2025年4月11日星期五

GitLab 多個漏洞

GitLab 多個漏洞

發佈日期: 2025年04月11日

風險: 中度風險

類型: 伺服器 - 其他伺服器

於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、彷冒、洩露敏感資料及繞過保安限制。


影響

  • 阻斷服務
  • 繞過保安限制
  • 資料洩露
  • 仿冒

受影響之系統或技術

  • GitLab Community Edition (CE) 17.10.4, 17.9.6 及 17.8.7 以前的版本
  • GitLab Enterprise Edition (EE) 17.10.4, 17.9.6 及 17.8.7 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

GitLab Multiple Vulnerabilities

GitLab Multiple Vulnerabilities

Release Date: 11 Apr 2025

RISK: Medium Risk

TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, spoofing, sensitive information disclosure and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Security Restriction Bypass
  • Information Disclosure
  • Spoofing

System / Technologies affected

  • GitLab Community Edition (CE) versions prior to 17.10.4, 17.9.6, and 17.8.7
  • GitLab Enterprise Edition (EE) versions prior to 17.10.4, 17.9.6, and 17.8.7

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Juniper Junos OS 多個漏洞

Juniper Junos OS 多個漏洞

發佈日期: 2025年04月11日

風險: 中度風險

類型: 操作系統 - Network

於 Juniper Junos OS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及洩露敏感資料。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露

受影響之系統或技術

  • Junos OS
  • Junos OS Evolved

詳情請參閱以下連結﹕

https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&f:ctype=[Security%20Advisories]


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

請參閱 2025-04 安全公告


漏洞識別碼


資料來源


相關連結

Juniper Junos OS Multiple Vulnerabilities

Juniper Junos OS Multiple Vulnerabilities

Release Date: 11 Apr 2025

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in Juniper Junos OS. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and sensitive information disclosure on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure

System / Technologies affected

  • Junos OS
  • Junos OS Evolved

Please refer to the link below for detail:

https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&f:ctype=[Security%20Advisories]


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Please refer to 2025-04 Security Bulletin.


Vulnerability Identifier


Source


Related Link

Palo Alto 產品多個漏洞

Palo Alto 產品多個漏洞

發佈日期: 2025年04月11日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

於 Palo Alto 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、洩露敏感資料、資料篡改及繞過保安限制。

 

注意:

CVE-2025-0124 的概念驗證碼已被公開。Palo Alto Networks PAN-OS 軟體中的經過身份驗證的文件刪除漏洞,可讓擁有透過網路存取 Web 管理介面的權限及經過身份驗證的攻擊者,以「nobody」使用者身份刪除特定檔案;檔案包括有限的日誌和組態檔案,但不包括系統檔案。因此,風險等級被評為中等風險。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 繞過保安限制
  • 資料洩露
  • 篡改

受影響之系統或技術

  • PAN-OS 10.1 到 10.1.14-h13 之前的版本
  • PAN-OS 10.1 到 10.1.14-h13 on VM-Series 之前的版本
  • PAN-OS 10.2 到 10.2.15 之前的版本
  • PAN-OS 10.2 到 10.2.9 on VM-Series 之前的版本
  • PAN-OS 11.0 到 11.0.4 on VM-Series 之前的版本
  • PAN-OS 11.0 到 11.0.6 之前的版本
  • PAN-OS 11.1 到 11.1.8 之前的版本
  • PAN-OS 11.2 到 11.2.6 之前的版本
  • Prisma Access 10.2.10-h17 on PAN-OS 之前的版本
  • Prisma Access 11.2.4-h5 on PAN-OS 之前的版本

對於 CVE-2025-0124

  • Cloud NGFW 全部版本
  • PAN-OS 11.2 到 11.2.1 之前的版本
  • PAN-OS 11.1 到 11.1.5 之前的版本
  • PAN-OS 11.0 到 11.0.6 之前的版本
  • PAN-OS 10.2 到 10.2.10 之前的版本
  • PAN-OS 10.1 到 10.1.14-h11 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Palo Alto Products Multiple Vulnerabilities

Palo Alto Products Multiple Vulnerabilities

Release Date: 11 Apr 2025

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

Multiple vulnerabilities were identified in Palo Alto Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.

 

Note:

Proof Of Concept exploit code is publicly available for CVE-2025-0124. An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files. Hence, the risk level is rated as Medium Risk.


Impact

  • Remote Code Execution
  • Denial of Service
  • Security Restriction Bypass
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • PAN-OS 10.1 versions earlier than 10.1.14-h13
  • PAN-OS 10.1 versions earlier than 10.1.14-h13 on VM-Series
  • PAN-OS 10.2 versions earlier than 10.2.15
  • PAN-OS 10.2 versions earlier than 10.2.9 on VM-Series
  • PAN-OS 11.0 versions earlier than 11.0.4 on VM-Series
  • PAN-OS 11.0 versions earlier than 11.0.6
  • PAN-OS 11.1 versions earlier than 11.1.8
  • PAN-OS 11.2 versions earlier than 11.2.6
  • Prisma Access versions earlier than 10.2.10-h17 on PAN-OS
  • Prisma Access versions earlier than 11.2.4-h5 on PAN-OS

For CVE-2025-0124

  • Cloud NGFW All versions
  • PAN-OS 11.2 versions earlier than 11.2.1
  • PAN-OS 11.1 versions earlier than 11.1.5
  • PAN-OS 11.0 versions earlier than 11.0.6
  • PAN-OS 10.2 versions earlier than 10.2.10
  • PAN-OS 10.1 versions earlier than 10.1.14-h11

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2025年4月9日星期三

Adobe 每月保安更新 (2025年4月)

Adobe 每月保安更新 (2025年4月)

發佈日期: 2025年04月09日

風險: 中度風險

類型: 用戶端 - 辦公室應用

Adobe已為產品提供本月保安更新:

 

受影響產品風險程度影響備註詳情(包括 CVE)
Adobe ColdFusion中度風險 中度風險資料洩露
遠端執行程式碼
繞過保安限制
 APSB25-15
Adobe After Effects中度風險 中度風險遠端執行程式碼
資料洩露
阻斷服務
 APSB25-23
Adobe Media Encoder中度風險 中度風險遠端執行程式碼 APSB25-24
Adobe Bridge中度風險 中度風險遠端執行程式碼 APSB25-25
Adobe Commerce中度風險 中度風險權限提升
阻斷服務
繞過保安限制
 APSB25-26
Adobe Experience Manager Forms中度風險 中度風險繞過保安限制 APSB25-27
Adobe Premiere Pro中度風險 中度風險遠端執行程式碼 APSB25-28
Adobe Photoshop中度風險 中度風險遠端執行程式碼 APSB25-30
Adobe Animate中度風險 中度風險遠端執行程式碼
資料洩露
 APSB25-31
Adobe Experience Manager Screens中度風險 中度風險遠端執行程式碼 APSB25-32
Adobe FrameMaker中度風險 中度風險遠端執行程式碼
阻斷服務
資料洩露
 APSB25-33
Adobe XMP Toolkit SDK中度風險 中度風險資料洩露 APSB25-34

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:12

「低度風險」產品數目:0

整體「風險程度」評估:中度風險


影響

  • 遠端執行程式碼
  • 資料洩露
  • 阻斷服務
  • 權限提升
  • 繞過保安限制

受影響之系統或技術

  • ColdFusion 2025 Build 331385
  • ColdFusion 2023 Update 12 及以前版本
  • ColdFusion 2021 Update 18 及以前版本
  • Adobe After Effects 24.6.4 及以前版本
  • Adobe After Effects 25.1 及以前版本
  • Adobe Media Encoder 24.6.4 及以前版本
  • Adobe Media Encoder 25.1 及以前版本
  • Adobe Bridge  14.1.5 及以前版本
  • Adobe Bridge  15.0.2 及以前版本
  • Adobe Commerce 2.4.8-beta2
  • Adobe Commerce 2.4.7-p4 及以前版本
  • Adobe Commerce 2.4.6-p9 及以前版本
  • Adobe Commerce 2.4.5-p11 及以前版本
  • Adobe Commerce 2.4.4-p12 及以前版本
  • Adobe Commerce B2B 1.5.1 及以前版本
  • Adobe Commerce B2B 1.4.2-p4 及以前版本
  • Adobe Commerce B2B 1.3.5-p9 及以前版本
  • Adobe Commerce B2B 1.3.4-p11 及以前版本
  • Adobe Commerce B2B 1.3.3-p12 及以前版本
  • Magento Open Source 2.4.8-beta
  • Magento Open Source 2.4.7-p4 及以前版本
  • Magento Open Source 2.4.6-p9 及以前版本
  • Magento Open Source 2.4.5-p11 及以前版本
  • Magento Open Source 2.4.4-p12 及以前版本
  • Adobe Experience Manager (AEM) Forms on JEE 6.5.22.0 (AEMForms-6.5.0-0093) 及以前版本
  • Adobe Premiere Pro 25.1 及以前版本
  • Adobe Premiere Pro 24.6.4 及以前版本
  • Photoshop 2025 26.4.1 及以前版本
  • Photoshop 2024 25.12.1 及以前版本
  • Adobe Animate 2023 23.0.10 及以前版本
  • Adobe Animate 2024 24.0.7 及以前版本
  • Adobe Experience Manager (AEM) Screens AEM 6.5 Screens FP11.3 及以前版本
  • Adobe FrameMaker 2020 Release Update 7 及以前版本
  • Adobe FrameMaker 2022 Release Update 5 及以前版本
  • Adobe XMP-Toolkit-SDK 2023.12 及以前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 安裝供應商提供的修補程式。個別產品詳情可參考上表「詳情」一欄或執行軟件更新。

漏洞識別碼


資料來源


相關連結

Adobe Monthly Security Update (April 2025)

Adobe Monthly Security Update (April 2025)

Release Date: 9 Apr 2025

RISK: Medium Risk

TYPE: Clients - Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
Adobe ColdFusionMedium Risk Medium RiskInformation Disclosure
Remote Code Execution
Security Restriction Bypass
 APSB25-15
Adobe After EffectsMedium Risk Medium RiskRemote Code Execution
Information Disclosure
Denial of Service
 APSB25-23
Adobe Media EncoderMedium Risk Medium RiskRemote Code Execution APSB25-24
Adobe BridgeMedium Risk Medium RiskRemote Code Execution APSB25-25
Adobe CommerceMedium Risk Medium RiskElevation of Privilege
Denial of Service
Security Restriction Bypass
 APSB25-26
Adobe Experience Manager FormsMedium Risk Medium RiskSecurity Restriction Bypass APSB25-27
Adobe Premiere ProMedium Risk Medium RiskRemote Code Execution APSB25-28
Adobe PhotoshopMedium Risk Medium RiskRemote Code Execution APSB25-30
Adobe AnimateMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB25-31
Adobe Experience Manager ScreensMedium Risk Medium RiskRemote Code Execution APSB25-32
Adobe FrameMakerMedium Risk Medium RiskRemote Code Execution
Denial of Service
Information Disclosure
 APSB25-33
Adobe XMP Toolkit SDKMedium Risk Medium RiskInformation Disclosure APSB25-34

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 12

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Remote Code Execution
  • Information Disclosure
  • Denial of Service
  • Elevation of Privilege
  • Security Restriction Bypass

System / Technologies affected

  • ColdFusion 2025 Build 331385
  • ColdFusion 2023 Update 12 and earlier versions
  • ColdFusion 2021 Update 18 and earlier versions
  • Adobe After Effects 24.6.4 and earlier versions
  • Adobe After Effects 25.1 and earlier versions
  • Adobe Media Encoder 24.6.4 and earlier versions
  • Adobe Media Encoder 25.1 and earlier versions
  • Adobe Bridge  14.1.5 and earlier versions
  • Adobe Bridge  15.0.2 and earlier versions
  • Adobe Commerce 2.4.8-beta2
  • Adobe Commerce 2.4.7-p4 and earlier versions
  • Adobe Commerce 2.4.6-p9 and earlier versions
  • Adobe Commerce 2.4.5-p11 and earlier versions
  • Adobe Commerce 2.4.4-p12 and earlier versions
  • Adobe Commerce B2B 1.5.1 and earlier versions
  • Adobe Commerce B2B 1.4.2-p4 and earlier versions
  • Adobe Commerce B2B 1.3.5-p9 and earlier versions
  • Adobe Commerce B2B 1.3.4-p11 and earlier versions
  • Adobe Commerce B2B 1.3.3-p12 and earlier versions
  • Magento Open Source 2.4.8-beta
  • Magento Open Source 2.4.7-p4 and earlier versions
  • Magento Open Source 2.4.6-p9 and earlier versions
  • Magento Open Source 2.4.5-p11 and earlier versions
  • Magento Open Source 2.4.4-p12 and earlier versions
  • Adobe Experience Manager (AEM) Forms on JEE 6.5.22.0 (AEMForms-6.5.0-0093) and earlier versions
  • Adobe Premiere Pro 25.1 and earlier versions
  • Adobe Premiere Pro 24.6.4 and earlier versions
  • Photoshop 2025 26.4.1 and earlier versions
  • Photoshop 2024 25.12.1 and earlier versions
  • Adobe Animate 2023 23.0.10 and earlier versions
  • Adobe Animate 2024 24.0.7 and earlier versions
  • Adobe Experience Manager (AEM) Screens AEM 6.5 Screens FP11.3 and earlier versions
  • Adobe FrameMaker 2020 Release Update 7 and earlier versions
  • Adobe FrameMaker 2022 Release Update 5 and earlier versions
  • Adobe XMP-Toolkit-SDK 2023.12 and earlier versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update.

Vulnerability Identifier


Source


Related Link

Aruba 產品多個漏洞

Aruba 產品多個漏洞

發佈日期: 2025年04月09日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

在Aruba產品發現多個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發跨網站指令碼、洩露敏感資料、篡改及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 篡改
  • 資料洩露
  • 跨網站指令碼

受影響之系統或技術

HPE Aruba Networking:

 

  • Access Points 運行 AOS-8 Instant
  • Access Points 運行 AOS-10 AP
  • Mobility Conductor
  • Mobility Controllers
  • WLAN and SD-WAN Gateways Managed by HPE Aruba Networking Central

受影響軟件版本:

 

  • AOS-8.12.x.x: 8.12.0.3 及以下
  • AOS-8.10.x.x: 8.10.0.15 及以下
  • AOS-8 Instant 8.12.x.x: 8.12.0.3 及以下
  • AOS-8 Instant 8.10.x.x: 8.10.0.15 及以下
  • AOS-10.7.x.x: 10.7.1.0 及以下
  • AOS-10.4.x.x: 10.4.1.6 及以下
  • AOS-10 AP 10.7.x.x: 10.7.0.1 及以下
  • AOS-10 AP 10.4.x.x: 10.4.1.5 及以下

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Aruba Products Multiple Vulnerabilities

Aruba Products Multiple Vulnerabilities

Release Date: 9 Apr 2025

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

Multiple vulnerabilities were identified in Aruba Products. A remote attacker could exploit this vulnerability to trigger cross-site scripting, sensitive information disclosure, data manipulation and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Data Manipulation
  • Information Disclosure
  • Cross-Site Scripting

System / Technologies affected

HPE Aruba Networking:

 

  • Access Points running AOS-8 Instant
  • Access Points running AOS-10 AP
  • Mobility Conductor
  • Mobility Controllers
  • WLAN and SD-WAN Gateways Managed by HPE Aruba Networking Central

Affected Software Version(s):

 

  • AOS-8.12.x.x: 8.12.0.3 and below
  • AOS-8.10.x.x: 8.10.0.15 and below
  • AOS-8 Instant 8.12.x.x: 8.12.0.3 and below
  • AOS-8 Instant 8.10.x.x: 8.10.0.15 and below
  • AOS-10.7.x.x: 10.7.1.0 and below
  • AOS-10.4.x.x: 10.4.1.6 and below
  • AOS-10 AP 10.7.x.x: 10.7.0.1 and below
  • AOS-10 AP 10.4.x.x: 10.4.1.5 and below

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Fortinet 產品多個漏洞

Fortinet 產品多個漏洞

發佈日期: 2025年04月09日

風險: 中度風險

類型: 操作系統 - Network

於 Fortinet 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、遠端執行任意程式碼、洩露敏感資料、繞過保安限制、阻斷服務、篡改及仿冒。

 


影響

  • 遠端執行程式碼
  • 資料洩露
  • 繞過保安限制
  • 篡改
  • 仿冒
  • 阻斷服務
  • 權限提升

受影響之系統或技術

有關受影響產品,請參閱以下連結:

 

 


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Fortinet Products Multiple Vulnerabilities

Fortinet Products Multiple Vulnerabilities

Release Date: 9 Apr 2025

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, remote code execution, sensitive information disclosure, security restriction bypass, data manipulation, denial of service and spoofing on the targeted system.

 


Impact

  • Remote Code Execution
  • Information Disclosure
  • Security Restriction Bypass
  • Data Manipulation
  • Spoofing
  • Denial of Service
  • Elevation of Privilege

System / Technologies affected

For affected products, please refer to the link below:

 

 


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Google Chrome 遠端執行程式碼漏洞

Google Chrome 遠端執行程式碼漏洞

發佈日期: 2025年04月09日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Google Chrome 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發遠端執行任意程式碼。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • Google Chrome 135.0.7049.84 (Linux) 之前的版本
  • Google Chrome 135.0.7049.84/.85 (Mac) 之前的版本
  • Google Chrome 135.0.7049.84/.85 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 升級 135.0.7049.84 (Linux) 或之後的版本
  • 升級 135.0.7049.84/.85 (Mac) 或之後的版本
  • 升級 135.0.7049.84/.85 (Windows) 或之後的版本

漏洞識別碼


資料來源


相關連結

Google Chrome Remote Code Execution Vulnerability

Google Chrome Remote Code Execution Vulnerability

Release Date: 9 Apr 2025

RISK: Medium Risk

TYPE: Clients - Browsers

A vulnerability was identified in Google Chrome. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • Google Chrome prior to 135.0.7049.84 (Linux)
  • Google Chrome prior to 135.0.7049.84/.85 (Mac)
  • Google Chrome prior to 135.0.7049.84/.85 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 135.0.7049.84 (Linux) or later
  • Update to version 135.0.7049.84/.85 (Mac) or later
  • Update to version 135.0.7049.84/.85 (Windows) or later

Vulnerability Identifier


Source


Related Link

微軟每月保安更新 (2025年4月)

微軟每月保安更新 (2025年4月)

發佈日期: 2025年04月09日

風險: 中度風險

類型: 操作系統 - 視窗操作系統

微軟已為產品提供本月保安更新:

 

受影響產品風險程度影響備註
視窗中度風險 中度風險遠端執行程式碼
資料洩露
權限提升
阻斷服務
繞過保安限制
仿冒
CVE-2025-29824 正被廣泛利用。此漏洞允許本地攻擊者在裝置/系統上取得 SYSTEM 權限。
延伸安全性更新 (ESU)中度風險 中度風險遠端執行程式碼
資料洩露
權限提升
阻斷服務
繞過保安限制
CVE-2025-29824 正被廣泛利用。此漏洞允許本地攻擊者在裝置/系統上取得 SYSTEM 權限。
微軟 Office中度風險 中度風險權限提升
遠端執行程式碼
繞過保安限制
 
System Center中度風險 中度風險權限提升 
瀏覽器中度風險 中度風險仿冒
遠端執行程式碼
 
微軟 Dynamics中度風險 中度風險資料洩露 
Azure中度風險 中度風險資料洩露
權限提升
 
開發者工具中度風險 中度風險權限提升
阻斷服務
 
SQL Server中度風險 中度風險權限提升 
Apps中度風險 中度風險資料洩露 

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:10

「低度風險」產品數目:0

整體「風險程度」評估:中度風險


影響

  • 權限提升
  • 遠端執行程式碼
  • 阻斷服務
  • 繞過保安限制
  • 仿冒
  • 資料洩露

受影響之系統或技術

  • 視窗
  • 延伸安全性更新 (ESU)
  • 微軟 Office
  • System Center
  • 瀏覽器
  • 微軟 Dynamics
  • Azure
  • 開發者工具
  • SQL Server
  • Apps

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 安裝軟件供應商提供的修補程式。
 

漏洞識別碼


資料來源


相關連結

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...