Cloud One Workload Security and Deep Security Updates
- * indicates a new version of an existing rule
Deep Packet Inspection Rules:
Web Client Common
1009171 - Microsoft Windows 10 Remote Code Execution Vulnerability
Web Server Apache
1009045* - Apache httpd 'mod_cache_socache' Denial Of Service Vulnerability (CVE-2018-1303)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update. - * indicates a new version of an existing rule
Deep Packet Inspection Rules:
Backup Server IBM Tivoli Storage Manager
1003393* - IBM Tivoli Storage Manager Express Backup Heap Corruption
CA ARCserve D2D Administration Interface
1004564* - CA ARCserve D2D Axis2 Default Credentials Remote Code Execution
FTP Client Windows
1002732* - FlashGet FTP 'PWD' Response Remote Buffer Overflow
HP OpenView
1003948* - HP OpenView Storage Data Protector Cell Manager Heap Buffer Overflow
LANDesk Management Suite QIP Server
1002912* - LANDesk Management Suite QIP Service Heal Packet Buffer Overflow
Oracle Secure Backup
1003382* - Oracle Secure Backup NDMP Packet Handling Multiple Denial Of Service
RealPlayer RTSP Client
1004554* - RealNetworks RealPlayer 'GIF87a' File Parsing Heap Overflow Vulnerability
Sybase Open Server
1004771* - Sybase Adaptive Server Backup And Monitor Server NULL Write Remote Code Execution Vulnerability
Web Application Common
1009111* - ImageMagick 'DecodeLabImage' And 'EncodeLabImage' Denial Of Service Vulnerability (CVE-2018-9133) - 1
1009109* - ImageMagick 'IsWEBPImageLossless' Heap Buffer Over Read Vulnerability (CVE-2018-9135) - 1
1009118* - ImageMagick 'ReadDCMImage' Denial Of Service Vulnerability (CVE-2018-8804) - 1
1008986* - ImageMagick 'load_tile' Denial Of Service Vulnerability (CVE-2017-13133) - 1
Web Application PHP Based
1008895* - PHP 'php_wddx_push_element' Function Out Of Bound Read Vulnerability (CVE-2016-7418)
1009168 - WordPress Authenticated Arbitrary File Deletion Vulnerability (CVE-2018-12895)
Web Client Internet Explorer/Edge
1002702* - Microsoft Uninitialized Memory Corruption Vulnerability
Web Server Apache
1009045* - Apache httpd 'mod_cache_socache' Denial Of Service Vulnerability (CVE-2018-1303)
Web Server Miscellaneous
1004628* - VLC Media Player Web Interface 'input' Parameter Remote Buffer Overflow Vulnerability
Web Server RealVNC
1004146* - RealVNC 'ClientCutText' Message Memory Corruption
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update. - * indicates a new version of an existing rule
Deep Packet Inspection Rules:
Advanced Message Queuing Protocol (AMQP)
1009126 - Pivotal Spring AMQP Remote Code Execution Vulnerability (CVE-2017-8045)
Directory Server LDAP
1008555* - Microsoft Windows Active Directory Denial Of Service Vulnerability (CVE-2008-1445)
VoIP Smart
1008941 - Asterisk 'chan_pjsip' SDP Format Denial Of Service Vulnerability
Web Application Common
1008966 - ImageMagick Multiple Security Vulnerabilities (Server) - 1
1008968 - ImageMagick Multiple Security Vulnerabilities (Server) - 2
1008957 - ImageMagick Multiple Security Vulnerabilities (Server) - 8
1008953 - ImageMagick Multiple Security Vulnerabilities (Server) - 9
1009151 - Pivotal Spring PATCH Requests Remote Code Execution (CVE-2017-8046)
Web Application PHP Based
1008818 - PHP WDDX Packet XML Document Invalid Read Vulnerability (CVE-2016-9935)
Web Client Common
1009097* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB18-09) - 7
1009144* - Adobe Flash Player Remote Code Execution Vulnerability (CVE-2018-5002)
1008965 - ImageMagick Multiple Security Vulnerabilities (Client) - 1
1008967 - ImageMagick Multiple Security Vulnerabilities (Client) - 2
1008956 - ImageMagick Multiple Security Vulnerabilities (Client) - 8
1008952 - ImageMagick Multiple Security Vulnerabilities (Client) - 9
Web Client Internet Explorer/Edge
1009068* - Microsoft Edge Memory Corruption Vulnerability (CVE-2018-8179)
1009141* - Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability (CVE-2018-8267)
Web Server Miscellaneous
1005825* - Nginx Crafted URI String Handling Access Restriction Bypass Vulnerability (CVE-2013-4547)
Web Server Oracle
1008688* - Oracle Identity Manager Default Account Vulnerability (CVE-2017-10151)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update. - * indicates a new version of an existing rule
Deep Packet Inspection Rules:
DCERPC Services
1003080* - Server Service Vulnerability (srvsvc)
DNS Client
1009135* - Microsoft Windows DNSAPI Remote Code Execution Vulnerability (CVE-2018-8225)
SIP SSL Client
1008554* - Digium Asterisk TLS Certificate Validation Security Bypass Vulnerability (CVE-2015-3008)
Unix RSync
1008896* - Rsync 'receive_xattr' Heap-based Buffer Overread Vulnerability (CVE-2017-16548)
VoIP Soft Phones
1008653* - Digium Asterisk Non-SIP URIs Denial Of Service Vulnerability (CVE-2017-14098)
Web Application Common
1009145 - Atlassian OAuth Plugin Information Disclosure Vulnerability (CVE-2017-9506)
1009111 - ImageMagick 'DecodeLabImage' And 'EncodeLabImage' Denial Of Service Vulnerability (CVE-2018-9133) - 1
1009109 - ImageMagick 'IsWEBPImageLossless' Heap Buffer Over Read Vulnerability (CVE-2018-9135) - 1
1009118 - ImageMagick 'ReadDCMImage' Denial Of Service Vulnerability (CVE-2018-8804) - 1
1008986 - ImageMagick 'load_tile' Denial Of Service Vulnerability (CVE-2017-13133) - 1
Web Application PHP Based
1008895 - PHP 'php_wddx_push_element' Function Out Of Bound Read Vulnerability (CVE-2016-7418)
1008914* - PHP WDDX Deserialization Denial Of Service Vulnerability (CVE-2017-11143)
1008913* - PHP WDDX Deserialization Heap Out-Of-Bound Read Vulnerability (CVE-2017-11145)
Web Client Common
1009110 - ImageMagick 'DecodeLabImage' And 'EncodeLabImage' Denial Of Service Vulnerability (CVE-2018-9133)
1009108 - ImageMagick 'IsWEBPImageLossless' Heap Buffer Over Read Vulnerability (CVE-2018-9135)
1009063 - ImageMagick 'ReadDCMImage' Denial Of Service Vulnerability (CVE-2018-8804)
1008985 - ImageMagick 'load_tile' Denial Of Service Vulnerability (CVE-2017-13133)
Web Server Apache
1009045 - Apache httpd 'mod_cache_socache' Denial Of Service Vulnerability (CVE-2018-1303)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update. - * indicates a new version of an existing rule
Deep Packet Inspection Rules:
DNS Client
1009059* - ISC BIND DNS Denial Of Service Vulnerability (CVE-2017-3145)
1009135 - Microsoft Windows DNSAPI Remote Code Execution Vulnerability (CVE-2018-8225)
Elasticsearch Java API Protocol
1008685* - Elastic Elasticsearch ThrowableObjectInputStream Insecure Deserialization (CVE-2015-5377)
HP Intelligent Management Center (IMC)
1008905* - HPE Intelligent Management Center 'UrlAccessController' Authentication Bypass Vulnerability (CVE-2017-8982)
1008969* - HPE Intelligent Management Center Multiple Expression Language Injection Vulnerability
Microsoft Office
1009138 - Microsoft Excel Remote Code Execution Vulnerability (CVE-2018-8248)
SIP SSL Client
1008554 - Digium Asterisk TLS Certificate Validation Security Bypass Vulnerability (CVE-2015-3008)
Trend Micro Control Manager
1008721* - Trend Micro Control Manager cmdHandlerStatusMonitor SQL Injection Vulnerability (CVE-2017-11385)
Trend Micro OfficeScan
1008191* - Trend Micro Smart Protection Server Authenticated Remote Code Execution Vulnerabilities
VoIP Soft Phones
1008653 - Digium Asterisk Non-SIP URIs Denial Of Service Vulnerability (CVE-2017-14098)
Web Application Common
1009041* - ImageMagick 'ReadDCMImage' Denial Of Service Vulnerability (CVE-2018-6405) - 1
1009038* - ImageMagick 'ReadMATImage' Denial Of Service Vulnerability (CVE-2017-13658) - 1
1008974* - ImageMagick 'ReadMATImage' Denial Of Service Vulnerability (CVE-2017-18029) - 1
1008990* - ImageMagick 'ReadMATImage' Information Disclosure Vulnerability (CVE-2017-13143) - 1
1008992* - ImageMagick 'ReadOneJNGImage' Denial Of Service Vulnerability (CVE-2017-11750) - 1
1008996* - ImageMagick 'ReadPSDImage' Denial Of Service Vulnerability (CVE-2017-13061) - 1
1009090* - ImageMagick ReadOneMNGImage Denial Of Service Vulnerability (CVE-2018-10177) - 1
1008994* - ImageMagick ReadOnePNGImage Memory Leak Vulnerability (CVE-2017-13141) - 1
1008980* - ImageMagick Use-After-Free Vulnerability (CVE-2017-17499) - 1
Web Application PHP Based
1008894* - PHP 'wddx_stack_destroy' Function Use After Free Vulnerability (CVE-2016-7413)
1008914 - PHP WDDX Deserialization Denial Of Service Vulnerability (CVE-2017-11143)
1008913 - PHP WDDX Deserialization Heap Out-Of-Bound Read Vulnerability (CVE-2017-11145)
Web Client Common
1009104 - Adobe Acrobat Reader Out Of Bounds Read Vulnerability (CVE-2017-16397)
1009102 - Adobe Acrobat Reader Out Of Bounds Read Vulnerability (CVE-2017-16404)
1009146 - Adobe Flash Player Multiple Security Vulnerabilities (APSB18-19)
1008829* - Foxit Reader Multiple Information Disclosure Vulnerabilities
1009014* - Microsoft Windows Graphics Multiple Security Vulnerabilities (Apr-2018)
1009140 - Microsoft Windows Media Foundation Memory Corruption Vulnerability (CVE-2018-8251)
1009131 - Microsoft Windows Multiple Elevation Of Privilege Vulnerabilities (June-2018)
1009134 - Microsoft Windows Remote Code Execution Vulnerability (CVE-2018-8210)
1009044 - Multiple Web Browser WebRTC Private IP Leakage To WebPage Vulnerability (CVE-2018-6849)
Web Client Internet Explorer/Edge
1009132 - Microsoft Edge Memory Corruption Vulnerability (CVE-2018-8110)
1009133 - Microsoft Edge Memory Corruption Vulnerability (CVE-2018-8111)
1009137 - Microsoft Edge Memory Corruption Vulnerability (CVE-2018-8236)
1009136 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2018-8229)
1009130 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2018-0978)
1009139 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2018-8249)
1009141 - Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability (CVE-2018-8267)
Web Server Adobe ColdFusion
1008879* - Adobe Coldfusion BlazeDS Java Object Deserialization Remote Code Execution Vulnerability (CVE-2017-3066)
Web Server Apache
1009087* - Apache httpd FilesMatch Directive Security Restriction Bypass Vulnerability (CVE-2017-15715)
Integrity Monitoring Rules:
1008720* - Users and Groups - Create and Delete Activity
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update. - * indicates a new version of an existing rule
Deep Packet Inspection Rules:
Web Client Common
1009144 - Adobe Flash Player Remote Code Execution Vulnerability (CVE-2018-5002)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update. - * indicates a new version of an existing rule
Deep Packet Inspection Rules:
Web Client Common
1009120 - Adobe Acrobat And Reader XFA 'Submission Handler' Privilege Escalation Vulnerability (CVE-2018-4995)
1008984 - Foxit Reader JPXDecode stream Out-Of-Bounds Write Remote Code Execution Vulnerability
1008742 - IBM Notes Remote Denial Of Service Vulnerability (CVE-2017-1130)
1009088* - Microsoft Windows Multiple Elevation Of Privilege Vulnerabilities (May 2018)
Web Client Internet Explorer/Edge
1009123 - Microsoft Internet Explorer Scripting Engine Information Disclosure Vulnerability (CVE-2018-0981)
1009122 - Microsoft Internet Explorer Scripting Engine Information Disclosure Vulnerability (CVE-2018-0987)
1009121 - Microsoft Internet Explorer Scripting Engine Information Disclosure Vulnerability (CVE-2018-1000)
Web Server Common
1005839* - Identified XML External Entity Injection In HTTP Request
Integrity Monitoring Rules:
1009060 - Kubernetes Cluster Master
Log Inspection Rules:
1002798* - Database Server - PostgreSQL
1009105 - Kubernetes
1002835* - Web Server - Web Access Events - * indicates a new version of an existing rule
Deep Packet Inspection Rules:
Directory Server LDAP
1008555 - Microsoft Windows Active Directory Denial Of Service Vulnerability (CVE-2008-1445)
Elasticsearch Java API Protocol
1008685 - Elastic Elasticsearch ThrowableObjectInputStream Insecure Deserialization (CVE-2015-5377)
HP Intelligent Management Center (IMC)
1008969 - HPE Intelligent Management Center Multiple Expression Language Injection Vulnerability
Trend Micro Control Manager
1008721 - Trend Micro Control Manager cmdHandlerStatusMonitor SQL Injection Vulnerability (CVE-2017-11385)
Web Application Common
1009041 - ImageMagick 'ReadDCMImage' Denial Of Service Vulnerability (CVE-2018-6405) - 1
1009038 - ImageMagick 'ReadMATImage' Denial Of Service Vulnerability (CVE-2017-13658) - 1
1008974 - ImageMagick 'ReadMATImage' Denial Of Service Vulnerability (CVE-2017-18029) - 1
1008990 - ImageMagick 'ReadMATImage' Information Disclosure Vulnerability (CVE-2017-13143) - 1
1008992 - ImageMagick 'ReadOneJNGImage' Denial Of Service Vulnerability (CVE-2017-11750) - 1
1008996 - ImageMagick 'ReadPSDImage' Denial Of Service Vulnerability (CVE-2017-13061) - 1
1008994 - ImageMagick ReadOnePNGImage Memory Leak Vulnerability (CVE-2017-13141) - 1
1008980 - ImageMagick Use-After-Free Vulnerability (CVE-2017-17499) - 1
Web Client Common
1009097* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB18-09) - 7
1008987 - ImageMagick 'ReadDCMImage' Denial Of Service Vulnerability (CVE-2018-6405)
1008988 - ImageMagick 'ReadMATImage' Denial Of Service Vulnerability (CVE-2017-13658)
1008973 - ImageMagick 'ReadMATImage' Denial Of Service Vulnerability (CVE-2017-18029)
1008989 - ImageMagick 'ReadMATImage' Information Disclosure Vulnerability (CVE-2017-13143)
1008991 - ImageMagick 'ReadOneJNGImage' Denial Of Service Vulnerability (CVE-2017-11750)
1008995 - ImageMagick 'ReadPSDImage' Denial Of Service Vulnerability (CVE-2017-13061)
1008993 - ImageMagick ReadOnePNGImage Memory Leak Vulnerability (CVE-2017-13141)
1008979 - ImageMagick Use-After-Free Vulnerability (CVE-2017-17499)
1009029 - PHP 'http_fopen_wrapper' Stack Buffer Overflow Vulnerability (CVE-2018-7584)
1008828* - Speculative Execution Information Disclosure Vulnerabilities (Spectre)
Web Proxy Squid
1008101* - Squid HTTP Proxy ESI Response Processing Denial Of Service Vulnerability
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update. - * indicates a new version of an existing rule
Deep Packet Inspection Rules:
DHCP Client
1009116 - DHCP Client Script Code Execution Vulnerability (CVE-2018-1111) - 1
DHCP Client - Incoming
1009114 - DHCP Client Script Code Execution Vulnerability (CVE-2018-1111)
DNS Server
1008652* - DNSmasq Answer Auth And Answer Request Integer Underflow Vulnerability (CVE-2017-13704)
Microsoft Office
1009052 - Microsoft Excel Remote Code Execution Vulnerability (CVE-2018-0796)
Web Application Common
1005613* - Generic SQL Injection Prevention - 2
1009090 - ImageMagick ReadOneMNGImage Denial Of Service Vulnerability (CVE-2018-10177) - 1
1009057* - Pivotal Spring Data Commons Remote Code Execution Vulnerability (CVE-2018-1273)
Web Application PHP Based
1009054* - Drupal Core Remote Code Execution Vulnerability (CVE-2018-7602)
Web Client Common
1008739* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB17-36) - 1
1009092 - Foxit PDF Reader JavaScript 'XFA Clone' Remote Code Execution Vulnerability (CVE-2018-3850)
1009091 - Foxit PDF Reader Javascript 'Search Query' Remote Code Execution Vulnerability (CVE-2017-14458)
1009089 - ImageMagick ReadOneMNGImage Denial Of Service Vulnerability (CVE-2018-10177)
Web Client Internet Explorer/Edge
1008700* - Microsoft Internet Explorer And Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-11837)
1009047 - Microsoft Internet Explorer Information Disclosure Vulnerability (CVE-2018-0929)
1008935* - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2018-0935)
Web Client Mozilla Firefox
1008951 - Mozilla Firefox Buffer Overflow Parsing HTML5 Fragments Vulnerability (CVE-2016-2819)
Web Server Common
1008646 - Detect Illegal Characters In URI
1000128* - HTTP Protocol Decoding
1005839* - Identified XML External Entity Injection In HTTP Request
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update. - * indicates a new version of an existing rule
Deep Packet Inspection Rules:
DNS Client
1009059 - ISC BIND DNS Denial Of Service Vulnerability (CVE-2017-3145)
1008447 - Identified Suspicious Order Of CNAME And DNAME Records In Query Response (CVE-2017-3137)
Microsoft Office
1008324 - Microsoft Office Word Malicious Macro Execution
Oracle Internet Directory
1003917* - Oracle Internet Directory 'oidldapd' Remote Memory Corruption Vulnerability
Trend Micro OfficeScan
1008191 - Trend Micro Smart Protection Server Authenticated Remote Code Execution Vulnerabilities
Unix RSync
1008896 - Rsync 'receive_xattr' Heap-based Buffer Overread Vulnerability (CVE-2017-16548)
Web Application PHP Based
1008894 - PHP 'wddx_stack_destroy' Function Use After Free Vulnerability (CVE-2016-7413)
1008856 - PHP Out-Of-Bounds Write Vulnerability (CVE-2016-5399)
Web Client Common
1008740* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB17-36) - 7
1008883* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB18-02) - 2
1008885* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB18-02) - 5
1009096 - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB18-09) - 1
1009095 - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB18-09) - 2
1009098 - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB18-09) - 3
1009103 - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB18-09) - 4
1009101 - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB18-09) - 5
1009100 - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB18-09) - 6
1009097 - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB18-09) - 7
1008859 - Adobe Acrobat ImageConversion EMF Integer Overflow Vulnerability (CVE-2017-11308)
1009062 - Adobe Acrobat Pro DC ImageConversion BMP Parsing Out-Of-Bounds Read Information Disclosure Vulnerability (CVE-2017-11253)
1009099 - Adobe Flash Player Type Confusion Vulnerability (CVE-2018-4944)
1009012* - Microsoft JET Database Engine Remote Code Execution Vulnerability (CVE-2018-1003)
1009002* - Microsoft Malware Protection Engine Remote Code Execution Vulnerability (CVE-2018-0986)
1008908* - Microsoft Windows EOT Font Engine Information Disclosure Vulnerability (CVE-2018-0755)
1008943* - Microsoft Windows EOT Font Engine Information Disclosure Vulnerability (CVE-2018-0760)
1008903* - Microsoft Windows EOT Font Engine Information Disclosure Vulnerability (CVE-2018-0761)
1008897* - Microsoft Windows EOT Font Engine Information Disclosure Vulnerability (CVE-2018-0855)
1009014* - Microsoft Windows Graphics Multiple Security Vulnerabilities (Apr-2018)
Web Client Internet Explorer/Edge
1009050 - Microsoft Edge Information Disclosure Vulnerability (CVE-2018-0839)
1008160* - Microsoft Edge Scripting Engine Multiple Memory Corruption Vulnerabilities
1008962 - Microsoft Internet Explorer And Edge Scripting Engine Information Disclosure Vulnerability (CVE-2018-0891)
Web Server Adobe ColdFusion
1008879 - Adobe Coldfusion BlazeDS Java Object Deserialization Remote Code Execution Vulnerability (CVE-2017-3066)
Web Server Apache
1009087 - Apache httpd FilesMatch Directive Security Restriction Bypass Vulnerability (CVE-2017-15715)
Web Server Common
1007185* - Java Unserialize Remote Code Execution Vulnerability
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.