<?xml version="1.0" encoding="UTF-8" ?>
<!DOCTYPE JpcertCcReport SYSTEM "http://www.jpcert.or.jp/wr/wr.dtd">
<JpcertCcReport>
  <Header>
    <Name>JPCERT-WR-2021-4101</Name>
    <Date>2021-10-20</Date>
    <From>2021-10-10</From>
    <To>2021-10-16</To>
  </Header>

<Article RiskLevel="1" Type="RU">
          <Title>複数のマイクロソフト製品に脆弱性</Title>
          <Source>
               <Name>CISA Current Activity</Name>
               <Title>Microsoft Releases October 2021 Security Updates</Title>
               <URL>https://us-cert.cisa.gov/ncas/current-activity/2021/10/12/microsoft-releases-october-2021-security-updates</URL>
          </Source>

<Summary>
複数のマイクロソフト製品には、複数の脆弱性があります。結果として、第三
者が任意のコードを実行するなどの可能性があります。

対象となる製品は、多岐に渡ります。詳細はマイクロソフト株式会社が提供す
るアドバイザリ情報を参照してください。

この問題は、Microsoft Updateなどを用いて、更新プログラムを適用すること
で解決します。詳細は、マイクロソフト株式会社が提供する情報を参照してく
ださい。
</Summary>

        <Reference Language="JAPANESE">
             <Name>マイクロソフト株式会社</Name>
             <Title>2021 年 10 月のセキュリティ更新プログラム</Title>
             <URL>https://msrc.microsoft.com/update-guide/releaseNote/2021-Oct</URL>
        </Reference>
        <Reference Language="JAPANESE">
             <Name>JPCERT/CC 注意喚起</Name>
             <Title>2021年10月マイクロソフトセキュリティ更新プログラムに関する注意喚起</Title>
             <URL>https://www.jpcert.or.jp/at/2021/at210045.html</URL>
        </Reference>
</Article>

<Article RiskLevel="1" Type="RU">
          <Title>Google Chromeに複数の脆弱性</Title>
          <Source>
               <Name>CISA Current Activity</Name>
               <Title>Google Releases Security Updates for Chrome</Title>
               <URL>https://us-cert.cisa.gov/ncas/current-activity/2021/10/12/google-releases-security-updates-chrome</URL>
          </Source>

<Summary>
Google Chromeには、複数の脆弱性があります。

対象となるバージョンは次のとおりです。

- Google Chrome 94.0.4606.81より前のバージョン

この問題は、Google ChromeをGoogleが提供する修正済みのバージョンに更新
することで解決します。詳細は、Googleが提供する情報を参照してください。
</Summary>

        <Reference Language="ENGLISH">
             <Name>Google</Name>
             <Title>Stable Channel Update for Desktop</Title>
             <URL>https://chromereleases.googleblog.com/2021/10/stable-channel-update-for-desktop.html</URL>
        </Reference>

</Article>

<Article RiskLevel="1" Type="RU">
          <Title>iOSおよびiPadOSにメモリ破損の脆弱性</Title>
          <Source>
               <Name>CISA Current Activity</Name>
               <Title>Apple Releases Security Update to Address CVE-2021-30883</Title>
               <URL>https://us-cert.cisa.gov/ncas/current-activity/2021/10/12/apple-releases-security-update-address-cve-2021-30883</URL>
          </Source>

<Summary>
iOSおよびiPadOSには、メモリ破損の脆弱性があります。結果として、第三者
が任意のコードを実行する可能性があります。

対象となるOSおよびバージョンは次のとおりです。

- iOS 15.0.2より前のバージョン
- iPadOS 15.0.2より前のバージョン

この問題は、該当するOSをAppleが提供する修正済みのバージョンに更新する
ことで解決します。詳細は、Appleが提供する情報を参照してください。
</Summary>

        <Reference Language="JAPANESE">
             <Name>Apple</Name>
             <Title>iOS 15.0.2 および iPadOS 15.0.2 のセキュリティコンテンツについて</Title>
             <URL>https://support.apple.com/ja-jp/HT212846</URL>
        </Reference>

        <Reference Language="JAPANESE">
             <Name>JPCERT/CC CyberNewsFlash</Name>
             <Title>Apple製品のアップデートについて（2021年10月）</Title>
             <URL>https://www.jpcert.or.jp/newsflash/2021101201.html</URL>
        </Reference>
</Article>

<Article RiskLevel="1" Type="RU">
          <Title>複数のアドビ製品に脆弱性</Title>
          <Source>
               <Name>CISA Current Activity</Name>
               <Title>Adobe Releases Security Updates for Multiple Products</Title>
               <URL>https://us-cert.cisa.gov/ncas/current-activity/2021/10/12/adobe-releases-security-updates-multiple-products</URL>
          </Source>

<Summary>
複数のアドビ製品には、脆弱性があります。結果として、遠隔の第三者が任意
のコードを実行するなどの可能性があります。

対象となる製品は次のとおりです。

- Adobe Campaign Standard
- Adobe Commerce
- Adobe ops-cli
- Adobe Acrobat Reader for Android
- Adobe Connect
- Adobe Acrobat
- Adobe Acrobat Reader

この問題は、該当する製品をアドビが提供する修正済みのバージョンに更新す
ることで解決します。詳細は、アドビが提供する情報を参照してください。
</Summary>

        <Reference Language="JAPANESE">
             <Name>JPCERT/CC 注意喚起</Name>
             <Title>Adobe AcrobatおよびReaderの脆弱性（APSB21-104）に関する注意喚起</Title>
             <URL>https://www.jpcert.or.jp/at/2021/at210044.html</URL>
        </Reference>
        <Reference Language="JAPANESE">
             <Name>JPCERT/CC CyberNewsFlash</Name>
             <Title>複数のアドビ製品のアップデートについて</Title>
             <URL>https://www.jpcert.or.jp/newsflash/2021101501.html</URL>
        </Reference>
        <Reference Language="JAPANESE">
             <Name>アドビ</Name>
             <Title>Adobe Campaign Standard に関するセキュリティアップデート公開 | APSB21-52</Title>
             <URL>https://helpx.adobe.com/jp/security/products/campaign/apsb21-52.html</URL>
        </Reference>
        <Reference Language="JAPANESE">
             <Name>アドビ</Name>
             <Title>Adobe Commerce に関するセキュリティアップデート公開 | APSB21-86</Title>
             <URL>https://helpx.adobe.com/jp/security/products/magento/apsb21-86.html</URL>
        </Reference>
        <Reference Language="JAPANESE">
             <Name>アドビ</Name>
             <Title>Adobe ops-cli で利用可能なセキュリティ更新プログラム | APSB21-88</Title>
             <URL>https://helpx.adobe.com/jp/security/products/ops_cli/apsb21-88.html</URL>
        </Reference>
        <Reference Language="JAPANESE">
             <Name>アドビ</Name>
             <Title>Adobe Acrobat Reader for Android で利用可能なセキュリティ更新プログラム | APSB21-89</Title>
             <URL>https://helpx.adobe.com/jp/security/products/reader-mobile/apsb21-89.html</URL>
        </Reference>
        <Reference Language="JAPANESE">
             <Name>アドビ</Name>
             <Title>Adobe Connect で利用可能なセキュリティ更新プログラム | APSB21-91</Title>
             <URL>https://helpx.adobe.com/jp/security/products/connect/apsb21-91.html</URL>
        </Reference>
        <Reference Language="JAPANESE">
             <Name>アドビ</Name>
             <Title>Adobe Acrobat および Reader に関するセキュリティアップデート公開 | APSB21-104</Title>
             <URL>https://helpx.adobe.com/jp/security/products/acrobat/apsb21-104.html</URL>
        </Reference>
</Article>

<Article RiskLevel="1" Type="RU">
          <Title>複数のJuniper製品に脆弱性</Title>
          <Source>
               <Name>CISA Current Activity</Name>
               <Title>Juniper Networks Releases Security Updates for Multiple Products</Title>
               <URL>https://us-cert.cisa.gov/ncas/current-activity/2021/10/14/juniper-networks-releases-security-updates-multiple-products</URL>
          </Source>

<Summary>
複数のJuniper製品には、脆弱性があります。結果として、第三者が任意のコー
ドを実行するなどの可能性があります。

対象となる製品は、多岐に渡ります。詳細はJuniperが提供するアドバイザリ
情報を参照してください。

この問題は、該当する製品をJuniperが提供する修正済みのバージョンに更新
することで解決します。詳細は、Juniperが提供する情報を参照してください。
</Summary>

        <Reference Language="ENGLISH">
             <Name>Juniper Networks</Name>
             <Title>Browse by Category: Security Advisories - Security Advisories</Title>
             <URL>https://kb.juniper.net/InfoCenter/index?page=content&amp;channel=SECURITY_ADVISORIES</URL>
        </Reference>

</Article>

<Article RiskLevel="1" Type="RU">
          <Title>Apache Tomcatにサービス運用妨害（DoS）の脆弱性</Title>
          <Source>
               <Name>CISA Current Activity</Name>
               <Title>Apache Releases Security Advisory for Tomcat</Title>
               <URL>https://us-cert.cisa.gov/ncas/current-activity/2021/10/15/apache-releases-security-advisory-tomcat</URL>
          </Source>
          <Source>
               <Name>Japan Vulnerability Notes JVNVU#92237586</Name>
               <Title>Apache Tomcatにおけるサービス運用妨害（DoS）の脆弱性</Title>
               <URL>https://jvn.jp/vu/JVNVU92237586/</URL>
          </Source>

<Summary>
Apache Tomcatには、サービス運用妨害（DoS）の脆弱性があります。結果とし
て、遠隔の第三者がサービス運用妨害（DoS）攻撃を行う可能性があります。

対象となるバージョンは次のとおりです。

- Apache Tomcat 10.1.0-M1から10.1.0-M5まで
- Apache Tomcat 10.0.0-M10から10.0.11まで
- Apache Tomcat 9.0.40から9.0.53まで
- Apache Tomcat 8.5.60から8.5.71まで

この問題は、Apache TomcatをThe Apache Software Foundationが提供する修
正済みのバージョンに更新することで解決します。詳細は、
The Apache Software Foundationが提供する情報を参照してください。
</Summary>

        <Reference Language="ENGLISH">
             <Name>The Apache Software Foundation</Name>
             <Title>CVE-2021-42340 Denial of Service</Title>
             <URL>https://lists.apache.org/thread.html/r83a35be60f06aca2065f188ee542b9099695d57ced2e70e0885f905c%40%3Cannounce.apache.org%3E</URL>
        </Reference>

        <Reference Language="ENGLISH">
             <Name>The Apache Software Foundation</Name>
             <Title>Fixed in Apache Tomcat 10.1.0-M6</Title>
             <URL>https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.0-M6</URL>
        </Reference>
        
        <Reference Language="ENGLISH">
             <Name>The Apache Software Foundation</Name>
             <Title>Fixed in Apache Tomcat 10.0.12</Title>
             <URL>https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.0.12</URL>
        </Reference>
        
        <Reference Language="ENGLISH">
             <Name>The Apache Software Foundation</Name>
             <Title>Fixed in Apache Tomcat 9.0.54</Title>
             <URL>https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.54</URL>
        </Reference>
        
        <Reference Language="ENGLISH">
             <Name>The Apache Software Foundation</Name>
             <Title>Fixed in Apache Tomcat 8.5.72</Title>
             <URL>https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.72</URL>
        </Reference>
        
</Article>

<Article RiskLevel="1" Type="RU">
        <Title>複数のIntel製品に脆弱性</Title>
          <Source>
            <Name>Japan Vulnerability Notes JVNVU#92532697</Name>
             <Title>Intel製品に複数の脆弱性（2021年10月）</Title>
             <URL>https://jvn.jp/vu/JVNVU92532697/</URL>
          </Source>

<Summary>
複数のIntel製品には、脆弱性があります。結果として、第三者が権限を昇格
したり、情報を窃取したりする可能性があります。

対象となる製品は、多岐にわたります。詳細は、Intelが提供する情報を参照
してください。
</Summary>

        <Reference Language="ENGLISH">
             <Name>Intel</Name>
             <Title>Intel HAXM Advisory</Title>
             <URL>https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00544.html</URL>
        </Reference>

        <Reference Language="ENGLISH">
             <Name>Intel</Name>
             <Title>Intel SGX SDK Advisory</Title>
             <URL>https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00548.html</URL>
        </Reference>

        <Reference Language="JAPANESE">
             <Name>JPCERT/CC CyberNewsFlash</Name>
             <Title>Intel製品に関する複数の脆弱性について</Title>
             <URL>https://www.jpcert.or.jp/newsflash/2021101301.html</URL>
        </Reference>

</Article>

<Article RiskLevel="1" Type="RU">
          <Title>オムロン製CX-Supervisorに領域外のメモリ参照の脆弱性</Title>
          <Source>
               <Name>Japan Vulnerability Notes JVNVU#90041391</Name>
               <Title>オムロン製CX-Supervisorにおける領域外のメモリ参照の脆弱性</Title>
               <URL>https://jvn.jp/vu/JVNVU90041391/</URL>
          </Source>

<Summary>
オムロン株式会社が提供するCX-Supervisorには、領域外のメモリ参照の脆弱
性があります。結果として、当該製品の設定を変更可能なユーザーが、細工さ
れたSCSプロジェクトファイルを開くことで、情報漏えいが起きたり、任意の
コードを実行されたりする可能性があります。

対象となるバージョンは次のとおりです。

- CX-Supervisor v4.0.0.13、v4.0.0.16

開発者によると、本脆弱性を検証し再現することを確認したバージョンは上記
であるとのことです。また、CX-Supervisorは日本国外でのみ販売されている
製品であるとのことです。

この問題は、該当する製品をオムロン株式会社が提供する修正済みのバージョン
に更新することで解決します。詳細は、オムロン株式会社が提供する情報を参
照してください。
</Summary>

        <Reference Language="ENGLISH">
             <Name>オムロン株式会社</Name>
             <Title>Release Notes For CX-Supervisor 4.1.1.2</Title>
             <URL>https://www.myomron.com/index.php?action=kb&amp;article=1692</URL>
        </Reference>

</Article>

<Memo>
<Title>内閣サイバーセキュリティセンター（NISC）がランサムウェア特設ページ「ストップ！ランサムウェア」を公開</Title>

<Content>
2021年10月13日、内閣サイバーセキュリティセンター（NISC）は、日本国内の
関係機関におけるランサムウェアに関する取り組みを紹介する特設ページ
「ストップ！ランサムウェア」を公開しました。ランサムウェアによるサイバー
攻撃は国内外のさまざまな組織で確認されており、注意が必要です。被害防止
の対策や緊急時の対応体制などをご検討いただく上での参考情報としてご活用
ください。</Content>

         <Reference Language="JAPANESE">
             <Name>内閣サイバーセキュリティセンター（NISC）</Name>
             <Title>ランサムウェア特設ページ</Title>
             <URL>https://security-portal.nisc.go.jp/stopransomware/</URL>
         </Reference>

  </Memo>
</JpcertCcReport>