Command injection vulnerability in IBM InfoSphere Information Server 
Indian - Computer Emergency Response Team (cert-in.org.in)

Severity Rating: HIGH

Software Affected

IBM InfoSphere Information Server version 11.7
Overview

A vulnerability has been reported in IBM InfoSphere Information Server
which could allow a remote attacker to execute arbitrary OS commands on the
targeted system.

Description

This vulnerability exists in IBM InfoSphere Information Server due to
improper input validation of special elements . A remote attacker could
exploit this vulnerability by sending specially crafted data to the
application.

Successful exploitation of this vulnerability could allow a remote attacker
to execute arbitrary OS commands on the targeted system.

Solution

Apply appropriate software fixes as available on the vendor website:


Vendor Information

IBM

CVE Name
CVE-2022-40752


 

Multiple Vulnerabilities in IBM WebSphere Application Server 
Indian - Computer Emergency Response Team (cert-in.org.in)

Severity Rating: MEDIUM

Software Affected

IBM WebSphere Application Server version 9.0
IBM WebSphere Application Server version 8.5
IBM WebSphere Application Server Liberty Continuous delivery
Overview

Multiple vulnerabilities have been reported in IBM WebSphere Application
Server and IBM Application Server Liberty which could be exploited by
unauthenticated remote attacker to manipulate data or cause denial of
service condition (DoS) condition on the targeted system.

Description

1. Data Manipulation Vulnerability ( CVE-2022-21624   )

This vulnerability exists in Java SE due to improper input validation
within the JNDI component in Oracle GraalVM Enterprise Edition. An
unauthenticated remote attacker could exploit this vulnerability to
manipulate data on the targeted system.

2. Denial of Service Vulnerability ( CVE-2022-21626   )

This vulnerability exists in Java SE due to improper input validation
within the Security component in Oracle GraalVM Enterprise Edition. An
unauthenticated remote attacker could exploit this vulnerability to perform
denial of service (DoS) condition on the targeted system.

Solution

Apply appropriate patches as mentioned in IBM Security Bulletin


Vendor Information

IBM

References

IBM

CVE Name
CVE-2022-21624
CVE-2022-21626


 

Multiple Vulnerabilities in Trend Micro Apex One 
Indian - Computer Emergency Response Team (cert-in.org.in)

Severity Rating: HIGH

Software Affected

Trend Micro Apex One - 2019 (On-prem)
Trend Micro Apex One as a Service (SaaS)
Overview

Multiple vulnerabilities have been reported in Trend Micro Apex One, which could allow an attacker to access sensitive information, gain elevated privileges or bypass security restrictions on the targeted system.

Description

1. Information Disclosure Vulnerabilities ( CVE-2022-44647   CVE-2022-44648   )

These vulnerabilities exist in Trend Micro Apex One and Apex One as a Service due to an out-of-bounds read error. Successful exploitation of these vulnerabilities could allow a local attacker to disclose sensitive information of the targeted system.

2. Privilege Escalation Vulnerabilities ( CVE-2022-44649   CVE-2022-44650   CVE-2022-44651   CVE-2022-44652   CVE-2022-44653   )

These vulnerabilities exist in Trend Micro Apex One and Apex One as a Service due to an out-of-bounds access error, memory corruption error in the Unauthorized Change Prevention service, a Time-of-Check Time-Of-Use error, improper handling of exceptional conditions, or directory traversal error. Successful exploitation of these vulnerabilities could allow a local attacker to gain escalated privileges on the targeted system.

3. Security Bypass Vulnerability ( CVE-2022-44654   )

This vulnerability exists in the monitor engine component of Trend Micro Apex One and Apex One as a Service which is complied without the /SAFESEH memory protection mechanism. An attacker could exploit this vulnerability by sending malicious payloads to the affected system. Successful exploitation of this vulnerability could allow the attacker to bypass security restrictions on the targeted system.

Solution

Apply appropriate updates as mentioned by the vendor:


Vendor Information

Trend Micro

References

Trend Micro

CVE Name
CVE-2022-44647
CVE-2022-44648
CVE-2022-44649
CVE-2022-44650
CVE-2022-44651
CVE-2022-44652
CVE-2022-44653
CVE-2022-44654

 

Multiple Vulnerabilities in Google ChromeOS 
Indian - Computer Emergency Response Team (cert-in.org.in)

Severity Rating: HIGH

Software Affected

Google ChromeOS Stable channel versions prior to 108.0.5359.71 for Mac and Linux
Google ChromeOS Stable channel versions prior to 108.0.5359.71/72 for Windows
Overview

Multiple vulnerabilities have been reported in Google Chrome OS which could be exploited by a remote attacker to bypass security restrictions, execute arbitrary code or cause denial of service condition on the targeted system.

Description

Multiple vulnerabilities exist in Google Chrome OS due to type confusion in V8; Use after free in Camera Capture, Extensions, Mojo, Audio, Forms, Sign-In, Live Caption and Accessibility;  Out-of bounds write in Lacros Graphics; Inappropriate implementation in Fenced Frames and Navigation; Insufficient policy enforcement in Popup Blocker, Autofill, DevTools, File System API and Safe Browsing; Insufficient validation of untrusted input in Downloads and CORS; Insufficient data validation in Directory. An attacker could exploit these vulnerabilities by persuading a victim to visit a specially crafted web site.

Successful exploitation of these vulnerabilities could allow a remote attacker to bypass security restriction, execute arbitrary code or cause denial of service condition on the targeted system.

Solution

Apply appropriate updates as mentioned


Vendor Information

Google Chrome

References

Google Chrome

CVE Name
CVE-2022-4174
CVE-2022-4175
CVE-2022-4176
CVE-2022-4177
CVE-2022-4178
CVE-2022-4179
CVE-2022-4180
CVE-2022-4181
CVE-2022-4182
CVE-2022-4183
CVE-2022-4184
CVE-2022-4185
CVE-2022-4186
CVE-2022-4187
CVE-2022-4188
CVE-2022-4189
CVE-2022-4190
CVE-2022-4191
CVE-2022-4192
CVE-2022-4193
CVE-2022-4194
CVE-2022-4195

 

CURRENT ACTIVITIES
Threat Actors exploiting RCE vulnerability in Oracle Fusion Middle Ware
Indian - Computer Emergency Response Team (cert-in.org.in)

It has been reported that the threat actors are exploiting remote code execution vulnerability in Oracle Fusion Middle Ware.

Software Affected

Oracle Access Manager (OAM) versions 11.1.2.3.0, 12.2.1.3.0, and 12.2.1.4.0
Description

Oracle Access Manager is a software extensively used by businesses for single sign-on (SSO) as part of the Oracle Fusion Middleware suite.

This vulnerability exists in OpenSSO Agent component of the Oracle Access Manager product due to improper input validation. Successful exploitation of this vulnerability could allow an unauthenticated attacker with network access via HTTP to take control of Oracle Access Manager.

Note: This vulnerability is being exploited in the wild. Users are advised to apply patches urgently.

Solution

Apply appropriate updates as mentioned by the vendor.


Vendor Information

Oracle

Reference

Oracle

CERT-In

CVE Name
CVE-2021-35587


Remote code execution vulnerability in Microsoft Edge (Chromium-based)
Indian - Computer Emergency Response Team (cert-in.org.in)

Severity Rating: HIGH

Software Affected

Microsoft Edge (Chromium-based) version prior to 107.0.1418.62
Overview

A Vulnerability has been reported in Microsoft Edge (Chromium-based), which could allow a remote attacker to execute arbitrary code on the targeted system.

Description

This vulnerability exists in Microsoft Edge due to Heap buffer overflow in GPU. A remote attacker could exploit this vulnerability by sending a specially crafted request to the targeted system. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the targeted system.

Note: This vulnerability (CVE-2022-4135) is being exploited in the wild. Users are advised to apply patches urgently.

Solution

Upgrade to Microsoft Edge version 107.0.1418.62


Vendor Information

Microsoft

References

Microsoft

CVE Name
CVE-2022-4135

Multiple Vulnerabilities in Cisco Identity Services Engine (ISE) 
Indian - Computer Emergency Response Team (cert-in.org.in)

Severity Rating: HIGH

Software Affected

Cisco Identity Services Engine
Overview

Multiple vulnerabilities have been reported in Cisco ISE which could allow a remote attacker to inject arbitrary operating system commands, bypass security protections, and conduct cross-site scripting attacks on targeted system.

Description

1. Command Injection Vulnerability  ( CVE-2022-20964   )

This Vulnerability exists in Cisco ISE due to improper validation of user input within requests as part of the web-based management interface tcpdump feature. A remote attacker could exploit this vulnerability by manipulating requests to the web-based management interface to contain operating system commands.
Successful exploitation of this vulnerability could allow the attacker to inject and execute arbitrary commands on the system with root privileges.

2. Security Bypass Vulnerability ( CVE-2022-20965   )

This Vulnerability exists in Cisco ISE due to improper access control on a feature within the web-based management interface. An attacker could exploit this vulnerability bypassing checks within the application through direct requests on affected system.
Successful exploitation of this vulnerability could allow the attacker to gain privileged actions within the web-based management interface that should be otherwise restricted.

3. Cross-site scripting  Vulnerability ( CVE-2022-20966   CVE-2022-20967   )

These vulnerabilities exist in web-based management interface of Cisco ISE due to improper validation of input to an application feature before storage within the web-based management interface tcpdump feature. An attacker could exploit these vulnerabilities  by creating entries that contain malicious HTML or script code within the application interface (URL).
Successful exploitation of these vulnerabilities could allow the attacker to store malicious HTML or script code within the application interface for use in further cross-site scripting attacks.

Solution

Apply appropriate updates as mentioned in:


Vendor Information

CISCO

References

CISCO

CVE Name
CVE-2022-20964
CVE-2022-20965
CVE-2022-20966
CVE-2022-20967

© Copyright 2020. Designed By Templateify

© Copyright 2020. Ud64

Scroll to Top