Mcafee Foundstone Fsl Update
Total Page:16
File Type:pdf, Size:1020Kb
2020-JUL-30 FSL version 7.6.168 MCAFEE FOUNDSTONE FSL UPDATE To better protect your environment McAfee has created this FSL check update for the Foundstone Product Suite. The following is a detailed summary of the new and updated checks included with this release. NEW CHECKS 26730 - WebSphere Application Server Remote Code Execution Vulnerability (CVE-2020-4450) Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS) Risk Level: High CVE: CVE-2020-4450 Description A vulnerability is present in some versions of IBM WebSphere Application Server. Observation IBM WebSphere Application Server is a server engine for Java EE Web applications. A vulnerability is present in some versions of IBM WebSphere Application Server. The flaw is in the handling of some specially-crafted sequence of serialized objects. Successful exploitation could allow an attacker to execute arbitrary code on the target. 26850 - Security Vulnerabilities Fixed In Firefox 78 Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS) Risk Level: High CVE: CVE-2020-12402, CVE-2020-12415, CVE-2020-12416, CVE-2020-12417, CVE-2020-12418, CVE-2020-12419, CVE-2020- 12420, CVE-2020-12421, CVE-2020-12422, CVE-2020-12423, CVE-2020-12424, CVE-2020-12425, CVE-2020-12426 Description Multiple vulnerabilities are present in some versions of Mozilla Firefox. Observation Mozilla Firefox is a popular web browser. Multiple vulnerabilities are present in some versions of Mozilla Firefox. The flaws lie in several components. Successful exploitation could allow an attacker to cause a denial of service condition, disclosure of sensitive information or execute arbitrary code on the target system. 26858 - Security Vulnerabilities Fixed In Firefox ESR 68.10 Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS) Risk Level: High CVE: CVE-2020-12417, CVE-2020-12418, CVE-2020-12419, CVE-2020-12420, CVE-2020-12421 Description Multiple vulnerabilities are present in some versions of Mozilla Firefox ESR. Observation Mozilla Firefox ESR is a popular web browser. Multiple vulnerabilities are present in some versions of Mozilla Firefox ESR. The flaw lies in multiple components. Successful exploitation could allow an attacker to cause a denial of service condition. 149211 - SuSE Linux 15.1 openSUSE-SU-2020:1037-1 Update Is Not Installed Category: SSH Module -> NonIntrusive -> SuSE Patches and Hotfixes Risk Level: High CVE: CVE-2019-11328, CVE-2019-19724, CVE-2020-13845, CVE-2020-13846, CVE-2020-13847 Description The scan detected that the host is missing the following update: openSUSE-SU-2020:1037-1 Observation Updates often remediate critical security problems that should be quickly addressed. For more information see: https://lists.opensuse.org/opensuse-updates/2020-07/msg00122.html SuSE Linux 15.1 x86_64 singularity-3.6.0-lp151.2.6.1 singularity-debuginfo-3.6.0-lp151.2.6.1 26726 - WordPress Multiple Vulnerabilities Prior To 5.4.2 Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High CVE: CVE-MAP-NOMATCH Description Multiple vulnerabilities are present in some versions of WordPress. Observation WordPress is a popular blog application. Multiple vulnerabilities are present in some versions of WordPress. The flaws lie in multiple components. Successful exploitation could allow an attacker to gain elevated privileges or perform cross-site scripting attacks. 26728 - Privilege Escalation Vulnerability In WebSphere Application Server (CVE-2020-4362) Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS) Risk Level: High CVE: CVE-2020-4362 Description A vulnerability is present in some versions of IBM WebSphere Application Server. Observation IBM WebSphere Application Server is a server engine for Java EE Web applications. A vulnerability is present in some versions of IBM WebSphere Application Server. The flaw occurs when using token-based authentication in an admin request over the SOAP connector. Successful exploitation could allow an attacker to gain elevated privileges. 26734 - Joomla CSRF In Com_postinstall Vulnerability (20200605) Category: General Vulnerability Assessment -> NonIntrusive -> Web Server Risk Level: High CVE: CVE-2020-13760 Description A vulnerability is present in some versions of Joomla!. Observation Joomla! is a content management system. A vulnerability is present in some versions of Joomla!. The flaw lies in the com_postinstall component. Successful exploitation could allow an attacker to conduct cross-site request forgery attacks. 131635 - Debian Linux 10.0 DSA-4729-1 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Debian Patches and Hotfixes Risk Level: High CVE: CVE-2019-14380, CVE-2019-17113 Description The scan detected that the host is missing the following update: DSA-4729-1 Observation Updates often remediate critical security problems that should be quickly addressed. For more information see: http://www.debian.org/security/2020/dsa-4729 Debian 10.0 all libopenmpt-dev_0.4.3-1+deb10u1 libopenmpt-modplug-dev_0.4.3-1+deb10u1 libopenmpt-doc_0.4.3-1+deb10u1 openmpt123_0.4.3-1+deb10u1 libopenmpt0_0.4.3-1+deb10u1 libopenmpt-modplug1_0.4.3-1+deb10u1 149190 - SuSE Linux 15.1 openSUSE-SU-2020:1102-1 Update Is Not Installed Category: SSH Module -> NonIntrusive -> SuSE Patches and Hotfixes Risk Level: High CVE: CVE-2020-13934, CVE-2020-13935 Description The scan detected that the host is missing the following update: openSUSE-SU-2020:1102-1 Observation Updates often remediate critical security problems that should be quickly addressed. For more information see: https://lists.opensuse.org/opensuse-updates/2020-07/msg00185.html SuSE Linux 15.1 noarch tomcat-webapps-9.0.36-lp151.3.27.1 tomcat-el-3_0-api-9.0.36-lp151.3.27.1 tomcat-9.0.36-lp151.3.27.1 tomcat-servlet-4_0-api-9.0.36-lp151.3.27.1 tomcat-lib-9.0.36-lp151.3.27.1 tomcat-javadoc-9.0.36-lp151.3.27.1 tomcat-admin-webapps-9.0.36-lp151.3.27.1 tomcat-docs-webapp-9.0.36-lp151.3.27.1 tomcat-jsvc-9.0.36-lp151.3.27.1 tomcat-embed-9.0.36-lp151.3.27.1 tomcat-jsp-2_3-api-9.0.36-lp151.3.27.1 149191 - SuSE Linux 15.2 openSUSE-SU-2020:1062-1 Update Is Not Installed Category: SSH Module -> NonIntrusive -> SuSE Patches and Hotfixes Risk Level: High CVE: CVE-2020-12771, CVE-2020-15393 Description The scan detected that the host is missing the following update: openSUSE-SU-2020:1062-1 Observation Updates often remediate critical security problems that should be quickly addressed. For more information see: https://lists.opensuse.org/opensuse-updates/2020-07/msg00147.html SuSE Linux 15.2 x86_64 kernel-debug-debuginfo-5.3.18-lp152.33.1 kernel-debug-debugsource-5.3.18-lp152.33.1 kernel-kvmsmall-debuginfo-5.3.18-lp152.33.1 kernel-preempt-devel-5.3.18-lp152.33.1 kernel-default-debuginfo-5.3.18-lp152.33.1 kernel-preempt-devel-debuginfo-5.3.18-lp152.33.1 kernel-kvmsmall-devel-5.3.18-lp152.33.1 kernel-preempt-5.3.18-lp152.33.1 kernel-preempt-debugsource-5.3.18-lp152.33.1 kernel-debug-5.3.18-lp152.33.1 kernel-debug-devel-5.3.18-lp152.33.1 kernel-default-5.3.18-lp152.33.1 kernel-default-base-5.3.18-lp152.33.1.lp152.8.4.4 kernel-default-devel-5.3.18-lp152.33.1 kernel-obs-build-debugsource-5.3.18-lp152.33.1 kernel-kvmsmall-5.3.18-lp152.33.1 kernel-default-devel-debuginfo-5.3.18-lp152.33.1 kernel-kvmsmall-devel-debuginfo-5.3.18-lp152.33.1 kernel-default-debugsource-5.3.18-lp152.33.1 kernel-syms-5.3.18-lp152.33.1 kernel-default-base-rebuild-5.3.18-lp152.33.1.lp152.8.4.4 kernel-debug-devel-debuginfo-5.3.18-lp152.33.1 kernel-preempt-debuginfo-5.3.18-lp152.33.1 kernel-kvmsmall-debugsource-5.3.18-lp152.33.1 kernel-obs-qa-5.3.18-lp152.33.1 kernel-obs-build-5.3.18-lp152.33.1 noarch kernel-source-5.3.18-lp152.33.1 kernel-macros-5.3.18-lp152.33.1 kernel-source-vanilla-5.3.18-lp152.33.1 kernel-docs-html-5.3.18-lp152.33.1 kernel-devel-5.3.18-lp152.33.1 kernel-docs-5.3.18-lp152.33.1 149192 - SuSE SLED 15 SP1, 15 SP2 SUSE-SU-2020:2029-1 Update Is Not Installed Category: SSH Module -> NonIntrusive -> SuSE Patches and Hotfixes Risk Level: High CVE: CVE-2020-15503 Description The scan detected that the host is missing the following update: SUSE-SU-2020:2029-1 Observation Updates often remediate critical security problems that should be quickly addressed. For more information see: http://lists.suse.com/pipermail/sle-security-updates/2020-July/007173.html SuSE SLED 15 SP1 x86_64 libraw16-0.18.9-3.11.1 libraw16-debuginfo-0.18.9-3.11.1 libraw-debugsource-0.18.9-3.11.1 libraw-debuginfo-0.18.9-3.11.1 libraw-devel-0.18.9-3.11.1 SuSE SLED 15 SP2 x86_64 libraw16-0.18.9-3.11.1 libraw16-debuginfo-0.18.9-3.11.1 libraw-debugsource-0.18.9-3.11.1 libraw-debuginfo-0.18.9-3.11.1 libraw-devel-0.18.9-3.11.1 149193 - SuSE Linux 15.2 openSUSE-SU-2020:1027-1 Update Is Not Installed Category: SSH Module -> NonIntrusive -> SuSE Patches and Hotfixes Risk Level: High CVE: CVE-2020-12823 Description The scan detected that the host is missing the following update: openSUSE-SU-2020:1027-1 Observation Updates often remediate critical security problems that should be quickly addressed. For more information see: https://lists.opensuse.org/opensuse-updates/2020-07/msg00112.html SuSE Linux 15.2 x86_64 openconnect-debugsource-7.08-lp152.9.4.2 openconnect-7.08-lp152.9.4.2 openconnect-debuginfo-7.08-lp152.9.4.2 openconnect-devel-7.08-lp152.9.4.2 openconnect-doc-7.08-lp152.9.4.2 noarch openconnect-lang-7.08-lp152.9.4.2 149194 - SuSE SLES 12 SP5 SUSE-SU-2020:2037-1 Update Is Not Installed Category: SSH Module -> NonIntrusive -> SuSE Patches and Hotfixes Risk Level: High CVE: CVE-2020-13934, CVE-2020-13935 Description The scan detected that the host is missing the following update: SUSE-SU-2020:2037-1 Observation Updates often remediate critical security problems that should be quickly addressed.