概要

* は既存ルールの新バージョンを示します。

DPI(Deep Packet Inspection) ルール:

IPSec-IKE
1011536* - Microsoft Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability (CVE-2022-34721)


SolarWinds Information Service
1011642 - SolarWinds Network Performance Monitor Insecure Deserialization Vulnerability (CVE-2022-36964)


SolarWinds Orion Platform
1011630* - SolarWinds Network Performance Monitor Command Injection Vulnerability (CVE-2022-36962)


Splunk Enterprise
1011640* - Splunk Enterprise Cross-Site Scripting Vulnerability (CVE-2022-43568)


Webアプリケーション 共通
1011649 - pgAdmin Remote Code Execution Vulnerability (CVE-2022-4223)


Webアプリケーション PHP
1011644* - LibreNMS Stored Cross-Site Scripting Vulnerability (CVE-2022-4067)
1011643* - WordPress 'Limit Login Attempts' Plugin Cross-Site Scripting Vulnerability (CVE-2020-35589)
1011637* - WordPress 'Simple School Staff Directory' Plugin Arbitrary File Upload Vulnerability (CVE-2021-24663)
1011636* - WordPress 'ThinkTwit' Plugin Cross-Site Scripting Vulnerability (CVE-2021-24582)
1011635* - WordPress 'youForms Free For CopeCart' Plugin Cross-Site Scripting Vulnerability (CVE-2021-24596)


Webサーバ Adobe ColdFusion
1011557* - Adobe ColdFusion Directory Traversal Vulnerability (CVE-2022-38421)


Webサーバ 共通
1011646 - Apache Airflow Command Injection Vulnerability (CVE-2022-40127)


Webサーバ HTTPS
1011573* - Centreon 'Poller Broker' SQL Injection Vulnerability (CVE-2022-42429)


変更監視(Integrity Monitoring)ルール:

今回のセキュリティアップデートには、新規の変更監視ルールおよび更新は含まれておりません。


セキュリティログ監視(Log Inspection)ルール:

1010002* - Microsoft PowerShell Command Execution (ATT&CK T1059.001)
1002795* - Microsoft Windows Events
1011453* - Microsoft Windows WMI Events - 1