2022年9月20日星期二

Microsoft Edge 多個漏洞

發佈日期: 2022年09月19日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及資料篡改。


Microsoft Edge Multiple Vulnerabilities

Release Date: 19 Sep 2022

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and data manipulation on the targeted system.

 


2022年9月15日星期四

Google Chrome 多個漏洞

發佈日期: 2022年09月15日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及篡改。


影響

  • 遠端執行程式碼
  • 篡改

受影響之系統或技術

  • Google Chrome 105.0.5195.125 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 105.0.5195.125 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 15 Sep 2022

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and data manipulation on the targeted system.


Impact

  • Remote Code Execution
  • Data Manipulation

System / Technologies affected

  • Google Chrome prior to 105.0.5195.125

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 105.0.5195.125 or later

Vulnerability Identifier


Source


Related Link

SUSE Linux 內核多個漏洞

發佈日期: 2022年09月15日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 SUSE Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及洩露敏感資料。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • SUSE Linux Enterprise Desktop 12-SP5
  • SUSE Linux Enterprise Desktop 15-SP3 
  • SUSE Linux Enterprise High Availability 12-SP4 
  • SUSE Linux Enterprise High Availability 12-SP5
  • SUSE Linux Enterprise High Availability 15-SP3 
  • SUSE Linux Enterprise High Performance Computing 
  • SUSE Linux Enterprise High Performance Computing 12-SP4
  • SUSE Linux Enterprise High Performance Computing 12-SP5 
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise Live Patching 12-SP4 
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Micro 5.1 
  • SUSE Linux Enterprise Micro 5.2 
  • SUSE Linux Enterprise Module for Basesystem 15-SP3 
  • SUSE Linux Enterprise Module for Development Tools 15-SP3 
  • SUSE Linux Enterprise Module for Legacy Software 15-SP3 
  • SUSE Linux Enterprise Module for Live Patching 15-SP3 
  • SUSE Linux Enterprise Server 
  • SUSE Linux Enterprise Server 12-SP3-BCL 
  • SUSE Linux Enterprise Server 12-SP4
  • SUSE Linux Enterprise Server 12-SP4-LTSS 
  • SUSE Linux Enterprise Server 12-SP5
  • SUSE Linux Enterprise Server 15-SP3 
  • SUSE Linux Enterprise Server for SAP Applications 
  • SUSE Linux Enterprise Server for SAP Applications 12-SP5
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • SUSE Linux Enterprise Server for SAP 12-SP4 
  • SUSE Linux Enterprise Software Development Kit 12-SP5 
  • SUSE Linux Enterprise Storage 7.1
  • SUSE Linux Enterprise Workstation Extension 12-SP5  
  • SUSE Linux Enterprise Workstation Extension 15-SP3 
  • SUSE Manager Proxy 4.2 
  • SUSE Manager Retail Branch Server 4.2 
  • SUSE Manager Server 4.2
  • SUSE OpenStack Cloud 9 
  • SUSE OpenStack Cloud Crowbar 9  
  • openSUSE Leap 15.3 
  • openSUSE Leap 15.4 
  • openSUSE Leap Micro 5.2 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

SUSE Linux Kernel Multiple Vulnerabilities

Release Date: 15 Sep 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in SUSE Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • SUSE Linux Enterprise Desktop 12-SP5
  • SUSE Linux Enterprise Desktop 15-SP3 
  • SUSE Linux Enterprise High Availability 12-SP4 
  • SUSE Linux Enterprise High Availability 12-SP5
  • SUSE Linux Enterprise High Availability 15-SP3 
  • SUSE Linux Enterprise High Performance Computing 
  • SUSE Linux Enterprise High Performance Computing 12-SP4
  • SUSE Linux Enterprise High Performance Computing 12-SP5 
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise Live Patching 12-SP4 
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Micro 5.1 
  • SUSE Linux Enterprise Micro 5.2 
  • SUSE Linux Enterprise Module for Basesystem 15-SP3 
  • SUSE Linux Enterprise Module for Development Tools 15-SP3 
  • SUSE Linux Enterprise Module for Legacy Software 15-SP3 
  • SUSE Linux Enterprise Module for Live Patching 15-SP3 
  • SUSE Linux Enterprise Server 
  • SUSE Linux Enterprise Server 12-SP3-BCL 
  • SUSE Linux Enterprise Server 12-SP4
  • SUSE Linux Enterprise Server 12-SP4-LTSS 
  • SUSE Linux Enterprise Server 12-SP5
  • SUSE Linux Enterprise Server 15-SP3 
  • SUSE Linux Enterprise Server for SAP Applications 
  • SUSE Linux Enterprise Server for SAP Applications 12-SP5
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • SUSE Linux Enterprise Server for SAP 12-SP4 
  • SUSE Linux Enterprise Software Development Kit 12-SP5 
  • SUSE Linux Enterprise Storage 7.1
  • SUSE Linux Enterprise Workstation Extension 12-SP5  
  • SUSE Linux Enterprise Workstation Extension 15-SP3 
  • SUSE Manager Proxy 4.2 
  • SUSE Manager Retail Branch Server 4.2 
  • SUSE Manager Server 4.2
  • SUSE OpenStack Cloud 9 
  • SUSE OpenStack Cloud Crowbar 9  
  • openSUSE Leap 15.3 
  • openSUSE Leap 15.4 
  • openSUSE Leap Micro 5.2 

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Adobe 每月保安更新 (2022年9月)

發佈日期: 2022年09月14日

風險: 中度風險

類型: 用戶端 - 辦公室應用

類型: 辦公室應用

Adobe已為產品提供本月保安更新:

 

受影響產品風險程度影響備註詳情(包括 CVE)
Adobe Experience Manager中度風險 中度風險跨網站指令碼
遠端執行程式碼
繞過保安限制
 APSB22-40
Adobe Bridge中度風險 中度風險遠端執行程式碼
資料洩露
 APSB22-49
Adobe InDesign中度風險 中度風險資料洩露
遠端執行程式碼
 APSB22-50
Adobe Photoshop中度風險 中度風險遠端執行程式碼
資料洩露
 APSB22-52
Adobe InCopy中度風險 中度風險遠端執行程式碼
資料洩露
 APSB22-53
Adobe Animate中度風險 中度風險遠端執行程式碼 APSB22-54
Adobe Illustrator中度風險 中度風險遠端執行程式碼
資料洩露
 APSB22-55

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:7

「低度風險」產品數目:0

整體「風險程度」評估:中度風險


影響

  • 跨網站指令碼
  • 遠端執行程式碼
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • Adobe Experience Manager (AEM) AEM Cloud Service (CS)
  • Adobe Experience Manager (AEM) 6.5.13.0 及以前版本
  • Adobe Bridge  12.0.2 及以前版本
  • Adobe Bridge  11.1.3 及以前版本
  • Adobe InDesign 17.3 及以前版本
  • Adobe InDesign 16.4.2 及以前版本
  • Photoshop 2021 22.5.8 及以前版本
  • Photoshop 2022 23.4.2 及以前版本
  • Adobe InCopy  17.3 及以前版本
  • Adobe InCopy  16.4.2 及以前版本
  • Adobe Animate 2021 21.0.11 及以前版本
  • Adobe Animate 2022 22.0.7 及以前版本
  • Illustrator 2022 26.4 及以前版本
  • Illustrator 2021 25.4.7 及以前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 安裝供應商提供的修補程式。個別產品詳情可參考上表「詳情」一欄或執行軟件更新。

漏洞識別碼


資料來源


相關連結

Adobe Monthly Security Update (September 2022)

Release Date: 14 Sep 2022

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
Adobe Experience ManagerMedium Risk Medium RiskCross-site Scripting
Remote Code Execution
Security Restriction Bypass
 APSB22-40
Adobe BridgeMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB22-49
Adobe InDesignMedium Risk Medium RiskInformation Disclosure
Remote Code Execution
 APSB22-50
Adobe PhotoshopMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB22-52
Adobe InCopyMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB22-53
Adobe AnimateMedium Risk Medium RiskRemote Code Execution APSB22-54
Adobe IllustratorMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB22-55

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 7

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Cross-Site Scripting
  • Remote Code Execution
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • Adobe Experience Manager (AEM) AEM Cloud Service (CS)
  • Adobe Experience Manager (AEM) 6.5.13.0 and earlier versions
  • Adobe Bridge  12.0.2 and earlier versions
  • Adobe Bridge  11.1.3 and earlier versions
  • Adobe InDesign 17.3 and earlier versions
  • Adobe InDesign 16.4.2 and earlier versions
  • Photoshop 2021 22.5.8 and earlier versions
  • Photoshop 2022 23.4.2 and earlier versions
  • Adobe InCopy  17.3 and earlier versions
  • Adobe InCopy  16.4.2 and earlier versions
  • Adobe Animate 2021 21.0.11 and earlier versions
  • Adobe Animate 2022 22.0.7 and earlier versions
  • Illustrator 2022 26.4 and earlier versions
  • Illustrator 2021 25.4.7 and earlier versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update

Vulnerability Identifier


Source


Related Link

微軟每月保安更新 (2022年9月)

發佈日期: 2022年09月14日

風險: 高度風險

類型: 操作系統 - 視窗操作系統

類型: 視窗操作系統

微軟已為產品提供本月保安更新:

 

受影響產品風險程度影響備註
視窗高度風險 高度風險權限提升
阻斷服務
遠端執行程式碼
資料洩露
繞過保安限制
開發者工具中度風險 中度風險遠端執行程式碼
阻斷服務
權限提升
 
延伸安全性更新 (ESU)高度風險 高度風險權限提升
遠端執行程式碼
阻斷服務
資料洩露
 
微軟 Dynamics中度風險 中度風險遠端執行程式碼 
微軟 Office中度風險 中度風險遠端執行程式碼 
System Center中度風險 中度風險權限提升 
瀏覽器中度風險 中度風險遠端執行程式碼 
Azure中度風險 中度風險權限提升 

 

「極高度風險」產品數目:0

「高度風險」產品數目:2

「中度風險」產品數目:6

「低度風險」產品數目:0

整體「風險程度」評估:高度風險


影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

  • 視窗
  • 開發者工具
  • 延伸安全性更新 (ESU)
  • 微軟 Dynamics
  • 微軟 Office
  • System Center
  • 瀏覽器
  • Azure

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 安裝軟件供應商提供的修補程式。

漏洞識別碼


資料來源


相關連結

Microsoft Monthly Security Update (September 2022)

Release Date: 14 Sep 2022

RISK: High Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
WindowsHigh Risk High RiskElevation of Privilege
Denial of Service
Remote Code Execution
Information Disclosure
Security Restriction Bypass
Developer ToolsMedium Risk Medium RiskRemote Code Execution
Denial of Service
Elevation of Privilege
 
Extended Security Updates (ESU)High Risk High RiskElevation of Privilege
Remote Code Execution
Denial of Service
Information Disclosure
 
Microsoft DynamicsMedium Risk Medium RiskRemote Code Execution 
Microsoft OfficeMedium Risk Medium RiskRemote Code Execution 
System CenterMedium Risk Medium RiskElevation of Privilege 
BrowserMedium Risk Medium RiskRemote Code Execution 
AzureMedium Risk Medium RiskElevation of Privilege 

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 2

Number of 'Medium Risk' product(s): 6

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': High Risk


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Windows
  • Developer Tools
  • Extended Security Updates (ESU)
  • Microsoft Dynamics
  • Microsoft Office
  • System Center
  • Browser
  • Azure

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

Trend Micro Apex One 多個漏洞

發佈日期: 2022年09月14日

風險: 高度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

於 Trend Micro Apex One 發現多個漏洞。攻擊者可利用這些漏洞,於目標系統觸發提升權限、遠端執行程式碼、資料洩露、繞過保安限制及阻斷服務。

 

注意﹕

CVE-2022-40139 漏洞正被廣泛利用。

因Trend Micro Apex One 及 Trend Micro Apex One as a Service 客戶端未有正確驗證復原機制中的某些組件,Apex One服務器管理員可以指示受影響客戶端下載未驗證的復原資料組包,從而觸發遠端執行程式碼。

 

攻擊者必須首先獲得Apex One服務器管理控制台訪問權限才能利用此漏洞。


影響

  • 權限提升
  • 遠端執行程式碼
  • 資料洩露
  • 阻斷服務
  • 繞過保安限制

受影響之系統或技術

  • Trend Micro Apex One - 2019 (On-prem)
  • Trend Micro Apex One as a Service (SaaS)

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Trend Micro Apex One Multiple Vulnerabilities

Release Date: 14 Sep 2022

RISK: High Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities were identified in Trend Micro Apex One. An attacker could exploit some of these vulnerabilities to trigger elevation of privilege, remote code execution, information disclosure, security restriction bypass and Denial of Service on the targeted system.

 

Note:
CVE-2022-40139 is being exploited in the wild.

 

Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution.

 

An attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.


Impact

  • Elevation of Privilege
  • Remote Code Execution
  • Information Disclosure
  • Denial of Service
  • Security Restriction Bypass

System / Technologies affected

  • Trend Micro Apex One - 2019 (On-prem)
  • Trend Micro Apex One as a Service (SaaS)

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Zoom 產品多個漏洞

發佈日期: 2022年09月14日

風險: 中度風險

類型: 用戶端 - 辦公室應用

類型: 辦公室應用

於 Zoom 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制。


影響

  • 繞過保安限制

受影響之系統或技術

  • Zoom On-Premise Meeting Connectors 4.8.20220815.130 之前的版本

解決方案

更新至 Zoom On-Premise Meeting Connectors 4.8.20220815.130


漏洞識別碼


資料來源


相關連結

Zoom Products Multiple Vulnerabilities

Release Date: 14 Sep 2022

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

Multiple vulnerabilities have been identified in Zoom products. A remote attacker can exploit this vulnerability to trigger security restriction bypass on the targeted system.


Impact

  • Security Restriction Bypass

System / Technologies affected

  • Zoom On-Premise Meeting Connectors before version 4.8.20220815.130

Solutions

Update to Zoom On-Premise Meeting Connectors 4.8.20220815.130


Vulnerability Identifier


Source


Related Link

2022年9月13日星期二

蘋果產品多個漏洞

發佈日期: 2022年09月13日

風險: 高度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於 Apple Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、彷冒、遠端執行任意程式碼及繞過保安限制。


影響

  • 權限提升
  • 仿冒
  • 遠端執行程式碼
  • 繞過保安限制

受影響之系統或技術

  • iOS 15.7 及 iPadOS 15.7 以前的版本
  • iOS 16 以前的版本
  • macOS Big Sur 11.7 以前的版本
  • macOS Monterey 12.6 以前的版本
  • Safari 16 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

  • iOS 15.7 and iPadOS 15.7
  • iOS 16
  • macOS Big Sur 11.7
  • macOS Monterey 12.6
  • Safari 16

漏洞識別碼


資料來源


相關連結

Apple Products Multiple Vulnerabilities

Release Date: 13 Sep 2022

RISK: High Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Apple Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, spoofing, remote code execution and security restriction bypass on the targeted system.


Impact

  • Elevation of Privilege
  • Spoofing
  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • Versions prior to iOS 15.7 and iPadOS 15.7
  • Versions prior to iOS 16
  • Versions prior to macOS Big Sur 11.7
  • Versions prior to macOS Monterey 12.6
  • Versions prior to Safari 16

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • iOS 15.7 and iPadOS 15.7
  • iOS 16
  • macOS Big Sur 11.7
  • macOS Monterey 12.6
  • Safari 16

Vulnerability Identifier


Source


Related Link

Debian Linux 內核多個漏洞

發佈日期: 2022年09月13日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 Debian Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及遠端執行任意程式碼。


影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼

受影響之系統或技術

  • Debian 10 linux-5.10 版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Debian Linux Kernel Multiple Vulnerabilities

Release Date: 13 Sep 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Debian Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and remote code execution on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution

System / Technologies affected

  • Debian 10 as linux-5.10

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

NetApp 產品多個漏洞

發佈日期: 2022年09月13日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 NetApp 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料及資料篡改。


影響

  • 阻斷服務
  • 資料洩露
  • 篡改

受影響之系統或技術

  • Active IQ Unified Manager for Linux
  • Active IQ Unified Manager for Microsoft Windows
  • Active IQ Unified Manager for VMware vSphere
  • Element Plug-in for vCenter Server
  • Management Services for Element Software and NetApp HCI
  • NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S
  • NetApp HCI Baseboard Management Controller (BMC) - H410C
  • NetApp HCI Compute Node (Bootstrap OS)
  • NetApp Manageability SDK
  • NetApp SolidFire & HCI Management Node
  • NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software)
  • OnCommand Insight
  • ONTAP Select Deploy administration utility
  • SnapCenter

解決方案


漏洞識別碼


資料來源


相關連結

NetApp Products Multiple Vulnerabilities

Release Date: 13 Sep 2022

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in NetApp Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • Active IQ Unified Manager for Linux
  • Active IQ Unified Manager for Microsoft Windows
  • Active IQ Unified Manager for VMware vSphere
  • Element Plug-in for vCenter Server
  • Management Services for Element Software and NetApp HCI
  • NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S
  • NetApp HCI Baseboard Management Controller (BMC) - H410C
  • NetApp HCI Compute Node (Bootstrap OS)
  • NetApp Manageability SDK
  • NetApp SolidFire & HCI Management Node
  • NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software)
  • OnCommand Insight
  • ONTAP Select Deploy administration utility
  • SnapCenter

Solutions


Vulnerability Identifier


Source


Related Link

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...