2022年4月20日星期三

Linux Kernel Multiple Vulnerabilities

Release Date: 20 Apr 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, remote code execution, sensitive information disclosure and data manipulation on the targeted system.


Impact

  • Information Disclosure
  • Elevation of Privilege
  • Data Manipulation
  • Remote Code Execution

System / Technologies affected

  • openSUSE Leap 15.3
  • openSUSE Leap 15.4
  • SUSE Enterprise Storage 7
  • SUSE Linux Enterprise Desktop 12-SP5
  • SUSE Linux Enterprise Desktop 15-SP3
  • SUSE Linux Enterprise High Availability 12-SP5
  • SUSE Linux Enterprise High Availability 15-SP2
  • SUSE Linux Enterprise High Availability 15-SP3
  • SUSE Linux Enterprise High Performance Computing
  • SUSE Linux Enterprise High Performance Computing 12-SP5
  • SUSE Linux Enterprise High Performance Computing 15-SP2
  • SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS
  • SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Micro 5.0
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Micro 5.2
  • SUSE Linux Enterprise Module for Basesystem 15-SP3
  • SUSE Linux Enterprise Module for Development Tools 15-SP3
  • SUSE Linux Enterprise Module for Legacy Software 15-SP3
  • SUSE Linux Enterprise Module for Live Patching 15-SP2
  • SUSE Linux Enterprise Module for Live Patching 15-SP3
  • SUSE Linux Enterprise Realtime Extension 15-SP2
  • SUSE Linux Enterprise Server
  • SUSE Linux Enterprise Server 12-SP5
  • SUSE Linux Enterprise Server 15-SP2
  • SUSE Linux Enterprise Server 15-SP2-BCL
  • SUSE Linux Enterprise Server 15-SP2-LTSS
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server for SAP 15-SP2
  • SUSE Linux Enterprise Server for SAP Applications
  • SUSE Linux Enterprise Server for SAP Applications 12-SP5
  • SUSE Linux Enterprise Server for SAP Applications 15-SP2
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • SUSE Linux Enterprise Software Development Kit 12-SP5
  • SUSE Linux Enterprise Workstation Extension 12-SP5
  • SUSE Linux Enterprise Workstation Extension 15-SP3
  • SUSE Manager Proxy 4.1
  • SUSE Manager Proxy 4.2
  • SUSE Manager Retail Branch Server 4.1
  • SUSE Manager Retail Branch Server 4.2
  • SUSE Manager Server 4.1
  • SUSE Manager Server 4.2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

甲骨文產品多個漏洞

發佈日期: 2022年04月20日

風險: 中度風險

類型: 伺服器 - 數據庫伺服器

類型: 數據庫伺服器

於甲骨文產品發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行程式碼、繞過保安限制、洩露敏感資料及資料篡改。


影響

  • 阻斷服務
  • 篡改
  • 遠端執行程式碼
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • MySQL
  • Java SE
  • Oracle Database Server
  • WebLogic Server
  • VirtualBox

 

有關其他 甲骨文 產品,請參閱以下連結:

https://www.oracle.com/security-alerts/cpuapr2022.html


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

甲骨文 Critical Patch Update Advisory


漏洞識別碼


資料來源


相關連結

Oracle Products Multiple Vulnerabilities

Release Date: 20 Apr 2022

RISK: Medium Risk

TYPE: Servers - Database Servers

TYPE: Database Servers

Multiple vulnerabilities were identified in Oracle Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, security restriction bypass, sensitive information disclosure and data manipulation and on the targeted system.


Impact

  • Denial of Service
  • Data Manipulation
  • Remote Code Execution
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • MySQL
  • Java SE
  • Oracle Database Server
  • WebLogic Server
  • VirtualBox

 

For other Oracle products, please refer to the link below:

https://www.oracle.com/security-alerts/cpuapr2022.html


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

Oracle Critical Patch Update Advisory


Vulnerability Identifier


Source


Related Link

2022年4月19日星期二

Google Chrome 遠端執行程式碼漏洞

發佈日期: 2022年04月19日

風險: 極高度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現一個漏洞。遠端使用者可利用此漏洞,於目標系統觸發遠端執行任意程式碼。

 

注意
CVE-2022-1364 漏洞正被廣泛利用。

該漏洞與處理  JavaScript 代碼的 V8 JavaScript 引擎有關。 該漏洞可以利用 V8 引擎將 JS 物件視為 JS 陣列,並在目標系統上運行任意程式碼。

 


影響

  • 遠端執行程式碼

受影響之系統或技術

  • Google Chrome 100.0.4896.127 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 100.0.4896.127 版本

漏洞識別碼


資料來源


相關連結

Google Chrome Remote Code Execution Vulnerability

Release Date: 19 Apr 2022

RISK: Extremely High Risk

TYPE: Clients - Browsers

TYPE: Browsers

A vulnerability was identified in Google Chrome. A remote user can exploit this vulnerability to trigger remote code execution on the targeted system.

 

Note:
CVE-2022-1364 is being exploited in the wild.

The vulnerability is related to the V8 JavaScript engine to process JavaScript code. The vulnerability can exploit the V8 engine to treat a JS object as an JS array and run arbitrary code on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • Google Chrome prior to 100.0.4896.127

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 100.0.4896.127

Vulnerability Identifier


Source


Related Link

Microsoft Edge 多個漏洞

發佈日期: 2022年04月19日

風險: 極高度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端使用者可利用這些漏洞,於目標系統觸發權限提升、遠端執行任意程式碼、繞過保安限制及敏感資料洩露。

 

注意
CVE-2022-1364 漏洞正被廣泛利用。

該漏洞與處理  JavaScript 代碼的 V8 JavaScript 引擎有關。 該漏洞可以利用 V8 引擎將 JS 物件視為 JS 陣列,並在目標系統上運行任意代碼。


Microsoft Edge Multiple Vulnerabilities

Release Date: 19 Apr 2022

RISK: Extremely High Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote user can exploit these vulnerabilities to trigger elevation of privilege, remote code execution, security restriction bypass and sensitive information disclosure on the targeted system.

 

Note:
CVE-2022-1364 is being exploited in the wild.

The vulnerability is related to the V8 JavaScript engine to process JavaScript code. The vulnerability can exploit the V8 engine to treat a JS object as an JS array and run arbitrary code on the targeted system.


2022年4月14日星期四

Apache Struts 遠端執行程式碼漏洞

發佈日期: 2022年04月14日

風險: 中度風險

類型: 伺服器 - 網站伺服器

類型: 網站伺服器

於 Apache Struts 發現一個漏洞。遠端使用者可利用此漏洞,於目標系統觸發遠端執行任意程式碼。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • Struts 2.0.0 - Struts 2.5.29

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 軟件供應商已發佈修補程式 (更新至 Struts 2.5.30 或更高版本)

漏洞識別碼


資料來源


相關連結

Apache Struts Remote Code Execution Vulnerability

Release Date: 14 Apr 2022

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

A vulnerability has been identified in Apache Struts. A remote user can exploit this vulnerability to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • Struts 2.0.0 - Struts 2.5.29

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (upgrade to Struts 2.5.30 or greater)

Vulnerability Identifier


Source


Related Link

2022年4月13日星期三

Adobe 每月保安更新 (2022年4月)

發佈日期: 2022年04月13日

風險: 中度風險

類型: 用戶端 - 辦公室應用

類型: 辦公室應用

Adobe已為產品提供本月保安更新:

 

受影響產品風險程度影響備註詳情(包括 CVE)
Adobe Commerce中度風險 中度風險遠端執行程式碼 APSB22-13
Adobe Acrobat and Reader中度風險 中度風險資料洩露
遠端執行程式碼
權限提升
繞過保安限制
 APSB22-16
Adobe After Effects中度風險 中度風險遠端執行程式碼 APSB22-19
Adobe Photoshop中度風險 中度風險遠端執行程式碼 APSB22-20

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:4

「低度風險」產品數目:0

整體「風險程度」評估:中度風險


影響

  • 遠端執行程式碼
  • 資料洩露
  • 權限提升
  • 繞過保安限制

受影響之系統或技術

  • Adobe Commerce 2.4.3-p1 及以前版本
  • Adobe Commerce 2.3.7-p2 及以前版本
  • Magento Open Source 2.4.3-p1 及以前版本
  • Magento Open Source 2.3.7-p2 及以前版本
  • Acrobat DC 22.001.20085 及以前版本
  • Acrobat Reader DC 22.001.20085 及以前版本
  • Acrobat 2020 20.005.30314 及以前版本
  • Acrobat Reader 2020 20.005.30314 及以前版本
  • Acrobat 2017 17.012.30205 及以前版本
  • Acrobat Reader 2017 17.012.30205  及以前版本
  • Adobe After Effects 22.2.1 及以前版本
  • Adobe After Effects 18.4.5 及以前版本
  • Photoshop 2021 22.5.6 及以前版本
  • Photoshop 2022 23.2.2 及以前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 安裝供應商提供的修補程式。個別產品詳情可參考上表「詳情」一欄或執行軟件更新。

漏洞識別碼


資料來源


相關連結

Adobe Monthly Security Update (April 2022)

Release Date: 13 Apr 2022

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
Adobe CommerceMedium Risk Medium RiskRemote Code Execution APSB22-13
Adobe Acrobat and ReaderMedium Risk Medium RiskInformation Disclosure
Remote Code Execution
Elevation of Privilege
Security Restriction Bypass
 APSB22-16
Adobe After EffectsMedium Risk Medium RiskRemote Code Execution APSB22-19
Adobe PhotoshopMedium Risk Medium RiskRemote Code Execution APSB22-20

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 4

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Remote Code Execution
  • Information Disclosure
  • Elevation of Privilege
  • Security Restriction Bypass

System / Technologies affected

  • Adobe Commerce 2.4.3-p1 and earlier versions
  • Adobe Commerce 2.3.7-p2 and earlier versions
  • Magento Open Source 2.4.3-p1 and earlier versions
  • Magento Open Source 2.3.7-p2 and earlier versions
  • Acrobat DC 22.001.20085 and earlier versions
  • Acrobat Reader DC 22.001.20085 and earlier versions
  • Acrobat 2020 20.005.30314 and earlier versions
  • Acrobat Reader 2020 20.005.30314 and earlier versions
  • Acrobat 2017 17.012.30205 and earlier versions
  • Acrobat Reader 2017 17.012.30205  and earlier versions
  • Adobe After Effects 22.2.1 and earlier versions
  • Adobe After Effects 18.4.5 and earlier versions
  • Photoshop 2021 22.5.6 and earlier versions
  • Photoshop 2022 23.2.2 and earlier versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update

Vulnerability Identifier


Source


Related Link

微軟每月保安更新 (2022年4月)

發佈日期: 2022年04月13日

風險: 高度風險

類型: 操作系統 - 視窗操作系統

類型: 視窗操作系統

微軟已為產品提供本月保安更新:

 

受影響產品風險程度影響備註
視窗高度風險 高度風險遠端執行程式碼
阻斷服務
權限提升
資料洩露
延伸安全性更新 (ESU)高度風險 高度風險遠端執行程式碼
權限提升
阻斷服務
資料洩露
SQL Server低度風險 低度風險仿冒 
開發者工具中度風險 中度風險權限提升
阻斷服務
 
微軟 Office中度風險 中度風險遠端執行程式碼
仿冒
資料洩露
 
瀏覽器中度風險 中度風險仿冒
權限提升
 
System Center中度風險 中度風險阻斷服務 
Azure中度風險 中度風險資料洩露
遠端執行程式碼
 
微軟 Dynamics中度風險 中度風險遠端執行程式碼 

 

「極高度風險」產品數目:0

「高度風險」產品數目:2

「中度風險」產品數目:6

「低度風險」產品數目:1

整體「風險程度」評估:高度風險


影響

  • 遠端執行程式碼
  • 權限提升
  • 阻斷服務
  • 資料洩露
  • 仿冒

受影響之系統或技術

  • 視窗
  • 延伸安全性更新 (ESU)
  • SQL Server
  • 開發者工具
  • 微軟 Office
  • 瀏覽器
  • System Center
  • Azure
  • 微軟 Dynamics

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 安裝軟件供應商提供的修補程式。

漏洞識別碼


資料來源


相關連結

Microsoft Monthly Security Update (April 2022)

Release Date: 13 Apr 2022

RISK: High Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
WindowsHigh Risk High RiskRemote Code Execution
Denial of Service
Elevation of Privilege
Information Disclosure
Extended Security Updates (ESU)High Risk High RiskRemote Code Execution
Elevation of Privilege
Denial of Service
Information Disclosure
SQL ServerLow Risk Low RiskSpoofing 
Developer ToolsMedium Risk Medium RiskElevation of Privilege
Denial of Service
 
Microsoft OfficeMedium Risk Medium RiskRemote Code Execution
Spoofing
Information Disclosure
 
BrowserMedium Risk Medium RiskSpoofing
Elevation of Privilege
 
System CenterMedium Risk Medium RiskDenial of Service 
AzureMedium Risk Medium RiskInformation Disclosure
Remote Code Execution
 
Microsoft DynamicsMedium Risk Medium RiskRemote Code Execution 

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 2

Number of 'Medium Risk' product(s): 6

Number of 'Low Risk' product(s): 1

Evaluation of overall 'Risk Level': High Risk


Impact

  • Remote Code Execution
  • Elevation of Privilege
  • Denial of Service
  • Information Disclosure
  • Spoofing

System / Technologies affected

  • Windows
  • Extended Security Updates (ESU)
  • SQL Server
  • Developer Tools
  • Microsoft Office
  • Browser
  • System Center
  • Azure
  • Microsoft Dynamics

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

SUSE Linux 內核多個漏洞

發佈日期: 2022年04月13日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 SUSE Linux Kernel 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行程式碼、權限提升及洩露敏感資料。


影響

  • 阻斷服務
  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise Module for Public Cloud 15-SP3
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • SUSE Manager Proxy 4.2
  • SUSE Manager Server 4.2
  • openSUSE Leap 15.3

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 


漏洞識別碼


資料來源


相關連結

SUSE Linux Kernel Multiple Vulnerabilities

Release Date: 13 Apr 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in SUSE Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, elevation of privilege and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise Module for Public Cloud 15-SP3
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • SUSE Manager Proxy 4.2
  • SUSE Manager Server 4.2
  • openSUSE Leap 15.3

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 


Vulnerability Identifier


Source


Related Link

2022年4月12日星期二

Nginx ldap-auth 遠端執行程式碼漏洞

發佈日期: 2022年04月12日

風險: 中度風險

類型: 伺服器 - 網站伺服器

類型: 網站伺服器

於 Nginx ldap-auth 發現漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行程式碼。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • Nginx 有使用 ldap-auth 服務
  • Nginx Plus 有使用 ldap‑auth 服務

 

注意:需滿足以下任何一個條件,LDAP 參考實現的部署才會受到漏洞的影響。

 

  1. 有使用命令行參數配置 Python 服務
  2. 有未使用的參數或未配置的可選配置參數
  3. LDAP 身份驗證取決於特定的組成員身份

解決方案

Nginx 已提供緩解方案以保護客戶
https://www.nginx.com/blog/addressing-security-weaknesses-nginx-ldap-reference-implementation/


漏洞識別碼

Note: No CVE information is available for this vulnerability


資料來源


相關連結

Nginx ldap-auth Remote Code Execution Vulnerability

Release Date: 12 Apr 2022

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

A vulnerability was identified in Nginx ldap-auth. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • Nginx with ldap‑auth daemon
  • Nginx Plus with ldap‑auth daemon

 

Note: Deployments of the LDAP reference implementation are affected by the vulnerability if any of the following conditions apply. 

 

  1. Command-line parameters are used to configure the Python daemon
  2. There are unused, optional configuration parameters
  3. LDAP authentication depends on specific group membership

Solutions

Nginx has suggested mitigation options to protect customers.
https://www.nginx.com/blog/addressing-security-weaknesses-nginx-ldap-reference-implementation/


Vulnerability Identifier

Note: No CVE information is available for this vulnerability


Source


Related Link

Google Chrome 多個漏洞

發佈日期: 2022年04月12日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼,繞過保安限制及資料洩露。


影響

  • 遠端執行程式碼
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • Google Chrome 100.0.4896.88 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 100.0.4896.88 版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 12 Apr 2022

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, security restriction bypass and information disclosure on the targeted system.


Impact

  • Remote Code Execution
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • Google Chrome prior to 100.0.4896.88

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 100.0.4896.88

Vulnerability Identifier


Source


Related Link

IBM WebSphere Application Server 多個漏洞

發佈日期: 2022年04月12日

風險: 中度風險

類型: 伺服器 - 互聯網應用伺服器

類型: 互聯網應用伺服器

於 IBM WebSphere Application Server 發現多個漏洞。遠端使用者可利用這些漏洞,於目標系統觸發遠端執行程式碼及阻斷服務狀況。


影響

  • 遠端執行程式碼
  • 阻斷服務

受影響之系統或技術

  • IBM Security Access Manager for Enterprise Single Sign-On 版本 8.2.0
  • IBM Security Access Manager for Enterprise Single Sign-On 版本 8.2.1
  • IBM Security Access Manager for Enterprise Single Sign-On 版本 8.2.2

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

IBM WebSphere Application Server Multiple Vulnerabilities

Release Date: 12 Apr 2022

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

Multiple vulnerabilities were identified in IBM WebSphere Application Server. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and denial of service condition on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service

System / Technologies affected

  • IBM Security Access Manager for Enterprise Single Sign-On 8.2.0
  • IBM Security Access Manager for Enterprise Single Sign-On 8.2.1
  • IBM Security Access Manager for Enterprise Single Sign-On 8.2.2

Solutions

Before installation of the software, please visit the vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

2022年4月11日星期一

Spring 遠端執行程式碼漏洞

最後更新 2022年04月11日 發佈日期: 2022年04月01日

風險: 高度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

在 Spring 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發遠端執行任意程式碼。

 

已有概念驗證碼針對應用程式運行於

  • JDK 9 或更高版本
  • Apache Tomcat 作為 Servlet 容器
  • 包裝為傳統的 WAR
  • 依賴 spring-webmvc 或 spring-webflux

 

[更新於 2022-04-11]

更新 受影響之系統或技術,解決方案,資料來源及相關連結。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • Spring Boot 2.6.6 之前的版本
  • Spring Boot 2.5.12 之前的版本
  • Spring Framework 5.3.18 之前的版本
  • Spring Framework 5.2.20 之前的版本

 

[更新於 2022-04-11]

 

對於Cisco產品

詳情請參閱以下連結:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67

 

For Apache Tomcat 

詳情請參閱以下連結:

https://tomcat.apache.org/

 

 


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement

 

[更新於 2022-04-11]

 

對於Cisco產品

詳情請參閱以下連結:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67

 

緩解方案

For Apache Tomcat 

詳情請參閱以下連結:

https://tomcat.apache.org/

注意: 強化物件加載器,為 Spring Framework 漏洞 CVE-2022-22965 提供緩解措施。

 


漏洞識別碼


資料來源


相關連結

Spring Remote Code Execution Vulnerability

Last Update Date: 11 Apr 2022 Release Date: 1 Apr 2022

RISK: High Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in Spring. A remote attacker can exploit this vulnerability to trigger remote code execution on the targeted system.

 

PoC exploit exists for application running

  • JDK 9 or higher
  • Apache Tomcat as the Servlet container
  • Packaged as a traditional WAR
  • spring-webmvc or spring-webflux dependency

 

[Updated on 2022-04-11]

Updated System / Technologies affected, Solutions, Source and Related Links.


Impact

  • Remote Code Execution

System / Technologies affected

  • Spring Boot version prior to 2.6.6
  • Spring Boot version prior to 2.5.12
  • Spring Framework version prior to 5.3.18
  • Spring Framework version prior to 5.2.20

 

[Updated on 2022-04-11]

 

For Cisco Products

For detail, please refer to the links below:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67

 

For Apache Tomcat 

For detail, please refer to the links below:

https://tomcat.apache.org/

 

 


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement

 

[Updated on 2022-04-11]

 

For Cisco Products

For detail, please refer to the links below:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67

 

Mitigation Alternative

For Apache Tomcat 

For detail, please refer to the links below:

https://tomcat.apache.org/

Note: Harden the class loader to provide a mitigation for CVE-2022-22965 a Spring Framework vulnerability.

 

 


Vulnerability Identifier


Source


Related Link

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...