2024年4月18日星期四

IBM WebSphere 產品多個漏洞

發佈日期: 2024年04月18日

風險: 中度風險

類型: 伺服器 - 互聯網應用伺服器

類型: 互聯網應用伺服器

於 IBM WebSphere 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料及繞過保安限制。


影響

  • 阻斷服務
  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

  • IBM WebSphere Application Server 版本 9.0
  • IBM WebSphere Application Server 版本 8.5
  • IBM WebSphere Application Server Liberty 17.0.0.3 - 24.0.0.3

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

IBM WebSphere Products Multiple Vulnerabilities

Release Date: 18 Apr 2024

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

Multiple vulnerabilities were identified in IBM WebSphere Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • IBM WebSphere Application Server 9.0
  • IBM WebSphere Application Server 8.5
  • IBM WebSphere Application Server Liberty 17.0.0.3 - 24.0.0.3

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Google Chrome 多個漏洞

發佈日期: 2024年04月17日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、資料洩露、繞過保安限制及遠端執行任意程式碼。

 

 

影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • Google Chrome 124.0.6367.60 (Linux) 之前的版本
  • Google Chrome 124.0.6367.60/.61 (Mac) 之前的版本
  • Google Chrome 124.0.6367.60/.61 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 124.0.6367.60 (Linux) 或之後版本
  • 更新至 124.0.6367.60/.61 (Mac) 或之後版本
  • 更新至 124.0.6367.60/.61 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 17 Apr 2024

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, information disclosure, security restriction bypass and remote code execution on the targeted system.

 


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • Google Chrome prior to 124.0.6367.60 (Linux)
  • Google Chrome prior to 124.0.6367.60/.61 (Mac)
  • Google Chrome prior to 124.0.6367.60/.61 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 124.0.6367.60(Linux) or later
  • Update to version 124.0.6367.60/.61 (Mac) or later
  • Update to version 124.0.6367.60/.61 (Windows) or later

Vulnerability Identifier


Source


Related Link

甲骨文產品多個漏洞

發佈日期: 2024年04月17日

風險: 極高度風險

類型: 伺服器 - 數據庫伺服器

類型: 數據庫伺服器

於甲骨文產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼、洩露敏感資料、資料篡改、跨網站指令碼及繞過保安限制。

 

注意: CVE-2023-41993 已被積極利用,讓未經認證的攻擊者透過多種通訊協定存取網絡,入侵 Oracle Java SE、Oracle GraalVM 企業版。 成功的攻擊需要攻擊者以外的人進行人為互動。 成功攻擊此漏洞可導致接管 Oracle Java SE、Oracle GraalVM 企業版。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 繞過保安限制
  • 資料洩露
  • 篡改
  • 權限提升
  • 跨網站指令碼

受影響之系統或技術

  • Oracle MySQL
  • Java SE
  • Oracle Database Server
  • WebLogic Server

 

有關其他 甲骨文 產品,請參閱以下連結:

https://www.oracle.com/security-alerts/cpuapr2024.html


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

https://www.oracle.com/security-alerts/cpuapr2024.html


漏洞識別碼


資料來源


相關連結

Oracle Products Multiple Vulnerabilities

Release Date: 17 Apr 2024

RISK: Extremely High Risk

TYPE: Servers - Database Servers

TYPE: Database Servers

Multiple vulnerabilities were identified in Oracle Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, sensitive information disclosure, data manipulation, cross-site scripting and security restriction bypass on the targeted system.

 

Note: CVE-2023-41993 have been actively exploited, allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM Enterprise Edition.


Impact

  • Remote Code Execution
  • Denial of Service
  • Security Restriction Bypass
  • Information Disclosure
  • Data Manipulation
  • Elevation of Privilege
  • Cross-Site Scripting

System / Technologies affected

  • Oracle MySQL
  • Java SE
  • Oracle Database Server
  • WebLogic Server

 

For other Oracle products, please refer to the link below:

https://www.oracle.com/security-alerts/cpuapr2024.html


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

https://www.oracle.com/security-alerts/cpuapr2024.html


Vulnerability Identifier


Source


Related Link

2024年4月16日星期二

Debian Linux 內核多個漏洞

發佈日期: 2024年04月16日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 Debian Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及洩露敏感資料。


影響

  • 權限提升
  • 資料洩露
  • 阻斷服務

受影響之系統或技術

  • Debian bookworm 6.1.85-1 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Debian Linux Kernel Multiple Vulnerabilities

Release Date: 16 Apr 2024

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Debian Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and sensitive information disclosure on the targeted system.


Impact

  • Elevation of Privilege
  • Information Disclosure
  • Denial of Service

System / Technologies affected

  • Debian bookworm versions prior to 6.1.85-1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2024年4月15日星期一

Xen 阻斷服務漏洞

發佈日期: 2024年04月15日

風險: 中度風險

類型: 操作系統 - 網絡操作系統

類型: 網絡操作系統

於 Xen 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發阻斷服務。

 

Xen Denial of Service Vulnerability

Release Date: 15 Apr 2024

RISK: Medium Risk

TYPE: Operating Systems - VM Ware

TYPE: VM Ware

A vulnerability was identified in Xen. A remote attacker could exploit this vulnerability to trigger denial of service on the targeted system.


Impact

  • Denial of Service

System / Technologies affected

  • Xen Server versions prior to 8
  • Citrix Hypervisor versions prior to 8.2 CU1 LTSR

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

GitLab 多個漏洞

發佈日期: 2024年04月15日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發跨網站指令碼及阻斷服務。

 

影響

  • 跨網站指令碼
  • 阻斷服務

受影響之系統或技術

  • GitLab Community Edition (CE) 16.10.2, 16.9.4 及 16.8.6 以前的版本
  • GitLab Enterprise Edition (EE) 16.10.2, 16.9.4 及 16.8.6 以前的版本
 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

GitLab Multiple Vulnerabilities

Release Date: 15 Apr 2024

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting and denial of service on the targeted system.


Impact

  • Cross-Site Scripting
  • Denial of Service

System / Technologies affected

  • GitLab Community Edition (CE) versions prior to 16.10.2, 16.9.4 and 16.8.6 
  • GitLab Enterprise Edition (EE) versions prior to 16.10.2, 16.9.4 and 16.8.6

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Palo Alto 遠端執行程式碼漏洞

發佈日期: 2024年04月15日

風險: 極高度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

在 Palo Alto 產品發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發遠端執行程式碼。

 

注意: CVE-2024-3400 影響 Palo Alto Networks PAN-OS 軟件中的 GlobalProtect 功能,在特定的PAN-OS 版本和不同的功能配置下,可能會讓未經認證的攻擊者以root 權限在防火牆上觸發遠端執行程式碼。

 

[更新於 2024-04-15 11:56]

更新解決方案, Palo Alto Networks 已發佈緊急更新。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • PAN-OS 11.1.2-h3 之前的版本
  • PAN-OS 11.0.4-h1 之前的版本
  • PAN-OS 10.2.9-h1 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 


漏洞識別碼


資料來源


相關連結

Palo Alto Products Remote Code Execution Vulnerability

Release Date: 15 Apr 2024

RISK: Extremely High Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in Palo Alto Products. A remote attacker can exploit this vulnerability to trigger remote code execution on the targeted system.

 

Note: CVE-2024-3400 affected GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.

 

[Updated on 2024-04-15 11:56] 

Updated solutions as Palo Alto Networks has released hotfix.


Impact

  • Remote Code Execution

System / Technologies affected

  • PAN-OS 11.1 versions earlier than 11.1.2-h3
  • PAN-OS 11.0 versions earlier than 11.0.4-h1
  • PAN-OS 10.2 versions earlier than 10.2.9-h1
 

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 


Vulnerability Identifier


Source


Related Link

2024年4月12日星期五

Juniper Junos OS 多個漏洞

發佈日期: 2024年04月12日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 Juniper Junos OS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料及繞過保安限制。


Juniper Junos OS Multiple Vulnerabilities

Release Date: 12 Apr 2024

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in Juniper Junos OS. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure and security restriction bypass on the targeted system.


思科產品多個漏洞

思科產品多個漏洞 於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況,資料篡改及繞過保安限制。 影響 阻斷服務 繞過保安限制 篡改 受影響之系統或技術 Cisco IOS Cisco IOS XE 請參考供應商發佈的連結以了解受影響的版本: https:...