Rule Update
DPIルール他更新情報:19-044(2019年8月27日)
2019年8月27日
概要
* は既存ルールの新バージョンを示します。
DPI(Deep Packet Inspection) ルール:
DHCP Failover Protocolサーバ
1009887* - Microsoft Windows DHCP Server Remote Code Execution Vulnerability (CVE-2019-0785)
HP Intelligent Management Center (IMC)
1008969* - HPE Intelligent Management Center Multiple Expression Language Injection Vulnerabilities
1009947 - HPE Intelligent Management Center Multiple Expression Language Injection Vulnerabilities (CVE-2019-11941 and CVE-2019-11943)
1009456* - HPE Intelligent Management Center Remote Code Execution Vulnerability (CVE-2017-12525)
Redisサーバ
1009949 - Redis Integer Overflow Vulnerability (CVE-2018-11219)
アプリケーションに関連する不審な活動(クライアント)
1009952 - Identified WhatsApp Communication Attempt (ATT&CK T1102)
Webアプリケーション 共通
1009594 - Apache httpd 'mod_md' Null Pointer Dereference Vulnerability (CVE-2018-8011)
1009946 - Atlassian JIRA Template Injection Remote Code Execution Vulnerability (CVE-2019-11581)
Webサーバ Adobe ColdFusion
1009893 - Adobe ColdFusion CFFILE Upload Action Unrestricted File Upload Vulnerability (CVE-2019-7816)
Webサーバ 共通
1009889 - Atlassian Crowd Remote Code Execution Vulnerability (CVE-2019-11580)
1000763* - URI Length Restriction
Webサーバ HTTPS
1009944 - Microsoft Windows HTTP/2 Server Denial Of Service Vulnerability (CVE-2019-9512)
Webサーバ その他
1009804* - Eclipse Jetty HTTP2 SETTINGS Frames Resource Exhaustion Vulnerability (CVE-2018-12545)
1009942 - GNOME 'libsoup' HTTP Chunked Encoding Remote Code Execution Vulnerability (CVE-2017-2885)
Webサーバ Oracle
1009345* - Oracle WebLogic Server Java Deserialization Remote Code Execution Vulnerability
1009845* - Oracle Weblogic Server Remote Code Execution Vulnerability (CVE-2019-2650)
Webサーバ Squid
1009943 - Squid Proxy HttpHeader 'getAuth' Heap Buffer Overflow Vulnerability (CVE-2019-12527)
Windows SMBサーバ
1009910 - Identified Remote Service Creation Over DCE/RPC Protocol (Invoke-SMBexec Tool)
Zoho ManageEngine
1009950 - Zoho ManageEngine OpManager Authenticated Code Execution Vulnerability
変更監視(Integrity Monitoring)ルール:
1005195* - Microsoft Windows - Log File Attributes Changes Detected
1005193* - Unix - Log File Attributes Changes Detected
セキュリティログ監視(Log Inspection)ルール:
今回のセキュリティアップデートには、新規のセキュリティログ監視ルールおよび更新は含まれておりません。
DPI(Deep Packet Inspection) ルール:
DHCP Failover Protocolサーバ
1009887* - Microsoft Windows DHCP Server Remote Code Execution Vulnerability (CVE-2019-0785)
HP Intelligent Management Center (IMC)
1008969* - HPE Intelligent Management Center Multiple Expression Language Injection Vulnerabilities
1009947 - HPE Intelligent Management Center Multiple Expression Language Injection Vulnerabilities (CVE-2019-11941 and CVE-2019-11943)
1009456* - HPE Intelligent Management Center Remote Code Execution Vulnerability (CVE-2017-12525)
Redisサーバ
1009949 - Redis Integer Overflow Vulnerability (CVE-2018-11219)
アプリケーションに関連する不審な活動(クライアント)
1009952 - Identified WhatsApp Communication Attempt (ATT&CK T1102)
Webアプリケーション 共通
1009594 - Apache httpd 'mod_md' Null Pointer Dereference Vulnerability (CVE-2018-8011)
1009946 - Atlassian JIRA Template Injection Remote Code Execution Vulnerability (CVE-2019-11581)
Webサーバ Adobe ColdFusion
1009893 - Adobe ColdFusion CFFILE Upload Action Unrestricted File Upload Vulnerability (CVE-2019-7816)
Webサーバ 共通
1009889 - Atlassian Crowd Remote Code Execution Vulnerability (CVE-2019-11580)
1000763* - URI Length Restriction
Webサーバ HTTPS
1009944 - Microsoft Windows HTTP/2 Server Denial Of Service Vulnerability (CVE-2019-9512)
Webサーバ その他
1009804* - Eclipse Jetty HTTP2 SETTINGS Frames Resource Exhaustion Vulnerability (CVE-2018-12545)
1009942 - GNOME 'libsoup' HTTP Chunked Encoding Remote Code Execution Vulnerability (CVE-2017-2885)
Webサーバ Oracle
1009345* - Oracle WebLogic Server Java Deserialization Remote Code Execution Vulnerability
1009845* - Oracle Weblogic Server Remote Code Execution Vulnerability (CVE-2019-2650)
Webサーバ Squid
1009943 - Squid Proxy HttpHeader 'getAuth' Heap Buffer Overflow Vulnerability (CVE-2019-12527)
Windows SMBサーバ
1009910 - Identified Remote Service Creation Over DCE/RPC Protocol (Invoke-SMBexec Tool)
Zoho ManageEngine
1009950 - Zoho ManageEngine OpManager Authenticated Code Execution Vulnerability
変更監視(Integrity Monitoring)ルール:
1005195* - Microsoft Windows - Log File Attributes Changes Detected
1005193* - Unix - Log File Attributes Changes Detected
セキュリティログ監視(Log Inspection)ルール:
今回のセキュリティアップデートには、新規のセキュリティログ監視ルールおよび更新は含まれておりません。