2022年11月9日星期三

微軟每月保安更新 (2022年11月)

發佈日期: 2022年11月09日

風險: 中度風險

類型: 操作系統 - 視窗操作系統

類型: 視窗操作系統

微軟已為產品提供本月保安更新:

 

受影響產品風險程度影響備註
視窗中度風險 中度風險資料洩露
權限提升
阻斷服務
遠端執行程式碼
繞過保安限制

CVE-2022-41091 正被廣泛利用。

注意:此攻擊者需要說服用戶採取行動來利用 CVE-2022-41091 漏洞,風險程度被評為中度風險。

延伸安全性更新 (ESU)中度風險 中度風險資料洩露
權限提升
阻斷服務
遠端執行程式碼
 
開源軟件中度風險 中度風險權限提升 
Azure中度風險 中度風險權限提升
遠端執行程式碼
 
開發者工具中度風險 中度風險資料洩露
權限提升
遠端執行程式碼
 
微軟 Office中度風險 中度風險仿冒
資料洩露
遠端執行程式碼
繞過保安限制
 
Exchange Server中度風險 中度風險仿冒
權限提升
 
微軟 Dynamics中度風險 中度風險資料洩露 

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:8

「低度風險」產品數目:0

整體「風險程度」評估:中度風險


影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露
  • 仿冒

受影響之系統或技術

  • 視窗
  • 延伸安全性更新 (ESU)
  • 開源軟件
  • Azure
  • 開發者工具
  • 微軟 Office
  • Exchange Server
  • 微軟 Dynamics

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 安裝軟件供應商提供的修補程式。

漏洞識別碼


資料來源


相關連結

Microsoft Monthly Security Update (November 2022)

Release Date: 9 Nov 2022

RISK: Medium Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
WindowsMedium Risk Medium RiskInformation Disclosure
Elevation of Privilege
Denial of Service
Remote Code Execution
Security Restriction Bypass

CVE-2022-41091 is being exploited in the wild.

Note: The attacker would have to convince a user to take action to exploit the vulnerability CVE-2022-41091, the risk level is rated as Medium Risk.

Extended Security Updates (ESU)Medium Risk Medium RiskInformation Disclosure
Elevation of Privilege
Denial of Service
Remote Code Execution
 
Open Source SoftwareMedium Risk Medium RiskElevation of Privilege 
AzureMedium Risk Medium RiskElevation of Privilege
Remote Code Execution
 
Developer ToolsMedium Risk Medium RiskInformation Disclosure
Elevation of Privilege
Remote Code Execution
 
Microsoft OfficeMedium Risk Medium RiskSpoofing
Information Disclosure
Remote Code Execution
Security Restriction Bypass
 
Exchange ServerMedium Risk Medium RiskSpoofing
Elevation of Privilege
 
Microsoft DynamicsMedium Risk Medium RiskInformation Disclosure 

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 8

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure
  • Spoofing

System / Technologies affected

  • Windows
  • Extended Security Updates (ESU)
  • Open Source Software
  • Azure
  • Developer Tools
  • Microsoft Office
  • Exchange Server
  • Microsoft Dynamics

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

微軟Exchange零日遠端執行任意程式碼漏洞

最後更新 2022年11月09日 發佈日期: 2022年09月30日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於微軟Exchange發現多個漏洞,遠端使用者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼。

 

[更新於 2022-09-21] 微軟指出這兩個漏洞用於對用戶系統進行有限度的針對性攻擊,風險級別已更新為高度風險。

 

[更新於 2022-10-05] 微軟已更新臨時處理方法

 

[更新於 2022-11-09] 微軟已於2022年11月的每月保安更新中發布 CVE-2022-41040 及 CVE-2022-41082 的保安更新。風險程度由高度風險更改至中度風險。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • 微軟Exchange 伺服器 2013
  • 微軟Exchange 伺服器 2016
  • 微軟Exchange 伺服器 2019

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

 

臨時處理方法:

通過 IIS 服務器上的 URL 重寫規則模塊添加規則以阻止帶有攻擊指標的請求,從而減少攻擊。

 

  1. In Autodiscover at FrontEnd, select tab URL Rewrite, and then Request Blocking.
  2. Add string “.*autodiscover\.json.*Powershell.*” to the URL Path.
  3. Condition input: Choose {REQUEST_URI}

漏洞識別碼


資料來源


相關連結

Microsoft Exchange Zero-day Remote Code Execution Vulnerabilities

Last Update Date: 9 Nov 2022 Release Date: 30 Sep 2022

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities have been identified in Microsoft Exchange. A remote user can exploit some of these vulnerabilities to trigger remote code execution on the targeted system.

 

[Updated on 2022-09-30] Microsoft stated that the two vulnerabilities were used for limited targeted attacks into users’ systems, the Risk Level has updated to High Risk.

 

[Updated on 2022-10-05] Microsoft updated the workaround for this issue.

 

[Updated on 2022-11-09] Microsoft released security updates for CVE-2022-41040 and CVE-2022-41082 in Monthly Security Update for November 2022. Risk level has changed from High Risk to Medium Risk.


Impact

  • Remote Code Execution

System / Technologies affected

  • Microsoft Exchange Server 2013
  • Microsoft Exchange Server 2016
  • Microsoft Exchange Server 2019

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

 

Workaround:

Reduce the vulnerability of attacks by adding a rule to block requests with indicators of attack through the URL Rewrite Rule module on IIS server.

 

  1. In Autodiscover at FrontEnd, select tab URL Rewrite, and then Request Blocking.
  2. Add string “.*autodiscover\.json.*Powershell.*” to the URL Path.
  3. Condition input: Choose {REQUEST_URI}

Vulnerability Identifier


Source


Related Link

2022年11月8日星期二

IBM MQ 阻斷服務漏洞

發佈日期: 2022年11月07日

風險: 中度風險

類型: 伺服器 - 網絡管理

類型: 網絡管理

於 IBM MQ 發現一個漏洞。遠端使用者可利用此漏洞,於目標系統觸發阻斷服務狀況。


影響

  • 阻斷服務

受影響之系統或技術

  • IBM MQ 9.1 LTS
  • IBM MQ 9.2 LTS
  • IBM MQ 9.3 LTS
  • IBM MQ 9.1 CD
  • IBM MQ 9.2 CD
  • IBM MQ 9.3 CD

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

IBM MQ Denial of Service Vulnerability

Release Date: 7 Nov 2022

RISK: Medium Risk

TYPE: Servers - Network Management

TYPE: Network Management

A vulnerability has been identified in IBM MQ. A remote user can exploit this vulnerability to trigger denial of service condition on the targeted system.

 
 
 
 

Impact

  • Denial of Service

System / Technologies affected

  • IBM MQ 9.1 LTS
  • IBM MQ 9.2 LTS
  • IBM MQ 9.3 LTS
  • IBM MQ 9.1 CD
  • IBM MQ 9.2 CD
  • IBM MQ 9.3 CD

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

GitLab 多個漏洞

發佈日期: 2022年11月07日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、彷冒、遠端執行任意程式碼、洩露敏感資料、跨網站指令碼及繞過保安限制。


影響

  • 資料洩露
  • 跨網站指令碼
  • 繞過保安限制
  • 阻斷服務
  • 遠端執行程式碼
  • 仿冒

受影響之系統或技術

  • GitLab Community Edition (CE) 15.5.2, 15.4.4 及 15.3.5 以前的版本
  • GitLab Enterprise Edition (EE) 15.5.2, 15.4.4 及 15.3.5 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

GitLab Multiple Vulnerabilities

Release Date: 7 Nov 2022

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, spoofing, remote code execution, sensitive information disclosure, cross-site scripting and security restriction bypass on the targeted system.


Impact

  • Information Disclosure
  • Cross-Site Scripting
  • Security Restriction Bypass
  • Denial of Service
  • Remote Code Execution
  • Spoofing

System / Technologies affected

  • GitLab Community Edition (CE) versions prior to 15.5.2, 15.4.4, and 15.3.5
  • GitLab Enterprise Edition (EE) versions prior to 15.5.2, 15.4.4, and 15.3.5

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2022年11月4日星期五

思科產品多個漏洞

發佈日期: 2022年11月04日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

在思科產品發現多個漏洞,遠端攻擊者可利用這些漏洞在目標系統觸發阻斷服務狀況、資料洩露、遠端執行程式碼、跨網站指令碼及權限提升。


影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼
  • 資料洩露
  • 跨網站指令碼

受影響之系統或技術

  • 思科 Email Security Appliance
  • 思科 Secure Email and Web Manager
  • 思科 Secure Web Appliance
  • 思科 Umbrella

 

詳情請參閱以下連結﹕

 


解決方案


漏洞識別碼


資料來源


相關連結

Cisco Products Multiple Vulnerabilities

Release Date: 4 Nov 2022

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities were identified in Cisco Products. A remote attacker could exploit some of these vulnerabilities to denial of service condition, information disclosure, remote code execution, cross-site scripting and elevation of privilege the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Information Disclosure
  • Cross-Site Scripting

System / Technologies affected

  • Cisco Email Security Appliance
  • Cisco Secure Email and Web Manager
  • Cisco Secure Web Appliance
  • Cisco Umbrella

 

Please refer to the link below for detail:

 


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2022年11月3日星期四

Fortinet 產品多個漏洞

發佈日期: 2022年11月03日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 Fortinet Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發洩露敏感資料、資料篡改及繞過保安限制。


影響

  • 篡改
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • FortiOS 運行 AV 引擎版本 6.2.168 及以下
  • FortiOS 運行 AV 引擎版本 6.4.274 及以下
  • FortiMail 運行 AV 引擎版本 6.2.168 及以下
  • FortiMail 運行 AV 引擎版本 6.4.274 及以下
  • FortiClient 運行 AV 引擎版本 6.2.168 及以下
  • FortiClient 運行 AV 引擎版本 6.4.274 及以下
  • FortiOS 版本 7.2.0
  • FortiOS 版本 7.0.0 至 7.0.6
  • FortiOS 版本 6.4.0 至 6.4.9

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Fortinet Products Multiple Vulnerabilities

Release Date: 3 Nov 2022

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.


Impact

  • Data Manipulation
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • FortiOS running AV engine version 6.2.168 and below.
  • FortiOS running AV engine version 6.4.274 and below.
  • FortiMail running AV engine version 6.2.168 and below.
  • FortiMail running AV engine version 6.4.274 and below.
  • FortiClient running AV engine version 6.2.168 and below.
  • FortiClient running AV engine version 6.4.274 and below.
  • FortiOS version 7.2.0
  • FortiOS version 7.0.0 through 7.0.6
  • FortiOS version 6.4.0 through 6.4.9

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Linux 內核多個漏洞

發佈日期: 2022年11月03日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼及洩露敏感資料。

 


影響

  • 阻斷服務
  • 權限提升
  • 資料洩露
  • 遠端執行程式碼

受影響之系統或技術

  • openSUSE Leap 15.4
  • Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.0 aarch64
  • Red Hat CodeReady Linux Builder for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.0 s390x
  • Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x
  • Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.0 ppc64le
  • Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le
  • Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.0 x86_64
  • Red Hat CodeReady Linux Builder for x86_64 9 x86_64
  • Red Hat Enterprise Linux Desktop 7 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.0 aarch64
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.0 s390x
  • Red Hat Enterprise Linux for IBM z Systems 7 s390x
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, big endian 7 ppc64
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.0 ppc64le
  • Red Hat Enterprise Linux for Power, little endian 7 ppc64le
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for Real Time - Telecommunications Update Service 8.2 x86_64
  • Red Hat Enterprise Linux for Real Time 7 x86_64
  • Red Hat Enterprise Linux for Real Time 9 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV - Telecommunications Update Service 8.2 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV 7 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV 9 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV for x86_64 - 4 years of updates 9.0 x86_64
  • Red Hat Enterprise Linux for Real Time for x86_64 - 4 years of updates 9.0 x86_64
  • Red Hat Enterprise Linux for Scientific Computing 7 x86_64
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.0 x86_64
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.2 x86_64
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.2 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.2 x86_64
  • Red Hat Enterprise Linux Server 7 x86_64
  • Red Hat Enterprise Linux Server for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux Server for IBM z Systems - 4 years of updates 9.0 s390x
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.2 ppc64le
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux Workstation 7 x86_64
  • Red Hat Virtualization Host 4 for RHEL 7 x86_64
  • SUSE Linux Enterprise Desktop 15-SP4
  • SUSE Linux Enterprise High Availability 15-SP4
  • SUSE Linux Enterprise High Performance Computing
  • SUSE Linux Enterprise High Performance Computing 15-SP4
  • SUSE Linux Enterprise Micro 5.3
  • SUSE Linux Enterprise Module for Basesystem 15-SP4
  • SUSE Linux Enterprise Module for Development Tools 15-SP4
  • SUSE Linux Enterprise Module for Legacy Software 15-SP4
  • SUSE Linux Enterprise Module for Live Patching 15-SP4
  • SUSE Linux Enterprise Server
  • SUSE Linux Enterprise Server 15-SP4
  • SUSE Linux Enterprise Server for SAP Applications
  • SUSE Linux Enterprise Server for SAP Applications 15-SP4
  • SUSE Linux Enterprise Workstation Extension 15-SP4
  • SUSE Manager Proxy 4.3
  • SUSE Manager Retail Branch Server 4.3
  • SUSE Manager Server 4.3
     

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

對於 RedHat

安裝供應商提供的修補程式:

 

對於 SUSE

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Linux Kernel Multiple Vulnerabilities

Release Date: 3 Nov 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution and sensitive information disclosure on the targeted system.

 


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Remote Code Execution

System / Technologies affected

  • openSUSE Leap 15.4
  • Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.0 aarch64
  • Red Hat CodeReady Linux Builder for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.0 s390x
  • Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x
  • Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.0 ppc64le
  • Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le
  • Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.0 x86_64
  • Red Hat CodeReady Linux Builder for x86_64 9 x86_64
  • Red Hat Enterprise Linux Desktop 7 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.0 aarch64
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.0 s390x
  • Red Hat Enterprise Linux for IBM z Systems 7 s390x
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, big endian 7 ppc64
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.0 ppc64le
  • Red Hat Enterprise Linux for Power, little endian 7 ppc64le
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for Real Time - Telecommunications Update Service 8.2 x86_64
  • Red Hat Enterprise Linux for Real Time 7 x86_64
  • Red Hat Enterprise Linux for Real Time 9 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV - Telecommunications Update Service 8.2 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV 7 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV 9 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV for x86_64 - 4 years of updates 9.0 x86_64
  • Red Hat Enterprise Linux for Real Time for x86_64 - 4 years of updates 9.0 x86_64
  • Red Hat Enterprise Linux for Scientific Computing 7 x86_64
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.0 x86_64
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.2 x86_64
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.2 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.2 x86_64
  • Red Hat Enterprise Linux Server 7 x86_64
  • Red Hat Enterprise Linux Server for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux Server for IBM z Systems - 4 years of updates 9.0 s390x
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.2 ppc64le
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux Workstation 7 x86_64
  • Red Hat Virtualization Host 4 for RHEL 7 x86_64
  • SUSE Linux Enterprise Desktop 15-SP4
  • SUSE Linux Enterprise High Availability 15-SP4
  • SUSE Linux Enterprise High Performance Computing
  • SUSE Linux Enterprise High Performance Computing 15-SP4
  • SUSE Linux Enterprise Micro 5.3
  • SUSE Linux Enterprise Module for Basesystem 15-SP4
  • SUSE Linux Enterprise Module for Development Tools 15-SP4
  • SUSE Linux Enterprise Module for Legacy Software 15-SP4
  • SUSE Linux Enterprise Module for Live Patching 15-SP4
  • SUSE Linux Enterprise Server
  • SUSE Linux Enterprise Server 15-SP4
  • SUSE Linux Enterprise Server for SAP Applications
  • SUSE Linux Enterprise Server for SAP Applications 15-SP4
  • SUSE Linux Enterprise Workstation Extension 15-SP4
  • SUSE Manager Proxy 4.3
  • SUSE Manager Retail Branch Server 4.3
  • SUSE Manager Server 4.3
     

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

For RedHat

Apply fixes issued by the vendor:

 

For SUSE

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2022年11月2日星期三

OpenSSL 多個漏洞

發佈日期: 2022年11月02日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

於 OpenSSL 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行任意程式碼。


影響

  • 阻斷服務
  • 遠端執行程式碼

受影響之系統或技術

  • OpenSSL 3.0.0 至 3.0.6 版本

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

更新至:

  • 3.0.7 版本

 

由於 OpenSSL 以原始碼分佈在各種產品中,我們建議用戶可以從供應商網站查看使用中的產品是否與漏洞相關並進行相應更新。


漏洞識別碼


資料來源


相關連結

OpenSSL Multiple Vulnerabilities

Release Date: 2 Nov 2022

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities were identified in OpenSSL. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • OpenSSL versions 3.0.0 to 3.0.6

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Update to:

  • Version 3.0.7

 

Since OpenSSL is distributed as source code in various products, users are recommended to review if the products in-use are related to the vulerabilities via vendors' website and update accordingly.


Vulnerability Identifier


Source


Related Link

2022年11月1日星期二

蘋果產品多個漏洞

發佈日期: 2022年11月01日

風險: 高度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於蘋果產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、彷冒、遠端執行任意程式碼、洩露敏感資料、資料篡改及繞過保安限制。

 

注意:

對於 CVE-2022-42827,Apple 指有報告稱此漏洞可能已被積極利用。


影響

  • 阻斷服務
  • 權限提升
  • 仿冒
  • 遠端執行程式碼
  • 資料洩露
  • 篡改
  • 繞過保安限制

受影響之系統或技術

  • iOS 15.7.1 及 iPadOS 15.7.1 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

  • iOS 15.7.1 及 iPadOS 15.7.1 

漏洞識別碼


資料來源


相關連結

Apple Products Multiple Vulnerabilities

Release Date: 1 Nov 2022

RISK: High Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Apple Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, spoofing, remote code execution, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.

 

Note:

For CVE-2022-42827, Apple is aware of a report that this issue may have been actively exploited.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Spoofing
  • Remote Code Execution
  • Information Disclosure
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

  • Versions prior to iOS 15.7.1 and iPadOS 15.7.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • iOS 15.7.1 and iPadOS 15.7.1

Vulnerability Identifier


Source


Related Link

Microsoft Edge 篡改漏洞

發佈日期: 2022年11月01日

風險: 高度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Microsoft Edge 發現一個漏洞。遠端攻擊者可利用這個漏洞,於目標系統觸發篡改。

 

注意:

CVE-2022-3723 漏洞正被廣泛利用。


影響

  • 篡改

受影響之系統或技術

  • Microsoft Edge 107.0.1418.26 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 107.0.1418.26 版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Data Manipulation Vulnerability

Release Date: 1 Nov 2022

RISK: High Risk

TYPE: Clients - Browsers

TYPE: Browsers

A vulnerability has been identified in Microsoft Edge. A remote attacker could exploit this vulnerability to trigger data manipulation on the targeted system.

 

Note:

CVE-2022-3723 is being exploited in the wild.


Impact

  • Data Manipulation

System / Technologies affected

  • Microsoft Edge prior to 107.0.1418.26

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 107.0.1418.26

Vulnerability Identifier


Source


Related Link

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...