2023年2月8日星期三

SUSE Linux Kernel Multiple Vulnerabilities

Last Update Date: 8 Feb 2023 Release Date: 7 Feb 2023

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in SUSE Linux. A attacker could exploit some of these vulnerabilities to trigger denial of service condition and elevation of privilege on the targeted system.

 

[Updated on 2023-02-08] 

Updated System / Technologies affected, Solutions, Vulnerability Identifier and Related Links.


Impact

  • Denial of Service
  • Elevation of Privilege

System / Technologies affected

  • SUSE Linux Enterprise High Performance Computing 15-SP1
  • SUSE Linux Enterprise High Performance Computing 15-SP2
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise High Performance Computing 15-SP4
  • SUSE Linux Enterprise Live Patching 12-SP4
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Module for Live Patching 15-SP1
  • SUSE Linux Enterprise Module for Live Patching 15-SP2
  • SUSE Linux Enterprise Module for Live Patching 15-SP3
  • SUSE Linux Enterprise Module for Live Patching 15-SP4
  • SUSE Linux Enterprise Server 15-SP1
  • SUSE Linux Enterprise Server 15-SP2
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server 15-SP4
  • SUSE Linux Enterprise Server for SAP Applications 15-SP1
  • SUSE Linux Enterprise Server for SAP Applications 15-SP2
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15-SP4

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2023年2月7日星期二

IBM MQ 阻斷服務漏洞

發佈日期: 2023年02月07日

風險: 中度風險

類型: 伺服器 - 網絡管理

類型: 網絡管理

於 IBM MQ 發現一個漏洞。遠端使用者可利用此漏洞,於目標系統觸發阻斷服務狀況。


影響

  • 阻斷服務

受影響之系統或技術

  • IBM MQ 9.2 LTS
  • IBM MQ 9.3 LTS
  • IBM MQ 9.2 CD
  • IBM MQ 9.3 CD

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

IBM MQ Denial of Service Vulnerability

Release Date: 7 Feb 2023

RISK: Medium Risk

TYPE: Servers - Network Management

TYPE: Network Management

A vulnerability has been identified in IBM MQ. A remote user can exploit this vulnerability to trigger denial of service condition on the targeted system.


Impact

  • Denial of Service

System / Technologies affected

  • IBM MQ 9.2 LTS
  • IBM MQ 9.3 LTS
  • IBM MQ 9.2 CD
  • IBM MQ 9.3 CD

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Android多個漏洞

發佈日期: 2023年02月07日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於 Android 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及洩露敏感資料。


Android Multiple Vulnerabilities

Release Date: 7 Feb 2023

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Android. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and sensitive information disclosure on the targeted system.


ChromeOS 多個漏洞

發佈日期: 2023年02月07日

風險: 中度風險

類型: 操作系統 - 其他操作系統

類型: 其他操作系統

於 ChromeOS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 阻斷服務

受影響之系統或技術

  • LTS-102, 102.0.5005.196 之前的版本(平台版本:14695.1782.0)

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

 


漏洞識別碼


資料來源


相關連結

ChromeOS Multiple Vulnerabilities

Release Date: 7 Feb 2023

RISK: Medium Risk

TYPE: Operating Systems - Others OS

TYPE: Others OS

Multiple vulnerabilities were identified in ChromeOS. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service

System / Technologies affected

  • Version prior to LTS-102, 102.0.5005.196 (Platform Version: 14695.1782.0)

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

 


Vulnerability Identifier


Source


Related Link

SUSE Linux 內核多個漏洞

發佈日期: 2023年02月07日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 SUSE Linux 發現多個漏洞。攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及權限提升。


影響

  • 阻斷服務
  • 權限提升

受影響之系統或技術

  • SUSE Linux Enterprise High Performance Computing 15-SP1
  • SUSE Linux Enterprise High Performance Computing 15-SP2
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise Live Patching 12-SP4
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Module for Live Patching 15-SP1
  • SUSE Linux Enterprise Module for Live Patching 15-SP2
  • SUSE Linux Enterprise Module for Live Patching 15-SP3
  • SUSE Linux Enterprise Server 15-SP1
  • SUSE Linux Enterprise Server 15-SP2
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15-SP1
  • SUSE Linux Enterprise Server for SAP Applications 15-SP2
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

SUSE Linux Kernel Multiple Vulnerabilities

Release Date: 7 Feb 2023

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in SUSE Linux. A attacker could exploit some of these vulnerabilities to trigger denial of service condition and elevation of privilege on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege

System / Technologies affected

  • SUSE Linux Enterprise High Performance Computing 15-SP1
  • SUSE Linux Enterprise High Performance Computing 15-SP2
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise Live Patching 12-SP4
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Module for Live Patching 15-SP1
  • SUSE Linux Enterprise Module for Live Patching 15-SP2
  • SUSE Linux Enterprise Module for Live Patching 15-SP3
  • SUSE Linux Enterprise Server 15-SP1
  • SUSE Linux Enterprise Server 15-SP2
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15-SP1
  • SUSE Linux Enterprise Server for SAP Applications 15-SP2
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

OpenSSH 多個漏洞

發佈日期: 2023年02月07日

風險: 中度風險

類型: 伺服器 - 網絡管理

類型: 網絡管理

於 OpenSSH 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行任意程式碼。


影響

  • 阻斷服務
  • 遠端執行程式碼

受影響之系統或技術

  • OpenSSH 9.1 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

OpenSSH Multiple Vulnerabilities

Release Date: 7 Feb 2023

RISK: Medium Risk

TYPE: Servers - Network Management

TYPE: Network Management

Multiple vulnerabilities were identified in OpenSSH. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Version prior to OpenSSH 9.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Microsoft Edge 資料篡改漏洞

發佈日期: 2023年02月06日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Microsoft Edge 發現一個漏洞。遠端攻擊者可利用這個漏洞,於目標系統觸發資料篡改。

 

注意:

CVE-2023-21720的概念驗證碼已被公開。


影響

  • 篡改

受影響之系統或技術

  • Microsoft Edge 109.0.1518.78之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 109.0.1518.78 或之後版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Data Manipulation Vulnerability

Release Date: 6 Feb 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

A vulnerability was identified in Microsoft Edge. A remote attacker could exploit this vulnerability to trigger data manipulation on the targeted system.

 

Note:

  • Proof Of Concept Exploit Code is Publicly Available for CVE-2023-21720.

Impact

  • Data Manipulation

System / Technologies affected

  • Microsoft Edge prior to 109.0.1518.78

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 109.0.1518.78 or later

Vulnerability Identifier


Source


Related Link

2023年2月4日星期六

F5 產品多個漏洞

發佈日期: 2023年02月03日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 F5 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行程式碼。

 


影響

  • 阻斷服務
  • 遠端執行程式碼

受影響之系統或技術

BIG-IP

  • 17.0.0
  • 16.1.0 - 16.1.3
  • 15.1.0 - 15.1.8
  • 14.1.0 - 14.1.5
  • 13.1.0 - 13.1.5

 

BIG-IP APM Clients

  • 7.2.2 - 7.2.3

 

BIG-IP SPK

  • 1.6.0

 

BIG-IQ Centralized Management

  • 8.0.0 - 8.2.0
  • 7.1.0

 

F5OS-A

  • 1.2.0
  • 1.1.0 - 1.1.1
  • 1.0.0 - 1.0.1

 

F5OS-C

  • 1.3.0 - 1.3.2

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

F5 Products Multiple Vulnerabilities

Release Date: 3 Feb 2023

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in F5 Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service and remote code execution on the targeted system.

 


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

BIG-IP

  • 17.0.0
  • 16.1.0 - 16.1.3
  • 15.1.0 - 15.1.8
  • 14.1.0 - 14.1.5
  • 13.1.0 - 13.1.5

 

BIG-IP APM Clients

  • 7.2.2 - 7.2.3

 

BIG-IP SPK

  • 1.6.0

 

BIG-IQ Centralized Management

  • 8.0.0 - 8.2.0
  • 7.1.0

 

F5OS-A

  • 1.2.0
  • 1.1.0 - 1.1.1
  • 1.0.0 - 1.0.1

 

F5OS-C

  • 1.3.0 - 1.3.2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

微軟每月保安更新 (2022年10月)

最後更新 2023年02月03日 發佈日期: 2022年10月12日

風險: 高度風險

類型: 操作系統 - 視窗操作系統

類型: 視窗操作系統

微軟已為產品提供本月保安更新:

 

受影響產品風險程度影響備註
視窗高度風險 高度風險遠端執行程式碼
阻斷服務
仿冒
權限提升
資料洩露
繞過保安限制

CVE-2022-41033

正被廣泛利用

 

CVE-2022-34689

的概念驗證碼已被公開

延伸安全性更新 (ESU)中度風險 中度風險遠端執行程式碼
阻斷服務
仿冒
權限提升
資料洩露
繞過保安限制
 
Azure中度風險 中度風險仿冒
權限提升
 
瀏覽器低度風險 低度風險仿冒 
System Center中度風險 中度風險權限提升 
微軟 Office中度風險 中度風險遠端執行程式碼
仿冒
資料洩露
 
開發者工具中度風險 中度風險權限提升
遠端執行程式碼
資料洩露
 

 

「極高度風險」產品數目:0

「高度風險」產品數目:1

「中度風險」產品數目:5

「低度風險」產品數目:1

整體「風險程度」評估:高度風險

 

 

[Updated on 2023-02-03]

CVE-2022-34689 的概念驗證碼已被公開。


影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露
  • 仿冒

受影響之系統或技術

  • 視窗
  • 延伸安全性更新 (ESU)
  • Azure
  • 瀏覽器
  • System Center
  • 微軟 Office
  • 開發者工具

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 安裝軟件供應商提供的修補程式。

漏洞識別碼


資料來源


相關連結

Microsoft Monthly Security Update (October 2022)

Last Update Date: 3 Feb 2023 Release Date: 12 Oct 2022

RISK: High Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
WindowsHigh Risk High RiskRemote Code Execution
Denial of Service
Spoofing
Elevation of Privilege
Information Disclosure
Security Restriction Bypass

CVE-2022-41033

is being exploited in the wild

 

Proof of Concept exploit code Is publicly available for CVE-2022-34689

Extended Security Updates (ESU)Medium Risk Medium RiskRemote Code Execution
Denial of Service
Spoofing
Elevation of Privilege
Information Disclosure
Security Restriction Bypass
 
AzureMedium Risk Medium RiskSpoofing
Elevation of Privilege
 
BrowserLow Risk Low RiskSpoofing 
System CenterMedium Risk Medium RiskElevation of Privilege 
Microsoft OfficeMedium Risk Medium RiskRemote Code Execution
Spoofing
Information Disclosure
 
Developer ToolsMedium Risk Medium RiskElevation of Privilege
Remote Code Execution
Information Disclosure
 

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 1

Number of 'Medium Risk' product(s): 5

Number of 'Low Risk' product(s): 1

Evaluation of overall 'Risk Level': High Risk

 

 

[Updated on 2023-02-03]

Proof of Concept exploit code Is publicly available for CVE-2022-34689.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure
  • Spoofing

System / Technologies affected

  • Windows
  • Extended Security Updates (ESU)
  • Azure
  • Browser
  • System Center
  • Microsoft Office
  • Developer Tools

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

2023年2月2日星期四

IBM WebSphere Application Server 遠端執行程式碼漏洞

發佈日期: 2023年02月02日

風險: 中度風險

類型: 伺服器 - 互聯網應用伺服器

類型: 互聯網應用伺服器

於 IBM WebSphere Application Server 發現一個漏洞。遠端使用者可利用此漏洞,於目標系統觸發遠端執行任意程式碼。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • IBM WebSphere Application Server 9.0 版本
  • IBM WebSphere Application Server 8.5. 版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

IBM WebSphere Application Server Remote Code Execution Vulnerability

Release Date: 2 Feb 2023

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

A vulnerability was identified in IBM WebSphere Application Server. A remote user can exploit this vulnerability to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • IBM WebSphere Application Server version 9.0
  • IBM WebSphere Application Server version 8.5

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Mozilla Thunderbird 繞過保安限制漏洞

發佈日期: 2023年02月02日

風險: 中度風險

類型: 用戶端 - 電郵用戶端

類型: 電郵用戶端

於 Mozilla Thunderbird 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發繞過保安限制。


影響

  • 繞過保安限制

受影響之系統或技術

  • Thunderbird 102.7.1 之前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

 

  • 更新至版本 102.7.1

漏洞識別碼


資料來源


相關連結

Mozilla Thunderbird Security Restriction Bypass Vulnerability

Release Date: 2 Feb 2023

RISK: Medium Risk

TYPE: Clients - Email Clients

TYPE: Email Clients

A vulnerability was identified in Mozilla Thunderbird. A remote attacker can exploit this vulnerability to trigger security restriction bypass on the targeted system.


Impact

  • Security Restriction Bypass

System / Technologies affected

  • Thunderbird version prior to 102.7.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

  • Update to version 102.7.1

Vulnerability Identifier


Source


Related Link

ISC BIND 多個漏洞

發佈日期: 2023年02月02日

風險: 中度風險

類型: 伺服器 - 網絡管理

類型: 網絡管理

於BIND發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況。


影響

  • 阻斷服務

受影響之系統或技術

  • BIND 9.16.12 至 9.16.36
  • BIND 9.18.0 至 9.18.10
  • BIND 9.19.0 至 9.19.8
  • BIND Supported Preview Edition 9.11.4-S1 至 9.11.37-S1
  • BIND Supported Preview Edition 9.16.8-S1 至 9.16.36-S1

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

  • BIND 9.16.37
  • BIND 9.18.11
  • BIND 9.19.9
  • BIND 9.16.37-S1

漏洞識別碼


資料來源


相關連結

ISC BIND Multiple Vulnerabilities

Release Date: 2 Feb 2023

RISK: Medium Risk

TYPE: Servers - Network Management

TYPE: Network Management

Multiple vulnerabilities were identified in BIND. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition on the targeted system.


Impact

  • Denial of Service

System / Technologies affected

  • BIND 9.16.12 to 9.16.36
  • BIND 9.18.0 to 9.18.10
  • BIND 9.19.0 to 9.19.8
  • BIND Supported Preview Edition 9.11.4-S1 to 9.11.37-S1
  • BIND Supported Preview Edition 9.16.8-S1 to 9.16.36-S1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • BIND 9.16.37
  • BIND 9.18.11
  • BIND 9.19.9
  • BIND 9.16.37-S1

Vulnerability Identifier


Source


Related Link

2023年2月1日星期三

ChromeOS 多個漏洞

發佈日期: 2023年02月01日

風險: 中度風險

類型: 操作系統 - 其他操作系統

類型: 其他操作系統

於 ChromeOS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行程式碼及敏感資料洩露。


影響

  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • LTS-108, 108.0.5359.219 之前的版本(平台版本:15183.82.0)

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

 


漏洞識別碼


資料來源


相關連結

ChromeOS Multiple Vulnerabilities

Release Date: 1 Feb 2023

RISK: Medium Risk

TYPE: Operating Systems - Others OS

TYPE: Others OS

Multiple vulnerabilities were identified in ChromeOS. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and sensitive information disclosure on the targeted system.


Impact

  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Version prior to LTC-108, 108.0.5359.219 (Platform Version: 15183.82.0)

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

 


Vulnerability Identifier


Source


Related Link

VMWare vRealize Log Insight 多個漏洞

最後更新 2023年02月01日 發佈日期: 2023年01月26日

風險: 高度風險

類型: 操作系統 - 網絡操作系統

類型: 網絡操作系統

於 VMware vRealize Log Insight 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行阻斷服務、任意程式碼及洩露敏感資料。

 

[Updated on 2023-02-01]

CVE-2022-31704、CVE-2022-31706 及 CVE-2022-31711 的概念驗證碼已被公開。風險程度由中度風險更改至高度風險。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • VMware vRealize Log Insight 8.x

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

VMWare vRealize Log Insight Multiple Vulnerabilities

Last Update Date: 1 Feb 2023 Release Date: 26 Jan 2023

RISK: High Risk

TYPE: Operating Systems - VM Ware

TYPE: VM Ware

Multiple vulnerabilities were identified in VMware vRealize Log Insight. A remote attacker could exploit some of these vulnerabilities to trigger denial of service, remote code execution and sensitive information disclosure on the targeted system.

 

[Updated on 2023-02-01]

Proof of Concept exploit code Is publicly available for CVE-2022-31704, CVE-2022-31706, and CVE-2022-31711. Risk level has changed from Medium Risk to High Risk.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • VMware vRealize Log Insight 8.x

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2023年1月31日星期二

QNAP NAS 遠端執行程式碼漏洞

發佈日期: 2023年01月31日

風險: 高度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 QNAP NAS 發現一個漏洞。遠端攻擊者可利用這個漏洞,於目標系統觸發遠端執行任意程式碼。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • QTS 5.0.1
  • QuTS hero h5.0.1

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 


漏洞識別碼


資料來源


相關連結

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...