Release notes for update package 1448-5242

This update package improves the detection capabilities of the Forcepoint LLM system.

RELEASE DATE:     Thursday March 31, 2022
MD5 CHECKSUM:     b5ebd125e24694328529cf8d7c6f2d04
SHA1 CHECKSUM:     5b494b59d211652a835266d6bd096e48308ffb86
SHA256 CHECKSUM:     6e66adf0db90e78082b2129052687b43095384017e37cf39d850c1e17c2faf87

UPDATE CRITICALITY:    HIGH

List of detected attacks in this update package:

Risk level Description Reference Vulnerability
High     An attempt to exploit a vulnerability in Pimcore Pimcore detected     CVE-2022-0831     Pimcore-Key-Field-Stored-Cross-Site-Scripting
High     An attempt to exploit a vulnerability in Apache Software Foundation APISIX detected     CVE-2022-24112     Apache-APISIX-Batch-Requests-Plugin-IP-Restriction-Bypass
High     An attempt to exploit a vulnerability in WordPress Project 10Web Photo Gallery detected     CVE-2022-0169     Wordpress-Photo-Gallery-Plugin-SQL-Injection
High     An attempt to exploit a vulnerability in Oracle Business Intelligence Enterprise Edition detected.     CVE-2021-2400     Oracle-Business-Intelligence-Publisher-Xdo-Xml-External-Entity-Injection

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS

New detected attacks:

HTTP Client Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Pimcore-Key-Field-Stored-Cross-Site-Scripting CVE-2022-0831 HTTP_CS-Pimcore-Key-Field-Stored-Cross-Site-Scripting Suspected Compromise

HTTP Normalized Request-Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Apache-APISIX-Batch-Requests-Plugin-IP-Restriction-Bypass CVE-2022-24112 HTTP_CRL-Apache-APISIX-Batch-Requests-Plugin-IP-Restriction-Bypass Suspected Compromise
High Wordpress-Photo-Gallery-Plugin-SQL-Injection CVE-2022-0169 HTTP_CRL-Wordpress-Photo-Gallery-Plugin-SQL-Injection Suspected Compromise

Identified Text File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Oracle-Business-Intelligence-Publisher-Xdo-Xml-External-Entity-Injection CVE-2021-2400 File-TextId_Oracle-Business-Intelligence-Publisher-Xdo-Xml-External-Entity-Injection Suspected Disclosure

Updated detected attacks:

HTTP Normalized Request-Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
Low Sun-Java-Web-Server-WebDAV-Stack-Overflow-Vulnerability CVE-2010-0361 HTTP_CRL-Excessively-Long-Options-Request-Argument Possibly Unwanted Content
Severity: 7->2
Category tag situation Possibly Unwanted Content added
Category tag situation Potential Compromise removed
Category tag group HTTP Correlation Dependency Group removed
Category tag group Severity over 4 Correlation Dependency Group removed

LIST OF OTHER CHANGES:

Updated objects:

Type Name Changes
IPList TOR exit nodes IP Address List
IPList Amazon AMAZON
IPList Amazon EC2
IPList Akamai Servers
IPList TOR relay nodes IP Address List
IPList Line Messenger IP Address List
IPList Botnet IP Address List
IPList Malicious Site IP Address List
IPList Amazon AMAZON eu-central-1
IPList Amazon EC2 eu-central-1
IPList LogMeIn GoToMeeting Servers
Situation FW_Info-Request
Comment has changed
Description has changed
Situation HTTP_CSH-Shared-Variables
Fingerprint regexp changed

DISCLAIMER AND COPYRIGHT

Copyright © 2022 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.