VMSA-2022-0010
CVSSv3 Range: 9.8
Issue Date: 2022-04-02
Updated On: 2022-04-02 (Initial Advisory)
CVE(s): CVE-2022-22965
Synopsis:
VMware Response to Spring Framework Remote Code Execution Vulnerability, aka Spring4Shell (CVE-2022-22965)
Impacted Products
VMware Tanzu Application Service for VMs
VMware Tanzu Operations Manager
VMware Tanzu Kubernetes Grid Integrated Edition (TKGI)
https://www.vmware.com/security/advisories/VMSA-2022-0010.html
CVSSv3 Range: 9.8
Issue Date: 2022-04-02
Updated On: 2022-04-02 (Initial Advisory)
CVE(s): CVE-2022-22965
Synopsis:
VMware Response to Spring Framework Remote Code Execution Vulnerability, aka Spring4Shell (CVE-2022-22965)
Impacted Products
VMware Tanzu Application Service for VMs
VMware Tanzu Operations Manager
VMware Tanzu Kubernetes Grid Integrated Edition (TKGI)
https://www.vmware.com/security/advisories/VMSA-2022-0010.html
CVE-2022-26871 Detail
NVD Published Date: 03/29/2022
NVD Last Modified: 03/30/2022
Source: Trend Micro, Inc.
Description
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
https://nvd.nist.gov/vuln/detail/CVE-2022-26871
NVD Published Date: 03/29/2022
NVD Last Modified: 03/30/2022
Source: Trend Micro, Inc.
Description
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
https://nvd.nist.gov/vuln/detail/CVE-2022-26871
Boletín de seguridad de Android de abril de 2022
Fecha de publicación: 05/04/2022
Importancia: 4 - Alta
Recursos afectados:
Android Open Source Project (AOSP):
Versiones 10, 11, 12 y 12L.
Descripción:
El boletín mensual de Android de abril de 2022 soluciona 3 vulnerabilidades de severidad alta que afectan al sistema, y que podrían permitir a un cibedelincuente la escalada remota de privilegios, sin necesidad de privilegios de ejecución adicionales ni interacción por parte del usuario, y la divulgación de información.
https://www.incibe.es/protege-tu-empresa/avisos-seguridad/boletin-seguridad-android-abril-2022
Fecha de publicación: 05/04/2022
Importancia: 4 - Alta
Recursos afectados:
Android Open Source Project (AOSP):
Versiones 10, 11, 12 y 12L.
Descripción:
El boletín mensual de Android de abril de 2022 soluciona 3 vulnerabilidades de severidad alta que afectan al sistema, y que podrían permitir a un cibedelincuente la escalada remota de privilegios, sin necesidad de privilegios de ejecución adicionales ni interacción por parte del usuario, y la divulgación de información.
https://www.incibe.es/protege-tu-empresa/avisos-seguridad/boletin-seguridad-android-abril-2022
INCIBE
Boletín de seguridad de Android de abril de 2022
SysAdmin 24x7
VMSA-2022-0010 CVSSv3 Range: 9.8 Issue Date: 2022-04-02 Updated On: 2022-04-02 (Initial Advisory) CVE(s): CVE-2022-22965 Synopsis: VMware Response to Spring Framework Remote Code Execution Vulnerability, aka Spring4Shell (CVE-2022-22965) Impacted Products…
https://t.me/sysadmin24x7/4927
Actualización de contenido sobre vulnerabilidad
VMSA-2022-0010.1
CVSSv3 Range: 9.8
Issue Date: 2022-04-02
Updated On: 2022-04-06
CVE(s): CVE-2022-22965
Synopsis:
VMware Response to Spring Framework Remote Code Execution Vulnerability (CVE-2022-22965)
Impacted Products
VMware Tanzu Application Service for VMs
VMware Tanzu Operations Manager
VMware Tanzu Kubernetes Grid Integrated Edition (TKGI)
https://www.vmware.com/security/advisories/VMSA-2022-0010.html
Actualización de contenido sobre vulnerabilidad
VMSA-2022-0010.1
CVSSv3 Range: 9.8
Issue Date: 2022-04-02
Updated On: 2022-04-06
CVE(s): CVE-2022-22965
Synopsis:
VMware Response to Spring Framework Remote Code Execution Vulnerability (CVE-2022-22965)
Impacted Products
VMware Tanzu Application Service for VMs
VMware Tanzu Operations Manager
VMware Tanzu Kubernetes Grid Integrated Edition (TKGI)
https://www.vmware.com/security/advisories/VMSA-2022-0010.html
Telegram
SysAdmin 24x7
VMSA-2022-0010
CVSSv3 Range: 9.8
Issue Date: 2022-04-02
Updated On: 2022-04-02 (Initial Advisory)
CVE(s): CVE-2022-22965
Synopsis:
VMware Response to Spring Framework Remote Code Execution Vulnerability, aka Spring4Shell (CVE-2022-22965)
Impacted Products…
CVSSv3 Range: 9.8
Issue Date: 2022-04-02
Updated On: 2022-04-02 (Initial Advisory)
CVE(s): CVE-2022-22965
Synopsis:
VMware Response to Spring Framework Remote Code Execution Vulnerability, aka Spring4Shell (CVE-2022-22965)
Impacted Products…
Vulnerabilidad SQLi en FortiWAN de Fortinet
Fecha de publicación: 06/04/2022
Importancia: 5 - Crítica
Recursos afectados:
FortiWAN 4.5.8 y anteriores.
Descripción:
Giuseppe Cocomazzi, del equipo Fortinet Product Security, ha descubierto esta vulnerabilidad crítica que podría permitir a un atacante ejecutar código o comandos no autorizados.
Solución:
Actualizar a FortiWAN 4.5.9 o superior.
https://www.incibe-cert.es/alerta-temprana/avisos-seguridad/vulnerabilidad-sqli-fortiwan-fortinet
Fecha de publicación: 06/04/2022
Importancia: 5 - Crítica
Recursos afectados:
FortiWAN 4.5.8 y anteriores.
Descripción:
Giuseppe Cocomazzi, del equipo Fortinet Product Security, ha descubierto esta vulnerabilidad crítica que podría permitir a un atacante ejecutar código o comandos no autorizados.
Solución:
Actualizar a FortiWAN 4.5.9 o superior.
https://www.incibe-cert.es/alerta-temprana/avisos-seguridad/vulnerabilidad-sqli-fortiwan-fortinet
www.incibe.es
Vulnerabilidad SQLi en FortiWAN de Fortinet
Giuseppe Cocomazzi, del equipo Fortinet Product Security, ha descubierto esta vulnerabilidad crítica q
VMSA-2022-0011
CVSSv3 Range: 5.3-9.8
Issue Date: 2022-04-06
CVE(s): CVE-2022-22954, CVE-2022-22955, CVE-2022-22956, CVE-2022-22957, CVE-2022-22958, CVE-2022-22959, CVE-2022-22960, CVE-2022-22961
Synopsis:
VMware Workspace ONE Access, Identity Manager and vRealize Automation updates address multiple vulnerabilities.
Impacted Products:
VMware Workspace ONE Access (Access)
VMware Identity Manager (vIDM)
VMware vRealize Automation (vRA)
VMware Cloud Foundation
vRealize Suite Lifecycle Manager
https://www.vmware.com/security/advisories/VMSA-2022-0011.html
CVSSv3 Range: 5.3-9.8
Issue Date: 2022-04-06
CVE(s): CVE-2022-22954, CVE-2022-22955, CVE-2022-22956, CVE-2022-22957, CVE-2022-22958, CVE-2022-22959, CVE-2022-22960, CVE-2022-22961
Synopsis:
VMware Workspace ONE Access, Identity Manager and vRealize Automation updates address multiple vulnerabilities.
Impacted Products:
VMware Workspace ONE Access (Access)
VMware Identity Manager (vIDM)
VMware vRealize Automation (vRA)
VMware Cloud Foundation
vRealize Suite Lifecycle Manager
https://www.vmware.com/security/advisories/VMSA-2022-0011.html
Citrix Hypervisor Security Update
Description of Problem
A security issue has been identified that affects Citrix Hypervisor.
This issue may allow privileged code in a guest VM to cause the host to crash or become unresponsive. The issue only affects systems with Intel CPUs where the malicious guest VM has had a physical PCI device assigned to it by the host administrator using the PCI passthrough feature.
The issue has the following identifier:
CVE-2022-26357
Customers who have not assigned a physical PCI device to a guest VM are not affected by this issue. Customers who are running on systems with only AMD CPUs are also not affected by this issue.
https://support.citrix.com/article/CTX390511
Description of Problem
A security issue has been identified that affects Citrix Hypervisor.
This issue may allow privileged code in a guest VM to cause the host to crash or become unresponsive. The issue only affects systems with Intel CPUs where the malicious guest VM has had a physical PCI device assigned to it by the host administrator using the PCI passthrough feature.
The issue has the following identifier:
CVE-2022-26357
Customers who have not assigned a physical PCI device to a guest VM are not affected by this issue. Customers who are running on systems with only AMD CPUs are also not affected by this issue.
https://support.citrix.com/article/CTX390511
VMSA-2022-0012
CVSSv3 Range: 7.3
Issue Date: 2022-04-06
CVE(s): CVE-2022-22962, CVE-2022-22964
Synopsis:
VMware Horizon Client for Linux update addresses multiple vulnerabilities (CVE-2022-22962, CVE-2022-22964)
Impacted Products
VMware Horizon Client for Linux
https://www.vmware.com/security/advisories/VMSA-2022-0012.html
CVSSv3 Range: 7.3
Issue Date: 2022-04-06
CVE(s): CVE-2022-22962, CVE-2022-22964
Synopsis:
VMware Horizon Client for Linux update addresses multiple vulnerabilities (CVE-2022-22962, CVE-2022-22964)
Impacted Products
VMware Horizon Client for Linux
https://www.vmware.com/security/advisories/VMSA-2022-0012.html
VMware
VMSA-2022-0012.1
VMware Horizon Agent for Linux update addresses multiple vulnerabilities (CVE-2022-22962, CVE-2022-22964)
ICS Medical Advisory (ICSMA-21-187-01)
Philips Vue PACS (Update B)
CVSS v3: 9.8
ATTENTION: Exploitable remotely/low attack complexity
Vendor: Philips
Equipment: Vue PACS
Vulnerabilities: Cleartext Transmission of Sensitive Information, Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Input Validation, Improper Authentication, Improper Initialization, Use of a Broken or Risky Cryptographic Algorithm, Protection Mechanism Failure, Use of a Key Past its Expiration Date, Insecure Default Initialization of Resource, Improper Handling of Unicode Encoding, Insufficiently Protected Credentials, Data Integrity Issues, Cross-site Scripting, Improper Neutralization, Use of Obsolete Function, Relative Path Traversal
https://www.cisa.gov/uscert/ics/advisories/icsma-21-187-01
Philips Vue PACS (Update B)
CVSS v3: 9.8
ATTENTION: Exploitable remotely/low attack complexity
Vendor: Philips
Equipment: Vue PACS
Vulnerabilities: Cleartext Transmission of Sensitive Information, Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Input Validation, Improper Authentication, Improper Initialization, Use of a Broken or Risky Cryptographic Algorithm, Protection Mechanism Failure, Use of a Key Past its Expiration Date, Insecure Default Initialization of Resource, Improper Handling of Unicode Encoding, Insufficiently Protected Credentials, Data Integrity Issues, Cross-site Scripting, Improper Neutralization, Use of Obsolete Function, Relative Path Traversal
https://www.cisa.gov/uscert/ics/advisories/icsma-21-187-01
https://t.me/sysadmin24x7/4927
Actualización de contenido sobre vulnerabilidad
VMSA-2022-0010.2
CVSSv3 Range: 9.8
Issue Date: 2022-04-02
Updated On: 2022-04-06
CVE(s):CVE-2022-22965
Synopsis:
VMware Response to Spring Framework Remote Code Execution Vulnerability (CVE-2022-22965)
Impacted Products
VMware Tanzu Application Service for VMs (TAS)
VMware Tanzu Operations Manager (Ops Manager)
VMware Tanzu Kubernetes Grid Integrated Edition (TKGI)
https://www.vmware.com/security/advisories/VMSA-2022-0010.html
Actualización de contenido sobre vulnerabilidad
VMSA-2022-0010.2
CVSSv3 Range: 9.8
Issue Date: 2022-04-02
Updated On: 2022-04-06
CVE(s):CVE-2022-22965
Synopsis:
VMware Response to Spring Framework Remote Code Execution Vulnerability (CVE-2022-22965)
Impacted Products
VMware Tanzu Application Service for VMs (TAS)
VMware Tanzu Operations Manager (Ops Manager)
VMware Tanzu Kubernetes Grid Integrated Edition (TKGI)
https://www.vmware.com/security/advisories/VMSA-2022-0010.html
Telegram
SysAdmin 24x7
VMSA-2022-0010
CVSSv3 Range: 9.8
Issue Date: 2022-04-02
Updated On: 2022-04-02 (Initial Advisory)
CVE(s): CVE-2022-22965
Synopsis:
VMware Response to Spring Framework Remote Code Execution Vulnerability, aka Spring4Shell (CVE-2022-22965)
Impacted Products…
CVSSv3 Range: 9.8
Issue Date: 2022-04-02
Updated On: 2022-04-02 (Initial Advisory)
CVE(s): CVE-2022-22965
Synopsis:
VMware Response to Spring Framework Remote Code Execution Vulnerability, aka Spring4Shell (CVE-2022-22965)
Impacted Products…
VMSA-2022-0010.4
CVSSv3 Range: 9.8
Issue Date: 2022-04-02
Updated On: 2022-04-08
CVE(s): CVE-2022-22965
Synopsis:
VMware Response to Spring Framework Remote Code Execution Vulnerability (CVE-2022-22965)
Impacted Products
VMware Tanzu Application Service for VMs (TAS)
VMware Tanzu Operations Manager (Ops Manager)
VMware Tanzu Kubernetes Grid Integrated Edition (TKGI)
https://www.vmware.com/security/advisories/VMSA-2022-0010.html
CVSSv3 Range: 9.8
Issue Date: 2022-04-02
Updated On: 2022-04-08
CVE(s): CVE-2022-22965
Synopsis:
VMware Response to Spring Framework Remote Code Execution Vulnerability (CVE-2022-22965)
Impacted Products
VMware Tanzu Application Service for VMs (TAS)
VMware Tanzu Operations Manager (Ops Manager)
VMware Tanzu Kubernetes Grid Integrated Edition (TKGI)
https://www.vmware.com/security/advisories/VMSA-2022-0010.html
Microsoft Releases April 2022 Security Updates
Original release date: April 12, 2022
Microsoft has released updates to address multiple vulnerabilities in Microsoft software. An attacker can exploit some of these vulnerabilities to take control of an affected system.
https://www.cisa.gov/uscert/ncas/current-activity/2022/04/12/microsoft-releases-april-2022-security-updates
Original release date: April 12, 2022
Microsoft has released updates to address multiple vulnerabilities in Microsoft software. An attacker can exploit some of these vulnerabilities to take control of an affected system.
https://www.cisa.gov/uscert/ncas/current-activity/2022/04/12/microsoft-releases-april-2022-security-updates
www.cisa.gov
Microsoft Releases April 2022 Security Updates | CISA
Microsoft has released updates to address multiple vulnerabilities in Microsoft software. An attacker can exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Microsoft’s April 2022…
Google Releases Security Updates for Chrome
https://www.cisa.gov/uscert/ncas/current-activity/2022/04/12/google-releases-security-updates-chrome
https://www.cisa.gov/uscert/ncas/current-activity/2022/04/12/google-releases-security-updates-chrome
www.cisa.gov
Google Releases Security Updates for Chrome | CISA
Google has released Chrome version 100.0.4896.88 for Windows, Mac, and Linux. This version addresses vulnerabilities that an attacker could exploit to take control of an affected system. CISA encourages users and administrators to review the Chrome Release…
Latest Servicing Stack Updates
ADV990001
Security Advisory
Released: Nov 13, 2018 Last updated: Apr 12, 2022
https://msrc.microsoft.com/update-guide/vulnerability/ADV990001
ADV990001
Security Advisory
Released: Nov 13, 2018 Last updated: Apr 12, 2022
https://msrc.microsoft.com/update-guide/vulnerability/ADV990001
Citrix Releases Security Updates for Multiple Products
Original release date: April 12, 2022
Citrix has released security updates to address vulnerabilities in multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system.
CISA encourages users and administrators to review the following Citrix security bulletins and apply the necessary updates.
CTX370550
CTX377814
CTX370551
CTX341455
https://www.cisa.gov/uscert/ncas/current-activity/2022/04/12/citrix-releases-security-updates-multiple-products
Original release date: April 12, 2022
Citrix has released security updates to address vulnerabilities in multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system.
CISA encourages users and administrators to review the following Citrix security bulletins and apply the necessary updates.
CTX370550
CTX377814
CTX370551
CTX341455
https://www.cisa.gov/uscert/ncas/current-activity/2022/04/12/citrix-releases-security-updates-multiple-products
Apache Releases Security Advisory for Struts 2
Original release date: April 12, 2022
The Apache Software Foundation has released a security advisory to address a vulnerability in Struts in the version range 2.0.0 to 2.5.29. An attacker could exploit this vulnerability to take control of an affected system.
CISA encourages users and administrators to review Apache’s security advisory S2-062 and upgrade to the latest released version.
https://www.cisa.gov/uscert/ncas/current-activity/2022/04/12/apache-releases-security-advisory-struts-2
https://cwiki.apache.org/confluence/plugins/servlet/mobile?contentId=210079428#content/view/210079428
Original release date: April 12, 2022
The Apache Software Foundation has released a security advisory to address a vulnerability in Struts in the version range 2.0.0 to 2.5.29. An attacker could exploit this vulnerability to take control of an affected system.
CISA encourages users and administrators to review Apache’s security advisory S2-062 and upgrade to the latest released version.
https://www.cisa.gov/uscert/ncas/current-activity/2022/04/12/apache-releases-security-advisory-struts-2
https://cwiki.apache.org/confluence/plugins/servlet/mobile?contentId=210079428#content/view/210079428
www.cisa.gov
Apache Releases Security Advisory for Struts 2 | CISA
The Apache Software Foundation has released a security advisory to address a vulnerability in Struts in the version range 2.0.0 to 2.5.29. An attacker could exploit this vulnerability to take control of an affected system. CISA encourages users and administrators…
Windows Network File System Remote Code Execution Vulnerability
CVE-2022-24491
Released: Apr 12, 2022
Assigning CNA:Microsoft
MITRE CVE-2022-24491
CVSS:3.1 9.8 / 8.5
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24491
CVE-2022-24491
Released: Apr 12, 2022
Assigning CNA:Microsoft
MITRE CVE-2022-24491
CVSS:3.1 9.8 / 8.5
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24491
Windows Network File System Remote Code Execution Vulnerability
CVE-2022-24497
Released: Apr 5, 2022
Assigning CNA:Microsoft
MITRE CVE-2022-24497
CVSS:3.1 9.8 / 8.5
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24497
CVE-2022-24497
Released: Apr 5, 2022
Assigning CNA:Microsoft
MITRE CVE-2022-24497
CVSS:3.1 9.8 / 8.5
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24497
USN-5371-1: nginx vulnerabilities
12 APRIL 2022
Several security issues were fixed in nginx.
Releases
Ubuntu 21.10
Ubuntu 20.04 LTS
Ubuntu 18.04 LTS
Ubuntu 16.04 ESM
Packages
nginx - small, powerful, scalable web/proxy server
https://ubuntu.com/security/notices/USN-5371-1
12 APRIL 2022
Several security issues were fixed in nginx.
Releases
Ubuntu 21.10
Ubuntu 20.04 LTS
Ubuntu 18.04 LTS
Ubuntu 16.04 ESM
Packages
nginx - small, powerful, scalable web/proxy server
https://ubuntu.com/security/notices/USN-5371-1
Ubuntu
USN-5371-1: nginx vulnerabilities | Ubuntu security notices | Ubuntu
Ubuntu is an open source software operating system that runs from the desktop, to the cloud, to all your internet connected things.
Microsoft Patch Tuesday includes most vulnerabilities since Sept. 2020
Microsoft released its latest security update Tuesday, disclosing more than 140 vulnerabilities across its array of products. This is a departure from past Patch Tuesdays this year, which have only featured a few dozen vulnerabilities, and is the largest amount of issues in a single Patch Tuesday since September 2020.
[...]
Windows Hyper-V contains three of the critical vulnerabilities patched this month [...]
[...]
There are also two critical remote code execution vulnerabilities in the Windows Network File System[...]
[...]
CVE-2022-24500 is another critical remote code execution vulnerability that exists in Windows SMB.[...]
https://blog.talosintelligence.com/2022/04/microsoft-patch-tuesday-includes-most.html
Microsoft released its latest security update Tuesday, disclosing more than 140 vulnerabilities across its array of products. This is a departure from past Patch Tuesdays this year, which have only featured a few dozen vulnerabilities, and is the largest amount of issues in a single Patch Tuesday since September 2020.
[...]
Windows Hyper-V contains three of the critical vulnerabilities patched this month [...]
[...]
There are also two critical remote code execution vulnerabilities in the Windows Network File System[...]
[...]
CVE-2022-24500 is another critical remote code execution vulnerability that exists in Windows SMB.[...]
https://blog.talosintelligence.com/2022/04/microsoft-patch-tuesday-includes-most.html
Cisco Talos Blog
Microsoft Patch Tuesday includes most vulnerabilities since Sept. 2020
Microsoft released its latest security update Tuesday, disclosing more than 140 vulnerabilities across its array of products. This is a departure from past Patch Tuesdays this year, which have only featured a few dozen vulnerabilities, and is the largest…
SAP Security Patch Day –April2022
https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10
https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10