linux Enterprise High Performance Computing 15-SP2
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Module for Live Patching 15-SP2
  • SUSE Linux Enterprise Module for Live Patching 15-SP3
  • SUSE Linux Enterprise Server 15-SP2 
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15-SP2 
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM
  • Ubuntu 20.04 LTS 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

For Debian

安裝供應商提供的修補程式:

 

For SUSE

安裝供應商提供的修補程式:

 

For Ubuntu

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Linux Kernel Multiple Vulnerabilities

Release Date: 5 Oct 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, sensitive information disclosure and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • Debian 10 buster version prior to 4.19.260-1
  • SUSE Linux Enterprise High Performance Computing 15-SP2
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Module for Live Patching 15-SP2
  • SUSE Linux Enterprise Module for Live Patching 15-SP3
  • SUSE Linux Enterprise Server 15-SP2 
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15-SP2 
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM
  • Ubuntu 20.04 LTS 

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

For Debian

Apply fixes issued by the vendor:

 

For SUSE

Apply fixes issued by the vendor:

 

For Ubuntu

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

微軟Exchange零日遠端執行任意程式碼漏洞

最後更新 2022年10月05日 發佈日期: 2022年09月30日

風險: 高度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於微軟Exchange發現多個漏洞,遠端使用者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼。

 

注意﹕暫無可用的修補程式。

 

[更新於 2022-09-21] 微軟指出這兩個漏洞用於對用戶系統進行有限度的針對性攻擊,風險級別已更新為高度風險。

 

[更新於 2022-10-05] 微軟已更新臨時處理方法


影響

  • 遠端執行程式碼

受影響之系統或技術

  • 微軟Exchange 伺服器 2013
  • 微軟Exchange 伺服器 2016
  • 微軟Exchange 伺服器 2019

解決方案

臨時處理方法:

通過 IIS 服務器上的 URL 重寫規則模塊添加規則以阻止帶有攻擊指標的請求,從而減少攻擊。

 

  1. In Autodiscover at FrontEnd, select tab URL Rewrite, and then Request Blocking.
  2. Add string “.*autodiscover\.json.*Powershell.*” to the URL Path.
  3. Condition input: Choose {REQUEST_URI}

漏洞識別碼


資料來源


相關連結

Microsoft Exchange Zero-day Remote Code Execution Vulnerabilities

Last Update Date: 5 Oct 2022 Release Date: 30 Sep 2022

RISK: High Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities have been identified in Microsoft Exchange. A remote user can exploit some of these vulnerabilities to trigger remote code execution on the targeted system.

 

Notes: No patch is currently available.

 

[Updated on 2022-09-30] Microsoft stated that the two vulnerabilities were used for limited targeted attacks into users’ systems, the Risk Level has updated to High Risk.

 

[Updated on 2022-10-05] Microsoft updated the workaround for this issue.


Impact

  • Remote Code Execution

System / Technologies affected

  • Microsoft Exchange Server 2013
  • Microsoft Exchange Server 2016
  • Microsoft Exchange Server 2019

Solutions

Workaround:

Reduce the vulnerability of attacks by adding a rule to block requests with indicators of attack through the URL Rewrite Rule module on IIS server.

 

  1. In Autodiscover at FrontEnd, select tab URL Rewrite, and then Request Blocking.
  2. Add string “.*autodiscover\.json.*Powershell.*” to the URL Path.
  3. Condition input: Choose {REQUEST_URI}

Vulnerability Identifier


Source


Related Link

2022年10月3日星期一

Google Chrome 多個漏洞

發佈日期: 2022年10月03日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及阻斷服務。


影響

  • 遠端執行程式碼
  • 阻斷服務

受影響之系統或技術

  • Google Chrome 106.0.5249.91 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 106.0.5249.91 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 3 Oct 2022

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and denial of service on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service

System / Technologies affected

  • Google Chrome prior to 106.0.5249.91

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 106.0.5249.91 or later

Vulnerability Identifier


Source


Related Link

Mozilla Thunderbird 多個漏洞

發佈日期: 2022年10月03日

風險: 中度風險

類型: 用戶端 - 電郵用戶端

類型: 電郵用戶端

於 Mozilla Thunderbird 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制、仿冒及資料篡改。


影響

  • 繞過保安限制
  • 仿冒
  • 篡改

受影響之系統或技術

  • Thunderbird 102.3.1 之前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

  • 更新至版本 102.3.1

漏洞識別碼


資料來源


相關連結

Mozilla Thunderbird Multiple Vulnerabilities

Release Date: 3 Oct 2022

RISK: Medium Risk

TYPE: Clients - Email Clients

TYPE: Email Clients

Multiple vulnerabilities were identified in Mozilla Thunderbird. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, spoofing and data manipulation disclosure on the targeted system.


Impact

  • Security Restriction Bypass
  • Spoofing
  • Data Manipulation

System / Technologies affected

  • Thunderbird version prior to 102.3.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Update to version 102.3.1

Vulnerability Identifier


Source


Related Link

2022年10月1日星期六

微軟Exchange零日遠端執行任意程式碼漏洞

最後更新 2022年09月30日 17:09 發佈日期: 2022年09月30日

風險: 高度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於微軟Exchange發現多個漏洞,遠端使用者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼。

 

注意﹕暫無可用的修補程式。

 

[更新於 2022-09-21] 微軟指出這兩個漏洞用於對用戶系統進行有限度的針對性攻擊,風險級別已更新為高度風險。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • 微軟Exchange 伺服器 2013
  • 微軟Exchange 伺服器 2016
  • 微軟Exchange 伺服器 2019

解決方案

臨時處理方法:

通過 IIS 服務器上的 URL 重寫規則模塊添加規則以阻止帶有攻擊指標的請求,從而減少攻擊。

 

  1. In Autodiscover at FrontEnd, select tab URL Rewrite, and then Request Blocking.
  2. Add string “.*autodiscover\.json.*\@.*Powershell.*“ to the URL Path.
  3. Condition input: Choose {REQUEST_URI}

漏洞識別碼


資料來源


相關連結

Microsoft Exchange Zero-day Remote Code Execution Vulnerabilities

Last Update Date: 30 Sep 2022 17:00 Release Date: 30 Sep 2022

RISK: High Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities have been identified in Microsoft Exchange. A remote user can exploit some of these vulnerabilities to trigger remote code execution on the targeted system.

 

Notes: No patch is currently available.

 

[Updated on 2022-09-30] Microsoft stated that the two vulnerabilities were used for limited targeted attacks into users’ systems, the Risk Level has updated to High Risk.


Impact

  • Remote Code Execution

System / Technologies affected

  • Microsoft Exchange Server 2013
  • Microsoft Exchange Server 2016
  • Microsoft Exchange Server 2019

Solutions

Workaround:

Reduce the vulnerability of attacks by adding a rule to block requests with indicators of attack through the URL Rewrite Rule module on IIS server.

 

  1. In Autodiscover at FrontEnd, select tab URL Rewrite, and then Request Blocking.
  2. Add string “.*autodiscover\.json.*\@.*Powershell.*“ to the URL Path.
  3. Condition input: Choose {REQUEST_URI}

Vulnerability Identifier


Source


Related Link

Apache Tomcat 資料洩露漏洞

發佈日期: 2022年09月30日

風險: 中度風險

類型: 伺服器 - 網站伺服器

類型: 網站伺服器

於 Apache Tomcat 發現一個漏洞,遠端使用者可利用此漏洞,於目標系統觸發資料洩露。


影響

  • 資料洩露

受影響之系統或技術

  • Apache Tomcat 10.1.0-M1 to 10.1.0-M12
  • Apache Tomcat 10.0.0-M1 to 10.0.18
  • Apache Tomcat 9.0.0-M1 to 9.0.60
  • Apache Tomcat 8.5.0 to 8.5.77

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

  • Apache Tomcat 8.5.78 或之後版本
  • Apache Tomcat 9.0.62 或之後版本
  • Apache Tomcat 10.0.20 或之後版本
  • Apache Tomcat 10.1.0-M14 或之後版本

注意 10.1.0-M13、10.0.19 和 9.0.61 未發布


漏洞識別碼


資料來源


相關連結

Apache Tomcat Information Disclosure Vulnerability

Release Date: 30 Sep 2022

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

A vulnerability has been identified in Apache Tomcat. A remote user can exploit this vulnerability to trigger information disclosure on the targeted system.


Impact

  • Information Disclosure

System / Technologies affected

  • Apache Tomcat 10.1.0-M1 to 10.1.0-M12
  • Apache Tomcat 10.0.0-M1 to 10.0.18
  • Apache Tomcat 9.0.0-M1 to 9.0.60
  • Apache Tomcat 8.5.0 to 8.5.77

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • Apache Tomcat version 8.5.78 or later
  • Apache Tomcat version 9.0.62 or later
  • Apache Tomcat version 10.0.20 or later
  • Apache Tomcat version 10.1.0-M14 or later

Note 10.1.0-M13, 10.0.19 and 9.0.61 were not released


Vulnerability Identifier


Source


Related Link

IBM WebSphere Application Server 阻斷服務漏洞

發佈日期: 2022年09月30日

風險: 中度風險

類型: 伺服器 - 互聯網應用伺服器

類型: 互聯網應用伺服器

於 IBM WebSphere Application Server 發現一個漏洞,遠端攻擊者可利用此漏洞,於目標系統觸發阻斷服務狀況。


影響

  • 阻斷服務

受影響之系統或技術

  • IBM WebSphere Application Server Liberty 17.0.0.3 - 22.0.0.10

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

https://www.ibm.com/support/pages/node/6824871
https://www.auscert.org.au/bulletins/ESB-2022.4841

IBM WebSphere Application Server Denial of Service Vulnerability

Release Date: 30 Sep 2022

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

A vulnerability was identified in IBM WebSphere Application Server. A remote attacker could exploit this vulnerability to trigger denial of service condition on the targeted system.


Impact

  • Denial of Service

System / Technologies affected

  • IBM WebSphere Application Server Liberty 17.0.0.3 - 22.0.0.10

Solutions

Before installation of the software, please visit the vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

https://www.ibm.com/support/pages/node/6824871
https://www.auscert.org.au/bulletins/ESB-2022.4841

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...