Rule Update
21-049 (November 9, 2021)
DESCRIPTION
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
DNS Client
1011122 - Zoom Client Marketplace Information Disclosure Vulnerability (ZDI-CAN-13616)
Microsoft Office
1011121* - Microsoft Office Remote Code Execution Vulnerability (CVE-2021-34478)
Web Application Common
1008192* - Identified Directory Traversal Sequence In Multipart HTTP Requests
1009227* - Identified Directory Traversal Sequence In Tar Archive
1009040* - Identified Directory Traversal Sequence In URI
1005933* - Identified Directory Traversal Sequence In Uri Query Parameter
Web Application PHP Based
1011200 - WordPress 'The BulletProof Security' Plugin Information Disclosure Vulnerability (CVE-2021-39327)
1011193* - WordPress 'iThemes Security' Plugin SQL Injection Vulnerability (CVE-2018-12636)
Web Client Common
1011201 - Chromium Use After Free Vulnerability (CVE-2021-30573)
Web Server Apache
1011183* - Apache HTTP Server Server-Side Request Forgery Vulnerability (CVE-2021-40438)
Web Server Common
1010759 - Command Injection Decoder
1008397* - Identified Directory Traversal Attack In HTTP Request Headers
Web Server HTTPS
1011196* - ACME mini_httpd Server Arbitrary File Read Vulnerability (CVE-2018-18778)
1011190* - Centreon 'ProceduresProxy.class.php' SQL Injection Vulnerability (CVE-2021-37558)
1011168* - WordPress 'Supsystic Ultimate Maps' Plugin Reflected Cross-Site Scripting Vulnerability (CVE-2021-24274)
Web Server Miscellaneous
1011177* - Atlassian Confluence Server Arbitrary File Read Vulnerability (CVE-2021-26085)
1011179* - Atlassian Jira Path Traversal Vulnerability (CVE-2021-26086)
Web Server Nagios
1011199 - Nagios XI Command Injection Vulnerability (CVE-2021-40345)
Zoho ManageEngine ADSelfService Plus
1011194* - Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability (CVE-2021-40539)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
1010489* - Auditd - Mitre ATT&CK TA0003: Persistence
1010465* - Auditd - Mitre ATT&CK TA0007: Discovery
1002795* - Microsoft Windows Events
1002831* - Unix - Syslog
Deep Packet Inspection Rules:
DNS Client
1011122 - Zoom Client Marketplace Information Disclosure Vulnerability (ZDI-CAN-13616)
Microsoft Office
1011121* - Microsoft Office Remote Code Execution Vulnerability (CVE-2021-34478)
Web Application Common
1008192* - Identified Directory Traversal Sequence In Multipart HTTP Requests
1009227* - Identified Directory Traversal Sequence In Tar Archive
1009040* - Identified Directory Traversal Sequence In URI
1005933* - Identified Directory Traversal Sequence In Uri Query Parameter
Web Application PHP Based
1011200 - WordPress 'The BulletProof Security' Plugin Information Disclosure Vulnerability (CVE-2021-39327)
1011193* - WordPress 'iThemes Security' Plugin SQL Injection Vulnerability (CVE-2018-12636)
Web Client Common
1011201 - Chromium Use After Free Vulnerability (CVE-2021-30573)
Web Server Apache
1011183* - Apache HTTP Server Server-Side Request Forgery Vulnerability (CVE-2021-40438)
Web Server Common
1010759 - Command Injection Decoder
1008397* - Identified Directory Traversal Attack In HTTP Request Headers
Web Server HTTPS
1011196* - ACME mini_httpd Server Arbitrary File Read Vulnerability (CVE-2018-18778)
1011190* - Centreon 'ProceduresProxy.class.php' SQL Injection Vulnerability (CVE-2021-37558)
1011168* - WordPress 'Supsystic Ultimate Maps' Plugin Reflected Cross-Site Scripting Vulnerability (CVE-2021-24274)
Web Server Miscellaneous
1011177* - Atlassian Confluence Server Arbitrary File Read Vulnerability (CVE-2021-26085)
1011179* - Atlassian Jira Path Traversal Vulnerability (CVE-2021-26086)
Web Server Nagios
1011199 - Nagios XI Command Injection Vulnerability (CVE-2021-40345)
Zoho ManageEngine ADSelfService Plus
1011194* - Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability (CVE-2021-40539)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
1010489* - Auditd - Mitre ATT&CK TA0003: Persistence
1010465* - Auditd - Mitre ATT&CK TA0007: Discovery
1002795* - Microsoft Windows Events
1002831* - Unix - Syslog