*** EX RELS 03486 Release *** Total number of signatures: 6040 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 23 rule(s): --------------- 1137042 EXPLOIT Oracle WebLogic CVE-2020-2798 Insecure Deserialization 1137063 WEB Opmantek Open-AudIT m_discoveries.php Command Injection (CVE-2020-11941) 1137064 FILE Foxit PhantomPDF text Field Object Use After Free (CVE-2020-8846) 1137066 WEB Cisco Data Center Network Manager installSwitchLicense Directory Traversal -1 (CVE-2019-15980) 1137069 SNMP AwindInc SNMP Service Command Injection (CVE-2017-16709) 1137070 EXPLOIT QNAP Transcode Server Command Execution (CVE-2017-13067) 1137071 WEB Unitrends UEB http api remote code execution (CVE-2017-12478) 1137072 WEB Unitrends UEB http api remote code execution (CVE-2018-6328) 1137074 SNMP Net-SNMP PDU Heap Overflow -3 (CVE-2018-1000116) 1137075 WEB Oracle Business Intelligence And XML Publisher XML External Entity Injection (CVE-2019-2616) 1137076 EXPLOIT Unitrends UEB bpserverd authentication bypass RCE (CVE-2017-12477) 1137077 WEB OrientDB 2.2.x Remote Code Execution (CVE-2017-11467) 1137090 WEB Jenkins CLI HTTP Java Deserialization Vulnerability (CVE-2016-9299) 1137092 WEB QNAP QCenter change_passwd Command Execution (CVE-2018-0707) 1137093 EXPLOIT SaltStack Salt ClearFuncs Directory Traversal -3 (CVE-2020-11652) 1137096 WEB Cisco UCS Director Cloupia Script RCE (CVE-2020-3243) 1137098 WEB Cisco UCS Director Cloupia Script RCE -1 (CVE-2020-3250) 1137099 WEB Cisco UCS Director Cloupia Script RCE -2 (CVE-2020-3250) 1137100 DNS ISC BIND TSIG Assertion Failure Denial of Service (CVE-2020-8617) 1137101 WEB WordPress Drag And Drop Multi File Uploader Remote Code Execution (CVE-2020-12800) 1137102 WEB VMware Cloud Director RCE (CVE-2020-3956) 1137103 WEB Moodle CMS questiontype.php Answer Remote Code Execution -3.1 (CVE-2018-1133) 1137104 WEB Moodle CMS questiontype.php Answer Remote Code Execution -3.2 (CVE-2018-1133) Modified 2 rule(s): --------------- 1133081 WEB-CLIENT Microsoft Edge Array.join Type Confusion (CVE-2016-7189) 1136912 EXPLOIT Oracle WebLogic Server 12.2.1.4.0 - Remote Code Execution (CVE-2020-2555) Deleted 0 rule(s): ---------------