Release notes for update package 1452-5242

This update package improves the detection capabilities of the Forcepoint NGFW system.

RELEASE DATE:    Thursday April 07, 2022
MD5 CHECKSUM:    1264522359e76c4992ac8d79cf47618d
SHA1 CHECKSUM:    be13fd8fc581e35fafd5b6d4b5f091f9682821ca
SHA256 CHECKSUM:    10d58fbb0381e0aaf2c83e69aae3ccd6d9b71dddba3002cbbabc28c2efbd6bff

UPDATE CRITICALITY:    HIGH

MINIMUM SOFTWARE VERSIONS
- Forcepoint NGFW Security Management Center:    6.5.1.10631
- Forcepoint NGFW:    6.3.1.19034

List of detected attacks in this update package:

Risk levelDescriptionReferenceVulnerability
High     An attempt to exploit a vulnerability in Spring Core detected     CVE-2022-22965     Spring-Core-Remote-Code-Execution
High     An attempt to exploit a vulnerability in MyBB Group MyBB detected     CVE-2022-24734     MyBB-Admin-Control-Panel-Code-Injection
High     An attempt to exploit a vulnerability in Oracle MySQL Cluster detected     CVE-2022-21279     Oracle-MySQL-Cluster-Management-API-Report_Event-Stack-Buffer-Overflow

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS

New detected attacks:

TCP Client Stream Unknown

RiskVulnerability/SituationReferencesRelated FingerprintSituation Type
High Oracle-MySQL-Cluster-Management-API-Report_Event-Stack-Buffer-Overflow CVE-2022-21279 Generic_CS-Oracle-MySQL-Cluster-Management-API-Report_Event-Stack-Buffer-Overflow Suspected Compromise

HTTP Normalized Request-Line

RiskVulnerability/SituationReferencesRelated FingerprintSituation Type
High Spring-Core-Remote-Code-Execution CVE-2022-22965 HTTP_CRL-Spring-Core-Remote-Code-Execution-Suspicious-Parameter-Name Potential Compromise
High MyBB-Admin-Control-Panel-Code-Injection CVE-2022-24734 HTTP_CRL-MyBB-Admin-Control-Panel-Code-Injection Suspected Compromise

Updated detected attacks:

HTTP Normalized Request-Line

RiskVulnerability/SituationReferencesRelated FingerprintSituation TypeChange Description
High Spring-Core-Remote-Code-Execution CVE-2022-22965 HTTP_CRL-Spring-Core-Remote-Code-Execution Suspected Compromise
Description has changed

LIST OF OTHER CHANGES:

Updated objects:

TypeNameChanges
IPListTOR exit nodes IP Address List
IPListAkamai Servers
IPListTOR relay nodes IP Address List
IPListMicrosoft Azure datacenter for centralus
IPListMicrosoft Azure datacenter for eastasia
IPListMicrosoft Azure datacenter for eastus2
IPListMicrosoft Azure datacenter for eastus
IPListMicrosoft Azure datacenter for southeastasia
IPListMicrosoft Azure datacenter for uksouth
IPListMicrosoft Azure datacenter for westeurope
IPListMicrosoft Azure datacenter for westus
IPListMicrosoft Azure datacenter
IPListBotnet IP Address List
IPListMalicious Site IP Address List
IPListMicrosoft Azure datacenter for germanywc
IPListMicrosoft Azure datacenter for uaenorth
IPListMicrosoft Azure service for ActionGroup
IPListMicrosoft Azure service for AzureCloud
IPListMicrosoft Azure service for AzureFrontDoor_FirstParty
IPListMicrosoft Azure service for AzureInformationProtection
IPListMicrosoft Azure service for DataFactory
IPListMicrosoft Azure service for DataFactoryManagement
SituationHTTP_CRL-Shared-Variables
Fingerprint regexp changed
SituationURLList for Microsoft-Azure
Name: URLList 3211289->URLList for Microsoft-Azure

HOW TO IMPORT AND ACTIVATE THE DYNAMIC UPDATE PACKAGE

  1. Download the dynamic update package, then make sure that the checksums for the original files and the files that you have downloaded match.
  2. In the Management Client, select Menu > File > Import > Import Update Packages.
  3. Browse to the file, select it, then click Import.
  4. Select  Configuration, then browse to Administration > Other Elements > Updates.
  5. Right-click the imported dynamic update package, then select Activate.
  6. When the activation is finished, refresh the policy on all NGFW Engines. If your policy uses a custom template, you might need to edit the policy.

DISCLAIMER AND COPYRIGHT

Copyright © 2022 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.