현재 자주 악용되고 있는 취약점 목록으로, 취약한 버전의 SW를 사용 중인 경우 긴급 패치를 권고 드립니다. * 참조 링크 : https://www.cisa.gov/known-exploited-vulnerabilities-catalogcveID | vendorProject | vulnerabilityName | dateAdded | shortDescription | requiredAction | dueDate |
---|
CVE-2023-21839 | Oracle | Oracle WebLogic Server Unspecified Vulnerability | 2023-05-01 | Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server. | Apply updates per vendor instructions. | 2023-05-22 |
---|
CVE-2021-45046 | Apache | Apache Log4j2 Deserialization of Untrusted Data Vulnerability | 2023-05-01 | Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations. | Apply updates per vendor instructions. | 2023-05-22 |
---|
CVE-2023-1389 | TP-Link | TP-Link Archer AX-21 Command Injection Vulnerability | 2023-05-01 | TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution. | Apply updates per vendor instructions. | 2023-05-22 |
---|
|
|