Release notes for update package 1469-5242

This update package improves the detection capabilities of the Forcepoint LLM system.

RELEASE DATE:     Thursday May 19, 2022
MD5 CHECKSUM:     08a1c133ce26cb4086ae41e686a74cba
SHA1 CHECKSUM:     f30f77c125a81a8622d55808824b6867fa40aa38
SHA256 CHECKSUM:     3727e45079ab2d7527b9c27bcb3137e0127a70c975fb325437c6c99eda835f90

UPDATE CRITICALITY:    HIGH

List of detected attacks in this update package:

Risk level Description Reference Vulnerability
High     An attempt to exploit a vulnerability in Apache httpd detected.     CVE-2022-22719     Apache-Httpd-Mod_Lua-req_parsebody-Denial-Of-Service
High     An attempt to exploit a vulnerability in ManageEngine OpManager detected.     CVE-2022-29535     Zoho-Manageengine-Opmanager-CVE-2022-29535-SQL-Injection
High     An attempt to exploit a vulnerability in Patrowl PatrowlManager detected.     CVE-2021-43829     Patrowl-PatrowlManager-Unrestricted-File-Upload
High     An attempt to exploit a vulnerability in Jenkins Credentials Plugin detected.     CVE-2022-29036     Jenkins-Credentials-Plugin-Stored-Cross-Site-Scripting
High     An attempt to exploit a vulnerability in multiple Zyxel firewall products detected     CVE-2022-30525     ZyXEL-Remote-Code-Execution-CVE-2022-30525
High     An attempt to exploit a vulnerability in Open-Falcon Falcon-Plus detected     CVE-2022-26245     Open-Falcon-Plus-Gethostsfromgroup-SQL-Injection
High     An attempt to exploit a vulnerability in Delta Electronics CNCSoft ScreenEditor detected.     CVE-2021-43982     Delta-Electronics-CNCSoft-Screeneditor-CVE-2021-43982-Stack-Buffer-Overflow

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS

New detected attacks:

HTTP Client Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Apache-Httpd-Mod_Lua-req_parsebody-Denial-Of-Service CVE-2022-22719 HTTP_CS-Apache-Httpd-Mod_Lua-req_parsebody-Denial-Of-Service Suspected Denial of Service
High Zoho-Manageengine-Opmanager-CVE-2022-29535-SQL-Injection CVE-2022-29535 HTTP_CS-Zoho-Manageengine-Opmanager-CVE-2022-29535-SQL-Injection Suspected Disclosure
High Patrowl-PatrowlManager-Unrestricted-File-Upload CVE-2021-43829 HTTP_CS-Patrowl-PatrowlManager-Unrestricted-File-Upload Suspected Compromise
High Jenkins-Credentials-Plugin-Stored-Cross-Site-Scripting CVE-2022-29036 HTTP_CS-Jenkins-Credentials-Plugin-Stored-Cross-Site-Scripting Suspected Compromise

HTTP Normalized Request-Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High ZyXEL-Remote-Code-Execution-CVE-2022-30525 CVE-2022-30525 HTTP_CRL-ZyXEL-Remote-Code-Execution-CVE-2022-30525 Suspected Compromise
High Open-Falcon-Plus-Gethostsfromgroup-SQL-Injection CVE-2022-26245 HTTP_CRL-Open-Falcon-Plus-Gethostsfromgroup-SQL-Injection Suspected Compromise

Other Binary File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Delta-Electronics-CNCSoft-Screeneditor-CVE-2021-43982-Stack-Buffer-Overflow CVE-2021-43982 File-Binary_Delta-Electronics-CNCSoft-Screeneditor-CVE-2021-43982-Stack-Buffer-Overflow Suspected Compromise

Updated detected attacks:

HTTP Request Header Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High Novell-Remote-Manager-Off-By-One-Denial-Of-Service No CVE/CAN HTTP_CSH-Novell-Remote-Manager-Off-By-One-Denial-Of-Service Suspected Compromise
Fingerprint regexp changed
High SaveNow-Software No CVE/CAN HTTP_CSH-SaveNow-Activity Spyware, Malware and Adware
Fingerprint regexp changed
High HTTP-Apache-Host-Header-Default-Error-Page-XSS CVE-2002-0840 HTTP_CSH-Apache-Host-Header-Default-Error-Page-XSS Suspected Disclosure
Fingerprint regexp changed
High HTTP-Apache-Host-Header-Default-Error-Page-XSS CVE-2002-0840 HTTP_CSH-Script-In-Host-Header Attack Related Anomalies
Fingerprint regexp changed
Low HTTP-Novell-eDirectory-HTTP-Server-Redirection-Buffer-Overflow CVE-2006-5478 HTTP_CSH-Overly-Long-Host-Header-Field Potential Compromise
Fingerprint regexp changed
Low IP-Address-As-HTTP-Host No CVE/CAN HTTP_CSH-IP-Address-As-HTTP-Host Protocol Information
Fingerprint regexp changed
High HTTP-Apache-Portable-Runtime-Apr-Psprintf-Long-String-Vulnerability CVE-2003-0245 HTTP_CSH-Oversized-Host-Header-Field Attack Related Anomalies
Description has changed
Category tag group CVE2019 added
Fingerprint regexp changed
Low UUSee-Streaming-Media No CVE/CAN HTTP_CSH-UUSee-Activity Streaming Protocols
Fingerprint regexp changed
High Squid-HTTP-Host-Header-Port-Handling-Denial-Of-Service CVE-2013-4123 HTTP_CSH-Squid-HTTP-Host-Header-Port-Handling-Denial-Of-Service Suspected Compromise
Fingerprint regexp changed
High Lighttpd-Host-Header-Mod_mysql_vhost-SQL-Injection CVE-2014-2323 HTTP_CSH-Lighttpd-Host-Header-Multiple-Vulnerabilities Suspected Compromise
Fingerprint regexp changed
Critical Furtims-Parent-Nullptr-Host-Field No CVE/CAN HTTP_CSH-Furtims-Parent-Nullptr-Host-Field Successful Attacks
Fingerprint regexp changed
High CMS-Made-Simple-Cache-Poisoning CVE-2016-2784 HTTP_CSH-CMS-Made-Simple-Cache-Poisoning Suspected Compromise
Fingerprint regexp changed
High Generic-HTTP-Exploit No CVE/CAN HTTP_CSH-Known-Exploit-Kit-Headers Potential Compromise
Fingerprint regexp changed
High HTTP-Novell-eDirectory-HTTP-Server-Redirection-Buffer-Overflow CVE-2006-5478 HTTP_CSH-Novell-eDirectory-CVE-2006-5478 Potential Compromise
Detection mechanism updated
High Felismus-Malware No CVE/CAN HTTP_CSH-Felismus-Malware-Request Botnet
Fingerprint regexp changed
High Squid-Proxy-HTTP-Request-Processing-Buffer-Overflow CVE-2020-8450 HTTP_CRH-Squid-Proxy-HTTP-Request-Processing-Buffer-Overflow Suspected Compromise
Fingerprint regexp changed

LIST OF OTHER CHANGES:

New objects:

Type Name
Category Patrowl PatrowlManager
Category Open-Falcon Falcon-Plus
Category Jenkins Credentials Plugin
Element Ref Application dependency from Microsoft-SharePoint-Online to Microsoft-PowerApps
Element Ref Application dependency from Microsoft-Teams to Microsoft-PowerApps

Updated objects:

Type Name Changes
Situation HTTP_CSH-Shared-Variables
Fingerprint regexp changed
Situation HTTP_CSH-Suspicious-Host-Header
Fingerprint regexp changed
Situation HTTP_CRH-ABB-Pb610-Panel-Builder-600-Idal-HTTP-Host-Stack-Buffer-Overflow
Description has changed
Category tag situation Obsolete added
Category tag os Any Operating System removed
Category tag hardware Any Hardware removed
Category tag application ABB Panel Builder removed
Category tag group CVE2019 removed
Category tag os_not_specific Any Operating System not specific removed
Category tag situation Suspected Compromise removed
Category tag group HTTP Correlation Dependency Group removed
Category tag group TCP Correlation Dependency Group removed
Category tag group Severity over 4 Correlation Dependency Group removed
Category tag group TCP Client Traffic removed
Fingerprint regexp changed

DISCLAIMER AND COPYRIGHT

Copyright © 2022 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.