Rule Update

22-011 (March 1, 2022)


* indicates a new version of an existing rule

Deep Packet Inspection Rules:

H2 Database
1011316 - H2 Database Remote Code Execution Vulnerability (CVE-2022-23221)

Trend Micro ServerProtect EarthAgent
1011312 - Identified Usage Of Trend Micro ServerProtect Static Credential

Web Application PHP Based
1011298 - WordPress Core Post Slug Stored Cross-Site Scripting Vulnerability (CVE-2022-21662)

Web Server HTTPS
1009761* - Microsoft Exchange Memory Corruption Vulnerability (CVE-2018-8302)
1009496* - Microsoft Exchange Server Multiple Elevation Of Privilege Vulnerabilities
1009467* - Microsoft Exchange Server NTLM Reflection EWS Authentication Bypass Vulnerability (CVE-2018-8581)
1009310* - Microsoft Exchange Server SSRF Vulnerability (CVE-2018-16793)
1010183* - Microsoft Exchange Validation Key Remote Code Execution Vulnerability (CVE-2020-0688)

Zoho ManageEngine
1011254 - Zoho ManageEngine Network Configuration Manager SQL Injection Vulnerability (CVE-2021-41081)

Integrity Monitoring Rules:

1010422* - Linux/Unix - SCP process detected (ATT&CK T1048.001, T1105)
1010791* - Linux/Unix - Task scheduler entries modified (ATT&CK T1053)

Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.