2023年6月13日星期二

Fortinet 產品多個漏洞

發佈日期: 2023年06月13日

風險: 高度風險

類型: 操作系統 - Network

類型: Network

於 Fortinet Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼、洩露敏感資料、阻斷服務、權限提升及繞過保安限制。

 

注意:

CVE-2023-27997 可能已被利用於為數不多的保安事件中。

 

影響

  • 繞過保安限制
  • 資料洩露
  • 遠端執行程式碼
  • 權限提升
  • 阻斷服務

受影響之系統或技術

  • FortiADC 5.2 所有版本
  • FortiADC 5.3 所有版本
  • FortiADC 5.4 所有版本
  • FortiADC 6.0 所有版本
  • FortiADC 6.1 所有版本
  • FortiADC 6.2 所有版本
  • FortiADC 7.0 所有版本
  • FortiADC 版本 7.1.0 至 7.1.2
  • FortiADC 版本 7.2.0
  • FortiADCManager 5.2 所有版本
  • FortiADCManager 5.3 所有版本
  • FortiADCManager 5.4 所有版本
  • FortiADCManager 6.0 所有版本
  • FortiADCManager 6.1 所有版本
  • FortiADCManager 6.2 所有版本
  • FortiADCManager 版本 7.0.0
  • FortiADCManager 版本 7.1.0
  • FortiClientWindows 版本 6.4.0 至 6.4.8
  • FortiClientWindows 版本 7.0.0 至 7.0.6
  • FortiConverter 6.0 所有版本
  • FortiConverter 6.2 所有版本
  • FortiConverter 版本 7.0.0
  • FortiNAC 8.5 所有版本
  • FortiNAC 8.6 所有版本
  • FortiNAC 8.7 所有版本
  • FortiNAC 8.8 所有版本
  • FortiNAC 9.1 所有版本
  • FortiNAC 9.2.0 至 9.2.7
  • FortiNAC 版本 9.4.0 至 9.4.2
  • FortiNAC-F 版本 7.2.0
  • FortiOS 6.0 所有版本
  • FortiOS 6.2 所有版本
  • FortiOS 6.4 所有版本
  • FortiOS 7.0 所有版本
  • FortiOS 7.2 所有版本
  • FortiOS-6K7K 版本 6.0.10
  • FortiOS-6K7K 版本 6.0.12 至 6.0.16
  • FortiOS-6K7K 版本 6.2.4
  • FortiOS-6K7K 版本 6.2.6 至 6.2.7
  • FortiOS-6K7K 版本 6.2.9 至 6.2.13
  • FortiOS-6K7K 版本 6.4.10
  • FortiOS-6K7K 版本 6.4.12
  • FortiOS-6K7K 版本 6.4.2
  • FortiOS-6K7K 版本 6.4.6
  • FortiOS-6K7K 版本 6.4.8
  • FortiOS-6K7K 版本 7.0.10
  • FortiOS-6K7K 版本 7.0.5
  • FortiProxy 1.0 所有版本
  • FortiProxy 1.1 所有版本
  • FortiProxy 1.2 所有版本
  • FortiProxy 2.0 所有版本
  • FortiProxy 7.0 所有版本
  • FortiProxy 版本 7.2.0 至 7.2.3
  • FortiSwitchManager 版本 7.0.0 至 7.0.1
  • FortiSwitchManager 版本 7.2.0 至 7.2.1
  • FortiWeb 6.3 所有版本
  • FortiWeb 6.4 所有版本
  • FortiWeb 版本 7.0.0 至 7.0.6
  • FortiWeb 版本 7.2.0 至 7.2.1
 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Fortinet Products Multiple Vulnerabilities

Release Date: 13 Jun 2023

RISK: High Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, sensitive information disclosure, denial of service, elevation of privilege and security restriction bypass on the targeted system.

 

Note:

CVE-2023-27997 may have been exploited in a limited number of cases


Impact

  • Security Restriction Bypass
  • Information Disclosure
  • Remote Code Execution
  • Elevation of Privilege
  • Denial of Service

System / Technologies affected

  • FortiADC 5.2 all versions
  • FortiADC 5.3 all versions
  • FortiADC 5.4 all versions
  • FortiADC 6.0 all versions
  • FortiADC 6.1 all versions
  • FortiADC 6.2 all versions
  • FortiADC 7.0 all versions
  • FortiADC version 7.1.0 through 7.1.2
  • FortiADC version 7.2.0
  • FortiADCManager 5.2 all versions
  • FortiADCManager 5.3 all versions
  • FortiADCManager 5.4 all versions
  • FortiADCManager 6.0 all versions
  • FortiADCManager 6.1 all versions
  • FortiADCManager 6.2 all versions
  • FortiADCManager version 7.0.0
  • FortiADCManager version 7.1.0
  • FortiClientWindows version 6.4.0 through 6.4.8
  • FortiClientWindows version 7.0.0 through 7.0.6
  • FortiConverter 6.0 all versions
  • FortiConverter 6.2 all versions
  • FortiConverter version 7.0.0
  • FortiNAC 8.5 all versions
  • FortiNAC 8.6 all versions
  • FortiNAC 8.7 all versions
  • FortiNAC 8.8 all versions
  • FortiNAC 9.1 all versions
  • FortiNAC 9.2.0 through 9.2.7
  • FortiNAC version 9.4.0 through 9.4.2
  • FortiNAC-F version 7.2.0
  • FortiOS 6.0 all versions
  • FortiOS 6.2 all versions
  • FortiOS 6.4 all versions
  • FortiOS 7.0 all versions
  • FortiOS 7.2 all versions
  • FortiOS-6K7K version 6.0.10
  • FortiOS-6K7K version 6.0.12 through 6.0.16
  • FortiOS-6K7K version 6.2.4
  • FortiOS-6K7K version 6.2.6 through 6.2.7
  • FortiOS-6K7K version 6.2.9 through 6.2.13
  • FortiOS-6K7K version 6.4.10
  • FortiOS-6K7K version 6.4.12
  • FortiOS-6K7K version 6.4.2
  • FortiOS-6K7K version 6.4.6
  • FortiOS-6K7K version 6.4.8
  • FortiOS-6K7K version 7.0.10
  • FortiOS-6K7K version 7.0.5
  • FortiProxy 1.0 all versions
  • FortiProxy 1.1 all versions
  • FortiProxy 1.2 all versions
  • FortiProxy 2.0 all versions
  • FortiProxy 7.0 all versions
  • FortiProxy version 7.2.0 through 7.2.3
  • FortiSwitchManager version 7.0.0 through 7.0.1
  • FortiSwitchManager version 7.2.0 through 7.2.1
  • FortiWeb 6.3 all versions
  • FortiWeb 6.4 all versions
  • FortiWeb version 7.0.0 through 7.0.6
  • FortiWeb version 7.2.0 through 7.2.1
 

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

IBM WebSphere Application Server 多個漏洞

發佈日期: 2023年06月13日

風險: 中度風險

類型: 伺服器 - 互聯網應用伺服器

類型: 互聯網應用伺服器

於 IBM WebSphere Application Server 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發資料洩露及篡改。


影響

  • 資料洩露
  • 篡改

受影響之系統或技術

  • IBM WebSphere Application Server 版本 8.5
  • IBM WebSphere Application Server 版本 9.0
 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

IBM WebSphere Application Server Multiple Vulnerabilities

Release Date: 13 Jun 2023

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

Multiple vulnerabilities were identified in IBM WebSphere Application Server. A remote attacker could exploit some of these vulnerabilities to trigger information disclosure and data manipulation on the targeted system.


Impact

  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • IBM WebSphere Application Server 8.5
  • IBM WebSphere Application Server 9.0

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

NetApp 產品多個漏洞

發佈日期: 2023年06月12日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 NetApp 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料及資料篡改。


影響

  • 阻斷服務
  • 資料洩露
  • 篡改

受影響之系統或技術

  • Active IQ Unified Manager for Linux
  • Active IQ Unified Manager for Microsoft Windows
  • Active IQ Unified Manager for VMware vSphere
  • Astra Trident
  • E-Series SANtricity OS Controller Software 11.x
  • E-Series SANtricity Unified Manager and Web Services Proxy
  • FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400
  • FAS/AFF BIOS - A900/9500
  • NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S
  • NetApp HCI Baseboard Management Controller (BMC) - H410C
  • NetApp SMI-S Provider
  • Management Services for Element Software and NetApp HCI
  • ONTAP 9 (formerly Clustered Data ONTAP)
  • ONTAP Antivirus Connector
  • ONTAP tools for VMware vSphere
  • ONTAP Select Deploy administration utility
  • SnapManager for Hyper-V

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 


漏洞識別碼


資料來源


相關連結

NetApp Products Multiple Vulnerabilities

Release Date: 12 Jun 2023

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in NetApp Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • Active IQ Unified Manager for Linux
  • Active IQ Unified Manager for Microsoft Windows
  • Active IQ Unified Manager for VMware vSphere
  • Astra Trident
  • E-Series SANtricity OS Controller Software 11.x
  • E-Series SANtricity Unified Manager and Web Services Proxy
  • FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400
  • FAS/AFF BIOS - A900/9500
  • NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S
  • NetApp HCI Baseboard Management Controller (BMC) - H410C
  • NetApp SMI-S Provider
  • Management Services for Element Software and NetApp HCI
  • ONTAP 9 (formerly Clustered Data ONTAP)
  • ONTAP Antivirus Connector
  • ONTAP tools for VMware vSphere
  • ONTAP Select Deploy administration utility
  • SnapManager for Hyper-V

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 


Vulnerability Identifier


Source


Related Link

2023年6月9日星期五

VMWare Aria Operations for Networks 多個漏洞

發佈日期: 2023年06月09日

風險: 中度風險

類型: 操作系統 - 網絡操作系統

類型: 網絡操作系統

於 VMWare Aria Operations for Networks 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及洩露敏感資料。


影響

  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • VMware Aria Operations for Networks 6.x (以前稱為 vRealize Network Insight)

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

VMWare Aria Operations for Networks Multiple Vulnerabilities

Release Date: 9 Jun 2023

RISK: Medium Risk

TYPE: Operating Systems - VM Ware

TYPE: VM Ware

Multiple vulnerabilities were identified in VMWare Aria Operations for Networks. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and sensitive information disclosure on the targeted system.


Impact

  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • VMware Aria Operations for Networks 6.x (Formerly vRealize Network Insight)

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2023年6月8日星期四

思科 AnyConnect 權限提升漏洞

發佈日期: 2023年06月08日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

於思科 AnyConnect 發現一個漏洞。遠端攻擊者可利用這個漏洞,於目標系統觸發權限提升。


影響

  • 權限提升

受影響之系統或技術

  • 思科 AnyConnect Secure Mobility Client for Windows Software 4.10MR7 以前的版本
  • 思科 Secure Client for Windows Software 5.0MR2 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Cisco AnyConnect Elevation of Privilege Vulnerability

Release Date: 8 Jun 2023

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability was identified in Cisco AnyConnect. A remote attacker could exploit this vulnerability to trigger elevation of privilege on the targeted system.


Impact

  • Elevation of Privilege

System / Technologies affected

  • Cisco AnyConnect Secure Mobility Client for Windows Software versions prior to 4.10MR7
  • Cisco Secure Client for Windows Software versions prior to 5.0MR2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Mozilla 產品多個漏洞

發佈日期: 2023年06月08日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Mozilla 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及繞過保安限制。


影響

  • 遠端執行程式碼
  • 繞過保安限制

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox 114
  • Firefox ESR 102.12

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox 114
  • Firefox ESR 102.12

漏洞識別碼


資料來源


相關連結

Mozilla Products Multiple Vulnerabilities

Release Date: 8 Jun 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Mozilla Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

Versions prior to:

 

  • Firefox 114
  • Firefox ESR 102.12

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Firefox 114
  • Firefox ESR 102.12

Vulnerability Identifier


Source


Related Link

SUSE Linux 內核多個漏洞

發佈日期: 2023年06月08日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 SUSE Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼、繞過保安限制及洩露敏感資料。

 

影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • Basesystem Module 15-SP4
  • Development Tools Module 15-SP4
  • Legacy Module 15-SP4
  • SUSE Linux Enterprise Desktop 15 SP4
  • SUSE Linux Enterprise High Availability Extension 15 SP4
  • SUSE Linux Enterprise High Performance Computing 12 SP4
  • SUSE Linux Enterprise High Performance Computing 12 SP5
  • SUSE Linux Enterprise High Performance Computing 15 SP1
  • SUSE Linux Enterprise High Performance Computing 15 SP2
  • SUSE Linux Enterprise High Performance Computing 15 SP3
  • SUSE Linux Enterprise High Performance Computing 15 SP4
  • SUSE Linux Enterprise Live Patching 12-SP4
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Live Patching 15-SP1
  • SUSE Linux Enterprise Live Patching 15-SP2
  • SUSE Linux Enterprise Live Patching 15-SP3
  • SUSE Linux Enterprise Live Patching 15-SP4
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Micro 5.2
  • SUSE Linux Enterprise Micro 5.3
  • SUSE Linux Enterprise Micro 5.4
  • SUSE Linux Enterprise Micro for Rancher 5.3
  • SUSE Linux Enterprise Real Time 15 SP4
  • SUSE Linux Enterprise Server 12 SP4
  • SUSE Linux Enterprise Server 12 SP5
  • SUSE Linux Enterprise Server 15 SP1
  • SUSE Linux Enterprise Server 15 SP2
  • SUSE Linux Enterprise Server 15 SP3
  • SUSE Linux Enterprise Server 15 SP4
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1
  • SUSE Linux Enterprise Server for SAP Applications 15 SP2
  • SUSE Linux Enterprise Server for SAP Applications 15 SP3
  • SUSE Linux Enterprise Server for SAP Applications 15 SP4
  • SUSE Linux Enterprise Workstation Extension 15 SP4
  • SUSE Manager Proxy 4.3
  • SUSE Manager Retail Branch Server 4.3
  • SUSE Manager Server 4.3
  • SUSE Real Time Module 15-SP4
  • openSUSE Leap 15.4
  • openSUSE Leap Micro 5.3

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

SUSE Linux Kernel Multiple Vulnerabilities

Release Date: 8 Jun 2023

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in SUSE Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, security restriction bypass and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • Basesystem Module 15-SP4
  • Development Tools Module 15-SP4
  • Legacy Module 15-SP4
  • SUSE Linux Enterprise Desktop 15 SP4
  • SUSE Linux Enterprise High Availability Extension 15 SP4
  • SUSE Linux Enterprise High Performance Computing 12 SP4
  • SUSE Linux Enterprise High Performance Computing 12 SP5
  • SUSE Linux Enterprise High Performance Computing 15 SP1
  • SUSE Linux Enterprise High Performance Computing 15 SP2
  • SUSE Linux Enterprise High Performance Computing 15 SP3
  • SUSE Linux Enterprise High Performance Computing 15 SP4
  • SUSE Linux Enterprise Live Patching 12-SP4
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Live Patching 15-SP1
  • SUSE Linux Enterprise Live Patching 15-SP2
  • SUSE Linux Enterprise Live Patching 15-SP3
  • SUSE Linux Enterprise Live Patching 15-SP4
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Micro 5.2
  • SUSE Linux Enterprise Micro 5.3
  • SUSE Linux Enterprise Micro 5.4
  • SUSE Linux Enterprise Micro for Rancher 5.3
  • SUSE Linux Enterprise Real Time 15 SP4
  • SUSE Linux Enterprise Server 12 SP4
  • SUSE Linux Enterprise Server 12 SP5
  • SUSE Linux Enterprise Server 15 SP1
  • SUSE Linux Enterprise Server 15 SP2
  • SUSE Linux Enterprise Server 15 SP3
  • SUSE Linux Enterprise Server 15 SP4
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1
  • SUSE Linux Enterprise Server for SAP Applications 15 SP2
  • SUSE Linux Enterprise Server for SAP Applications 15 SP3
  • SUSE Linux Enterprise Server for SAP Applications 15 SP4
  • SUSE Linux Enterprise Workstation Extension 15 SP4
  • SUSE Manager Proxy 4.3
  • SUSE Manager Retail Branch Server 4.3
  • SUSE Manager Server 4.3
  • SUSE Real Time Module 15-SP4
  • openSUSE Leap 15.4
  • openSUSE Leap Micro 5.3

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...