Trend Micro Security
  Rule Update

19-059 (2019年12月3日)


  概要

* indicates a new version of an existing rule

Deep Packet Inspection Rules:

DHCP Server
1008591* - FreeRADIUS Integer Underflow Out Of Bounds Read Vulnerability (CVE-2017-10986)


SolarWinds Dameware Mini Remote Control
1010070 - SolarWinds DameWare Mini Remote Control RsaPubKeyLen Heap Buffer Overflow Vulnerability (CVE-2019-3955)


Solr Service
1010063* - Apache Solr 'Velocity Template' Command Injection Vulnerability (CNVD-2019-38290)
1010038* - Apache Solr DataImportHandler Remote Code Execution Vulnerability (CVE-2019-0193)


Trend Micro OfficeScan
1010041* - Trend Micro ApexOne And OfficeScan Directory Traversal Vulnerability (CVE-2019-18189)


Web Application Common
1010074 - Disallow Unvalidated Redirect And Forward Over HTTP In URIQUERY
1010075 - Expat XML Parsing Remote Denial of Service Vulnerability (CVE-2018-20843) - Server
1010046* - rConfig Remote Command Execution Vulnerability (CVE-2019-16662)


Web Application PHP Based
1010056 - Joomla Remote Code Execution Vulnerability
1010065* - PHP EXIF Uninitialized Read Vulnerabilities (CVE-2019-9638 and CVE-2019-9639)
1010064* - PHP Exif Heap Buffer Overflow Vulnerability (CVE-2019-11040)


Web Client Common
1010076 - Expat XML Parsing Remote Denial of Service Vulnerability (CVE-2018-20843) - Client


Web Client VNC
1010078 - TightVNC VNCViewer Integer Overflow Vulnerability (CVE-2019-15678)


Web Server Common
1010044* - PHP Unauthenticated Remote Code Execution Vulnerability (CVE-2019-11043)
1000763* - URI Length And Depth Restriction


Web Server Oracle
1010045* - Oracle Event Processing Arbitrary File Upload Vulnerability (CVE-2014-2424)
1010069 - Oracle WebLogic Server XML External Entity Injection Vulnerability (CVE-2019-2888)
1010077 - Oracle Weblogic Insecure Deserialization Vulnerability (CVE-2019-2890)


Zoho ManageEngine
1010061 - Zoho ManageEngine OpManager OPMDeviceDetailsServlet Category SQL Injection Vulnerability (CVE-2019-17602)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.