B
今週中
Progress Softwareは、Kemp LoadMaster、ECS Connection Manager、およびConnection Manager…
📌 一言でいうと
Progress Softwareは、Kemp LoadMaster、ECS Connection Manager、およびConnection Manager for ObjectScaleにおける5つの高深刻度の脆弱性を修正するアップデートをリリースしました。これらの脆弱性が悪用された場合、認証済みの攻撃者が権限を昇格させ、ターゲットシステム上で任意のコードを実行できる可能性があります。影響を受けるバージョンは、製品によって異なりますが、主にバージョン7.2.63.2以前などが対象となります。
🔍該当判定
- Progress社の『Kemp LoadMaster』を導入して利用している
- Progress社の『ECS Connection Manager』を導入して利用している
- Progress社の『Connection Manager for ObjectScale』を導入して利用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
ベンダーが提供する最新のセキュリティアップデートを適用してください。各製品の公式セキュリティアドバイザリを確認し、適切なバージョンへの更新を推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Progress Software製品 (Kemp LoadMaster等) の脆弱性対応について
お疲れさまです。Progress Software製品の脆弱性に関する情報共有です。
■ 概要
Kemp LoadMaster、ECS Connection Manager、Connection Manager for ObjectScaleにおいて、権限昇格および任意のコード実行が可能な5つの高深刻度な脆弱性が報告されました。認証済みのユーザーによる攻撃が想定されます。
■ 影響範囲
- Progress ECS Connection Manager / Connection Manager for ObjectScale: v7.2.63.2 以前 (GA)
- Progress Kemp LoadMaster: v7.2.54.18 以前 (LTFS)
- Progress Kemp Multi-Tenant LoadMaster: v7.1.35.15 以前
■ 対応手順
1. 自社環境で利用している製品およびバージョンの確認
2. ベンダーの公式セキュリティアドバイザリに基づき、最新バージョンへのアップデートを適用
■ 参考情報
- Progress Software 公式セキュリティアドバイザリ
対応優先度: 高
対応期限: 速やかに
お疲れさまです。Progress Software製品の脆弱性に関する情報共有です。
■ 概要
Kemp LoadMaster、ECS Connection Manager、Connection Manager for ObjectScaleにおいて、権限昇格および任意のコード実行が可能な5つの高深刻度な脆弱性が報告されました。認証済みのユーザーによる攻撃が想定されます。
■ 影響範囲
- Progress ECS Connection Manager / Connection Manager for ObjectScale: v7.2.63.2 以前 (GA)
- Progress Kemp LoadMaster: v7.2.54.18 以前 (LTFS)
- Progress Kemp Multi-Tenant LoadMaster: v7.1.35.15 以前
■ 対応手順
1. 自社環境で利用している製品およびバージョンの確認
2. ベンダーの公式セキュリティアドバイザリに基づき、最新バージョンへのアップデートを適用
■ 参考情報
- Progress Software 公式セキュリティアドバイザリ
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Vulnerabilities in Progress Software Products (Kemp LoadMaster, etc.)
Dear IT/Security Team,
This is a notification regarding high-severity vulnerabilities identified in Progress Software products.
■ Overview
Five high-severity vulnerabilities have been discovered in Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale. These flaws could allow an authenticated attacker to achieve privilege escalation and execute arbitrary code.
■ Affected Scope
- Progress ECS Connection Manager / Connection Manager for ObjectScale: v7.2.63.2 and earlier (GA)
- Progress Kemp LoadMaster: v7.2.54.18 and earlier (LTFS)
- Progress Kemp Multi-Tenant LoadMaster: v7.1.35.15 and earlier
■ Mitigation Steps
1. Identify the current versions of the affected products in your environment.
2. Apply the latest security updates as specified in the vendor's official security bulletin.
■ Reference
- Progress Software Official Security Advisory
Priority: High
Deadline: Immediate
Dear IT/Security Team,
This is a notification regarding high-severity vulnerabilities identified in Progress Software products.
■ Overview
Five high-severity vulnerabilities have been discovered in Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale. These flaws could allow an authenticated attacker to achieve privilege escalation and execute arbitrary code.
■ Affected Scope
- Progress ECS Connection Manager / Connection Manager for ObjectScale: v7.2.63.2 and earlier (GA)
- Progress Kemp LoadMaster: v7.2.54.18 and earlier (LTFS)
- Progress Kemp Multi-Tenant LoadMaster: v7.1.35.15 and earlier
■ Mitigation Steps
1. Identify the current versions of the affected products in your environment.
2. Apply the latest security updates as specified in the vendor's official security bulletin.
■ Reference
- Progress Software Official Security Advisory
Priority: High
Deadline: Immediate