Cloud One Workload Security and Deep Security Updates

  • * indicates a new version of an existing rule

    Deep Packet Inspection Rules:

    DNS Client
    1008203 - DNSMessenger Malware C&C Traffic Over DNS Protocol
    1008204 - DNSMessenger Malware Domain Blocker


    Microsoft Office
    1004312* - Identified Suspicious Microsoft Word Document


    NTP Server Linux
    1007741 - NTP Crypto-NAK Packets Symmetric Association Authentication Bypass Vulnerability (CVE-2015-7871)


    P2P Applications
    1007034* - Share EX2 P2P
    1003086* - Winny


    Web Application PHP Based
    1006386* - PHP 'unserialize()' Integer Overflow Vulnerability (CVE-2014-3669)
    1008135 - PHP Exif Null Pointer Dereference Vulnerability (CVE-2016-6292)
    1007289 - PHP cURL Lib NULL Byte Injection Vulnerability
    1008182 - PHP phar_parse_pharfile Integer Overflow Vulnerability (CVE-2016-10159)
    1007222* - WordPress Ajax Load More Plugin File Upload Vulnerability
    1008186 - phpMyAdmin Authenticated Remote Code Execution Vulnerability (CVE-2013-3238)


    Web Client Common
    1004870* - Identified Suspicious Jar File


    Web Client Internet Explorer/Edge
    1008064* - Microsoft Edge Memory Corruption Vulnerability (CVE-2016-7288)


    Web Server Miscellaneous
    1008104 - Apache ActiveMQ Multiple Remote Code Execution Vulnerabilities (CVE-2016-3088)
    1008207 - Apache Struts2 Remote Code Execution Vulnerability (CVE-2017-5638)
    1008129* - IBM WebSphere Application Server Remote Code Execution Vulnerability (CVE-2016-5983)


    Web Server Oracle
    1004840* - Oracle Application Server Web Cache HTTP Request Method Heap Overrun Vulnerability


    Integrity Monitoring Rules:

    There are no new or updated Integrity Monitoring Rules in this Security Update.


    Log Inspection Rules:

    There are no new or updated Log Inspection Rules in this Security Update.
  • * indicates a new version of an existing rule

    Deep Packet Inspection Rules:

    Backup Server IBM Tivoli Storage Manager FastBack Server
    1007356* - IBM Tivoli Storage Manager FastBack Server Buffer Overflow Vulnerability (CVE-2015-1924)


    Database Oracle
    1003340* - Oracle Database Trigger MDSYS.SDO_TOPO_DROP_FTBL SQL Injection


    Microsoft Office
    1004311* - Identified Suspicious Microsoft PowerPoint Document


    VoIP Smart
    1008087* - IBM WebSphere Application Server SIP Processing DoS Vulnerability (CVE-2016-2960)


    Web Application Common
    1000608* - Generic SQL Injection Prevention


    Web Application PHP Based
    1008144 - PHP Remote Code Execution Vulnerability (CVE-2017-5340)


    Web Client Common
    1004335* - Apple QuickTime 'QuickTimeStreaming.qtx' Remote Stack Buffer Overflow
    1008185 - Identified Suspicious Obfuscated PDF Document
    1008028 - Microsoft Windows File Manager Remote Code Execution Vulnerability (CVE-2016-7212)
    1008147 - Microsoft Windows RPC Network Data Representation Engine Remote Code Execution Vulnerability (CVE-2016-0178)


    Web Client Mozilla Firefox
    1007061* - Mozilla Firefox Arbitrary JavaScript Code Execution
    1007062* - Mozilla Firefox Arbitrary JavaScript Execution Vulnerability (CVE-2015-0802)
    1008052* - Mozilla Firefox SVG Animation Use After Free Vulnerability (CVE-2016-9079)


    Web Server Adobe ColdFusion
    1008113 - Adobe ColdFusion OOXML XXE Information Disclosure Vulnerability (CVE-2016-4264)


    Web Server Common
    1005671* - PHP SSL Module "subjectAltNames" NULL Byte Handling Security Vulnerability


    Integrity Monitoring Rules:

    There are no new or updated Integrity Monitoring Rules in this Security Update.


    Log Inspection Rules:

    There are no new or updated Log Inspection Rules in this Security Update.
  • * indicates a new version of an existing rule

    Deep Packet Inspection Rules:

    Web Client Internet Explorer/Edge
    1008153 - Microsoft Internet Explorer And Edge Memory Corruption Vulnerability (CVE-2017-0037)


    Integrity Monitoring Rules:

    There are no new or updated Integrity Monitoring Rules in this Security Update.


    Log Inspection Rules:

    There are no new or updated Log Inspection Rules in this Security Update.
  • * indicates a new version of an existing rule

    Deep Packet Inspection Rules:

    DCERPC Services - Client
    1008138* - Microsoft Windows SMB Tree Connect Response Denial Of Service Vulnerability (CVE-2017-0016)


    DNS Client
    1008180 - ISC BIND Inconsistent DS Record Assertion Failure Denial Of Service Vulnerability (CVE-2016-9444)
    1008136 - ISC BIND RRSIG Record Response Assertion Failure Denial Of Service (CVE-2016-9147)


    Suspicious Client Ransomware Activity
    1007579* - Ransomware HTTP Request


    Unix Kerberos
    1008095* - MIT Kerberos 'kadmin' DB Denial Of Service Vulnerability (CVE-2016-3119)


    Web Application Common
    1007609* - ImageMagick Remote Code Execution Vulnerability (CVE-2016-3714)


    Web Application PHP Based
    1008125 - Joomla Denial Of Service Vulnerability (CVE-2013-3242)
    1008037 - PHP GC Use After Free Vulnerability (CVE-2016-5771)
    1008131 - PHP Unserialize() ZVAL Reference Counter Overflow Vulnerability (CVE-2007-1286)
    1008140* - WordPress REST API Unauthenticated Content Injection Vulnerability
    1008132* - phpMyAdmin RegEx Pattern Modifier Code Injection Vulnerability (CVE-2016-5734)


    Web Client Common
    1008121* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB17-01) - 2
    1008183 - Adobe Flash Player Multiple Security Vulnerabilities (APSB17-04)
    1008171 - Microsoft Windows Graphics Component Information Disclosure Vulnerability (CVE-2017-0038)
    1008108 - Oracle Java Uninitialized Object Generation Remote Code Execution Vulnerability (CVE-2016-3606)


    Web Client Internet Explorer/Edge
    1008064* - Microsoft Edge Memory Corruption Vulnerability (CVE-2016-7288)


    Web Media Applications
    1002451* - YouTube


    Web Server Miscellaneous
    1008097* - Identified Apache Struts Incorrect Default 'excludeParams' Security Bypass Vulnerability
    1008141 - Jetty Path Sanitization Vulnerability (CVE-2016-4800)
    1008093* - Oracle GlassFish Server Username And Password Brute Force Vulnerability (CVE-2011-0807)


    Integrity Monitoring Rules:

    There are no new or updated Integrity Monitoring Rules in this Security Update.


    Log Inspection Rules:

    There are no new or updated Log Inspection Rules in this Security Update.
  • * indicates a new version of an existing rule

    Deep Packet Inspection Rules:

    Backup Server IBM Tivoli Storage Manager FastBack Server
    1007357* - IBM Tivoli Storage Manager FastBack Server Buffer Overflow (CVE-2015-1929)


    DCERPC Services
    1008123* - Microsoft Windows Local Security Authority Subsystem Service Denial Of Service Vulnerability (CVE-2016-7237)


    DCERPC Services - Client
    1008138* - Microsoft Windows SMB Tree Connect Response Denial Of Service Vulnerability (CVE-2017-0016)


    DNS Client
    1008128* - ISC BIND ANY Query Assertion Failure Vulnerability (CVE-2016-9131)
    1008115* - ISC BIND DNAME Resource Records Denial Of Service Vulnerability (CVE-2016-1286)


    Directory Server LDAP
    1007360* - IBM Domino LDAP Server Remote Execution Vulnerability (CVE-2015-0117)
    1008051* - Samba Active Directory Server Denial Of Service Vulnerability (CVE-2015-3223)


    HP OpenView
    1008110* - HP Data Protector Buffer Overflow Vulnerability (CVE-2016-2005)
    1008114* - HP Data Protector Multiple Remote Code Execution Vulnerabilities
    1008109* - HP Data Protector Remote Code Execution Vulnerability (CVE-2016-2007)


    HP OpenView Network Node Manager
    1007466* - HP OpenView Network Node Manager Ovalarmsrv Service Buffer Overflow (CVE-2008-1852)


    Microsoft Office
    1008075* - Microsoft Office Information Disclosure Vulnerability (CVE-2016-7264)
    1008078* - Microsoft Office Memory Corruption Vulnerability (CVE-2016-7289)


    NTP Server Linux
    1007383* - NTP Configuration Directive File Overwrite Vulnerability (CVE-2015-7703)
    1007399* - NTP Long Control Packet Message Denial Of Service Vulnerability (CVE-2015-7855)
    1008091* - NTP Oversized UDP Packet Denial Of Service Vulnerability (CVE-2016-9312)


    Suspicious Client Application Activity
    1005067* - Identified Potentially Harmful Client Traffic
    1005283* - Identified Potentially Malicious RAT Traffic - I
    1005299* - Identified Potentially Malicious RAT Traffic - III
    1005300* - Identified Potentially Malicious RAT Traffic - IV
    1005473* - Identified Potentially Malicious RAT Traffic - V
    1006247* - Identified Potentially Malicious RAT Traffic - VI
    1007116* - VMware vCenter Java JMX Server Insecure Configuration Java Code Execution Vulnerability


    Suspicious Server Application Activity
    1005974* - Identified DNS Reflected Denial Of Service
    1006560* - Identified Microsoft SQL Server Resolution Service Distributed Denial Of Service Attack
    1006240* - Identified NTP Reflected Denial Of Service
    1005090* - Identified Potentially Harmful Server Traffic
    1005957* - Identified SNMP Reflected Denial Of Service
    1005910* - Identified ntpd 'monlist' Query Reflected Denial Of Service Attack
    1005517* - Restrict Maximum Packet (Transport Data Length) Size


    Unix Kerberos
    1008095 - MIT Kerberos 'kadmin' DB Denial Of Service Vulnerability (CVE-2016-3119)


    Web Application PHP Based
    1007178* - WordPress Font Plugin Path Traversal Vulnerability (CVE-2015-7683)
    1008132 - phpMyAdmin RegEx Pattern Modifier Code Injection Vulnerability (CVE-2016-5734)


    Web Client Common
    1008124* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB17-01) - 1
    1008121* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB17-01) - 2
    1008133* - Cisco WebEx Plugin Magic URL Arbitrary Remote Command Execution Vulnerability
    1004114* - Identified Malicious Adobe SWF File
    1008139 - Linux Kernel Use After Free Remote Code Execution Vulnerability (CVE-2016-7117)
    1008068* - Microsoft Windows Graphics Remote Code Execution Vulnerability (CVE-2016-7272)
    1008052* - Mozilla Firefox SVG Animation Use After Free Vulnerability (CVE-2016-9079)


    Web Proxy Squid
    1008103* - Squid Proxy ESI Response Handler Buffer Overflow Vulnerability (CVE-2016-4054)
    1008101 - Squid Proxy ESI Response Processing Denial Of Service Vulnerability (CVE-2016-4555)


    Web Server Common
    1000473* - Parameter Name Length Restriction


    Web Server Miscellaneous
    1008120* - Apache Jetspeed Portal Site Manager ZIP File Upload Directory Traversal (CVE-2016-0709)
    1008129 - IBM WebSphere Application Server Remote Code Execution Vulnerability (CVE-2016-5983)
    1008097 - Identified Apache Struts Incorrect Default 'excludeParams' Security Bypass Vulnerability
    1008093 - Oracle GlassFish Server Username And Password Brute Force Vulnerability (CVE-2011-0807)


    Web Server Oracle HTTPS
    1003212* - Oracle Secure Backup exec_qr() Command Injection Vulnerability


    Windows Services RPC Client DCERPC
    1007538* - Windows Client Port Mapper Decoder


    Integrity Monitoring Rules:

    There are no new or updated Integrity Monitoring Rules in this Security Update.


    Log Inspection Rules:

    There are no new or updated Log Inspection Rules in this Security Update.
  • * indicates a new version of an existing rule

    Deep Packet Inspection Rules:

    DCERPC Services - Client
    1008138 - Microsoft Windows SMB Tree Connect Response Denial Of Service Vulnerability (CVE-2017-0016)


    Web Application PHP Based
    1008140 - WordPress REST API Unauthenticated Content Injection Vulnerability


    Integrity Monitoring Rules:

    There are no new or updated Integrity Monitoring Rules in this Security Update.


    Log Inspection Rules:

    There are no new or updated Log Inspection Rules in this Security Update.
  • * indicates a new version of an existing rule

    Deep Packet Inspection Rules:

    Web Client Common
    1008133 - Cisco WebEx Plugin Magic URL Arbitrary Remote Command Execution Vulnerability


    Integrity Monitoring Rules:

    There are no new or updated Integrity Monitoring Rules in this Security Update.


    Log Inspection Rules:

    There are no new or updated Log Inspection Rules in this Security Update.
  • * indicates a new version of an existing rule

    Deep Packet Inspection Rules:

    BIND RNDC
    1008099 - ISC BIND rndc Control Channel Denial Of Service Vulnerability (CVE-2016-1285)


    DCERPC Services
    1007596* - Identified Possible Ransomware File Extension Rename Activity Over Network Share
    1008119 - Microsoft Windows Local Security Authority Subsystem Service (LSASS) Denial Of Service Vulnerability (CVE-2017-0004)


    DCERPC Services - Client
    1007913* - Identified Possible Ransomware File Extension Rename Activity Over Network Share - Client


    DNS Client
    1008053* - ISC BIND DNAME Answer Handling Denial Of Service Vulnerability (CVE-2016-8864)
    1007740* - ISC BIND Multiple DNS Cookies Denial Of Service Vulnerability (CVE-2016-2088)
    1008085 - Nginx DNS UDP Packet Handler Crash Denial Of Service Vulnerability (CVE-2016-0742)


    DNS Server
    1008092 - ISC BIND Assertion Failure Denial Of Service Vulnerability (CVE-2016-2848)
    1008105 - PowerDNS Authoritative Server Long Qname Denial Of Service Vulnerability (CVE-2016-5426)


    Directory Server LDAP
    1007360 - IBM Domino LDAP Server Remote Execution Vulnerability (CVE-2015-0117)
    1007932* - Microsoft Windows Remote Code Execution Vulnerability (CVE-2016-3368)


    ISC LightWeight DNS Resolver
    1008100 - ISC BIND Long Name Query DOS Vulnerability (CVE-2016-2775)


    Microsoft Office
    1008116 - Microsoft Office Memory Corruption Vulnerability (CVE-2017-0003)


    NTP Server Linux
    1008040* - NTP AutoKey Malicious Message Multiple Denial Of Service Vulnerabilities
    1007383* - NTP Configuration Directive File Overwrite Vulnerability (CVE-2015-7703)
    1008086 - NTP Daemon CRYPTO_NAK Denial Of Service Vulnerability (CVE-2016-4957)
    1008048* - NTP Mrulist Malicious Query Denial Of Service Vulnerability (CVE-2016-7434)


    Novell GroupWise Admin Service
    1006822* - Novell Groupwise "poLibMaintenanceFileSave" Security Bypass Vulnerability


    SSL Client
    1008088 - GnuTLS Libtasn1 ASN.1 DER Infinite Loop Denial Of Service Vulnerability (CVE-2016-4008) - Client


    SSL/TLS Server
    1008089 - GnuTLS Libtasn1 ASN.1 DER Infinite Loop Denial Of Service Vulnerability (CVE-2016-4008) - Server


    Suspicious Client Ransomware Activity
    1007704* - Ransomware Network Traffic - 1


    Web Application Common
    1008050 - ImageMagick Out Of Bounds Array Indexing Denial Of Service Vulnerability (CVE-2016-7799)
    1008046 - ImageMagick SGI Coder Out Of Bounds Read Vulnerability (CVE-2016-7101)


    Web Application PHP Based
    1008096 - Identified Drupal Core system.temporary Information Disclosure Vulnerability
    1008118 - Identified Suspicious Upload Of WordPress Plugin
    1008038* - PHP GC ZipArchive Class Use After Free Vulnerability (CVE-2016-5773)


    Web Client Common
    1008049 - ImageMagick Out Of Bounds Array Indexing Denial Of Service Vulnerability (CVE-2016-7799) - 1
    1008047 - ImageMagick SGI Coder Out Of Bounds Read Vulnerability (CVE-2016-7101) - 1
    1007427* - Microsoft Windows DLL Loading Vulnerabilities Over WebDAV (MS16-014)
    1008067* - Microsoft Windows Uniscribe Remote Code Execution Vulnerability (CVE-2016-7274)


    Web Server Miscellaneous
    1008001* - MongoDB Javascript Injection Collection Enumeration Vulnerability


    Integrity Monitoring Rules:

    There are no new or updated Integrity Monitoring Rules in this Security Update.


    Log Inspection Rules:

    1003802* - Directory Server – Microsoft Windows Active Directory
  • * indicates a new version of an existing rule

    Deep Packet Inspection Rules:

    DCERPC Services - Client
    1007426* - Microsoft Windows DLL Loading Vulnerabilities Over Network Share (MS16-014)


    Novell GroupWise Admin Service
    1006822 - Novell Groupwise "poLibMaintenanceFileSave" Security Bypass Vulnerability


    Web Application PHP Based
    1007642 - WordPress Comment Handler Same Origin Method Execution Vulnerability (CVE-2015-3439)


    Web Client Common
    1007997* - Adobe Acrobat And Reader Multiple Memory Corruption Vulnerabilities (APSB16-33) - 2


    Web Server Miscellaneous
    1008001 - MongoDB Javascript Injection Collection Enumeration Vulnerability
    1005557* - Novell ZENWorks Mobile Management Multiple Directory Traversal Vulnerabilities


    Integrity Monitoring Rules:

    There are no new or updated Integrity Monitoring Rules in this Security Update.


    Log Inspection Rules:

    There are no new or updated Log Inspection Rules in this Security Update.
  • * indicates a new version of an existing rule

    Deep Packet Inspection Rules:

    DNS Client
    1007740 - ISC BIND Multiple DNS Cookies Denial Of Service Vulnerability (CVE-2016-2088)


    Directory Server LDAP
    1007932* - Microsoft Windows Remote Code Execution Vulnerability (CVE-2016-3368)


    Web Application Common
    1007610* - Identified Usage Of ImageMagick Pseudo Protocols


    Web Application PHP Based
    1008041 - Drupal Coder Module Remote Code Execution Vulnerability


    Web Application Ruby Based
    1005331* - Ruby On Rails XML Processor YAML Deserialization DoS


    Web Application Tomcat
    1000637* - Tomcat JSP Source Code Exposure Vulnerability (CVE-2002-1148)


    Web Client Common
    1008090 - Adobe Flash Player Multiple Security Vulnerabilities (APSB16-39)
    1008033* - Microsoft Windows Elevation Of Privilege Vulnerability (CVE-2016-7255)


    Web Client Internet Explorer/Edge
    1008063* - Microsoft Edge Memory Corruption Vulnerability (CVE-2016-7286)
    1008009* - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2016-7201)
    1007920* - Microsoft Internet Explorer And Edge Memory Corruption Vulnerability (CVE-2016-3247)
    1005366* - Microsoft Internet Explorer COMWindowProxy Use After Free Vulnerability (CVE-2013-0019)


    Web Server Miscellaneous
    1007650 - Identified Access To NetIQ URLs Prone To Information Disclosure Vulnerability (CVE-2014-5215)


    Integrity Monitoring Rules:

    There are no new or updated Integrity Monitoring Rules in this Security Update.


    Log Inspection Rules:

    There are no new or updated Log Inspection Rules in this Security Update.