2022年11月19日星期六

F5 產品多個漏洞

發佈日期: 2022年11月18日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 F5 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及繞過保安限制。

 

注意﹕

已有 CVE-2022-41622 的概念驗證碼。該漏洞與遠端執行任意程式碼有關,它需要至少具有資源管理員角色權限並通過 iControl SOAP 中的基本身份驗證進行身份驗證的用戶才能執行關鍵操作。因此,整體風險水平為中度風險。


影響

  • 遠端執行程式碼
  • 繞過保安限制

受影響之系統或技術

  • BIG-IP (all modules)
  • BIG-IP SPK
  • BIG-IQ Centralized Management

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

F5 Products Multiple Vulnerabilities

Release Date: 18 Nov 2022

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in F5 Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and security restriction bypass on the targeted system.

 

Note:

Proof of concept exploit for CVE-2022-41622 exists on the internet. The vulnerability is related to remote code execution, and it required a users who have at least resource administrator role privilege and are authenticated through basic authentication in iControl SOAP into performing critical actions. Hence, the overall risk level is medium.


Impact

  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • BIG-IP (all modules)
  • BIG-IP SPK
  • BIG-IQ Centralized Management

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2022年11月18日星期五

Samba 阻斷服務漏洞

發佈日期: 2022年11月17日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

於 Samba 發現一個漏洞。遠端使用者可利用此漏洞,於目標系統觸發阻斷服務狀況、權限提升及資料篡改。


影響

  • 阻斷服務
  • 權限提升
  • 篡改

受影響之系統或技術

  • Samba 4.17.3 以前的版本
  • Samba 4.16.7 以前的版本
  • Samba 4.15.12 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Samba Denial of Service Vulnerability

Release Date: 17 Nov 2022

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in Samba. A remote user can exploit this vulnerability to trigger denial of service condition, elevation of privilege and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Data Manipulation

System / Technologies affected

  • Samba versions prior to 4.17.3
  • Samba versions prior to 4.16.7
  • Samba versions prior to 4.15.12

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

IBM WebSphere Application Server 多個漏洞

發佈日期: 2022年11月17日

風險: 中度風險

類型: 伺服器 - 互聯網應用伺服器

類型: 互聯網應用伺服器

於 IBM WebSphere Application Server 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及資料篡改。


影響

  • 阻斷服務
  • 篡改

受影響之系統或技術

  • IBM WebSphere Application Server 版本 9.0
  • IBM WebSphere Application Server 版本 8.5
  • IBM WebSphere Application Server Liberty Continuous delivery

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

IBM WebSphere Application Server Multiple Vulnerabilities

Release Date: 17 Nov 2022

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

Multiple vulnerabilities were identified in IBM WebSphere Application Server. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Data Manipulation

System / Technologies affected

  • IBM WebSphere Application Server 9.0
  • IBM WebSphere Application Server 8.5
  • IBM WebSphere Application Server Liberty Continuous delivery

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Linux 內核多個漏洞

最後更新 2022年11月17日 發佈日期: 2022年11月10日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼、洩露敏感資料、繞過保安限制及跨網站指令碼。

 

[更新於 2022-11-14] 

更新受影響之系統或技術,解決方案及相關連結。

 

[更新於 2022-11-17] 

更新影響,受影響之系統或技術,解決方案,漏洞識別碼及相關連結。


影響

  • 阻斷服務
  • 權限提升
  • 資料洩露
  • 遠端執行程式碼
  • 繞過保安限制
  • 跨網站指令碼

受影響之系統或技術

  • openSUSE Leap 15.3
  • openSUSE Leap 15.4
  • openSUSE Leap Micro 5.2
  • Red Hat CodeReady Linux Builder for ARM 64 8 aarch64
  • Red Hat CodeReady Linux Builder for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x
  • Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x
  • Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le
  • Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le
  • Red Hat CodeReady Linux Builder for x86_64 8 x86_64
  • Red Hat CodeReady Linux Builder for x86_64 9 x86_64
  • Red Hat Enterprise Linux for ARM 64 8 aarch64
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for Real Time 8 x86_64
  • Red Hat Enterprise Linux for Real Time 9 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV 8 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV 9 x86_64
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1 x86_64
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.2 x86_64
  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1 ppc64le
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.2 ppc64le
  • Red Hat Satellite 6.12 x86_64
  • Red Hat Satellite Capsule 6.12 x86_64
  • Red Hat Virtualization Host 4 for RHEL 8 x86_64
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise High Performance Computing 15-SP4
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Micro 5.2
  • SUSE Linux Enterprise Module for Live Patching 15-SP4
  • SUSE Linux Enterprise Module for Public Cloud 15-SP3
  • SUSE Linux Enterprise Module for Public Cloud 15-SP4
  • SUSE Linux Enterprise Module for Realtime 15-SP3
  • SUSE Linux Enterprise Real Time 15-SP3
  • SUSE Linux Enterprise Real Time Extension 12-SP5
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server 15-SP4
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15-SP4
  • SUSE Linux Enterprise Storage 7.1
  • SUSE Manager Proxy 4.2
  • SUSE Manager Proxy 4.3
  • SUSE Manager Retail Branch Server 4.2
  • SUSE Manager Retail Branch Server 4.3
  • SUSE Manager Server 4.2
  • SUSE Manager Server 4.3

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

對於 RedHat

安裝供應商提供的修補程式:

 

對於 SUSE

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Linux Kernel Multiple Vulnerabilities

Last Update Date: 17 Nov 2022 Release Date: 10 Nov 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, sensitive information disclosure, security restriction bypass and cross-site scripting on the targeted system.

 

[Updated on 2022-11-14] 

Updated System / Technologies affected, Solutions and Related Links.

 

[Updated on 2022-11-17] 

Updated Impact, System / Technologies affected, Solutions, Vulnerability Identifier and Related Links.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Remote Code Execution
  • Security Restriction Bypass
  • Cross-Site Scripting

System / Technologies affected

  • openSUSE Leap 15.3
  • openSUSE Leap 15.4
  • openSUSE Leap Micro 5.2
  • Red Hat CodeReady Linux Builder for ARM 64 8 aarch64
  • Red Hat CodeReady Linux Builder for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x
  • Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x
  • Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le
  • Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le
  • Red Hat CodeReady Linux Builder for x86_64 8 x86_64
  • Red Hat CodeReady Linux Builder for x86_64 9 x86_64
  • Red Hat Enterprise Linux for ARM 64 8 aarch64
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for Real Time 8 x86_64
  • Red Hat Enterprise Linux for Real Time 9 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV 8 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV 9 x86_64
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1 x86_64
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.2 x86_64
  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1 ppc64le
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.2 ppc64le
  • Red Hat Satellite 6.12 x86_64
  • Red Hat Satellite Capsule 6.12 x86_64
  • Red Hat Virtualization Host 4 for RHEL 8 x86_64
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise High Performance Computing 15-SP4
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Micro 5.2
  • SUSE Linux Enterprise Module for Live Patching 15-SP4
  • SUSE Linux Enterprise Module for Public Cloud 15-SP3
  • SUSE Linux Enterprise Module for Public Cloud 15-SP4
  • SUSE Linux Enterprise Module for Realtime 15-SP3
  • SUSE Linux Enterprise Real Time 15-SP3
  • SUSE Linux Enterprise Real Time Extension 12-SP5
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server 15-SP4
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15-SP4
  • SUSE Linux Enterprise Storage 7.1
  • SUSE Manager Proxy 4.2
  • SUSE Manager Proxy 4.3
  • SUSE Manager Retail Branch Server 4.2
  • SUSE Manager Retail Branch Server 4.3
  • SUSE Manager Server 4.2
  • SUSE Manager Server 4.3

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

For RedHat

Apply fixes issued by the vendor:

 

For SUSE

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2022年11月16日星期三

Mozilla 產品多個漏洞

發佈日期: 2022年11月16日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Mozilla 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼、仿冒、資料洩露及繞過保安限制。


影響

  • 遠端執行程式碼
  • 仿冒
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox 107
  • Firefox ESR 102.5
  • Thunderbird 102.5

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox 107
  • Firefox ESR 102.5
  • Thunderbird 102.5

漏洞識別碼


資料來源


相關連結

Mozilla Products Multiple Vulnerabilities

Release Date: 16 Nov 2022

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Mozilla Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, spoofing, information disclosure and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Spoofing
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

Versions prior to:

 

  • Firefox 107
  • Firefox ESR 102.5
  • Thunderbird 102.5

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Firefox 107
  • Firefox ESR 102.5
  • Thunderbird 102.5

Vulnerability Identifier


Source


Related Link

2022年11月14日星期一

Linux 內核多個漏洞

最後更新 2022年11月14日 發佈日期: 2022年11月10日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼、洩露敏感資料及繞過保安限制。

 

[更新於 2022-11-14] 

更新受影響之系統或技術,解決方案及相關連結。

 


影響

  • 阻斷服務
  • 權限提升
  • 資料洩露
  • 遠端執行程式碼
  • 繞過保安限制

受影響之系統或技術

  • openSUSE Leap 15.3
  • openSUSE Leap Micro 5.2
  • Red Hat CodeReady Linux Builder for ARM 64 8 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x
  • Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le
  • Red Hat CodeReady Linux Builder for x86_64 8 x86_64
  • Red Hat Enterprise Linux for ARM 64 8 aarch64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for Real Time 8 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV 8 x86_64
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.2 x86_64
  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.2 ppc64le
  • Red Hat Virtualization Host 4 for RHEL 8 x86_64
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Micro 5.2
  • SUSE Linux Enterprise Module for Public Cloud 15-SP3
  • SUSE Linux Enterprise Module for Realtime 15-SP3
  • SUSE Linux Enterprise Real Time 15-SP3
  • SUSE Linux Enterprise Real Time Extension 12-SP5
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • SUSE Linux Enterprise Storage 7.1
  • SUSE Manager Proxy 4.2
  • SUSE Manager Retail Branch Server 4.2
  • SUSE Manager Server 4.2

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

對於 RedHat

安裝供應商提供的修補程式:

 

對於 SUSE

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Linux Kernel Multiple Vulnerabilities

Last Update Date: 14 Nov 2022 Release Date: 10 Nov 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.

 

[Updated on 2022-11-14] 

Updated System / Technologies affected, Solutions and Related Links.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • openSUSE Leap 15.3
  • openSUSE Leap Micro 5.2
  • Red Hat CodeReady Linux Builder for ARM 64 8 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x
  • Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le
  • Red Hat CodeReady Linux Builder for x86_64 8 x86_64
  • Red Hat Enterprise Linux for ARM 64 8 aarch64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for Real Time 8 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV 8 x86_64
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.2 x86_64
  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.2 ppc64le
  • Red Hat Virtualization Host 4 for RHEL 8 x86_64
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Micro 5.2
  • SUSE Linux Enterprise Module for Public Cloud 15-SP3
  • SUSE Linux Enterprise Module for Realtime 15-SP3
  • SUSE Linux Enterprise Real Time 15-SP3
  • SUSE Linux Enterprise Real Time Extension 12-SP5
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • SUSE Linux Enterprise Storage 7.1
  • SUSE Manager Proxy 4.2
  • SUSE Manager Retail Branch Server 4.2
  • SUSE Manager Server 4.2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

For RedHat

Apply fixes issued by the vendor:

 

For SUSE

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...