Wuerth Phoenix has released some Critical Patches (CPs) for NetEye 4. These CPs resolve multiple vulnerabilities related to SQL injections, Cross Site Scripting and an unauthenticated remote command execution (RCE) exploit.
Description
GLPI was affected by:
[Critical] RCE using a third-party library script (CVE-2022-35914).
[Critical] Privilege Escalation by authentication via SQL injection (CVE-2022-35947)
XSS through registration API (CVE-2022-35945)
Leak of sensitive information through login page error (CVE-2022-31143)
SQL injection through plugin controller (CVE-2022-35946)
CVE-2022-35914 RCE workaround for older NetEye 4 versions
Remove /usr/share/glpi/vendor/htmlawed/htmlawed/htmLawedTest.php file from the filesystem on all NetEye nodes. This will prevent unauthenticated attackers to compromise your NetEye installation.
Solution
For details on how to apply this update, which includes the changes described in this advisory, refer to the NetEye Update Section inside the User Guide.
Affected Products
All NetEye 4.x versions prior to and including 4.26.
Full Stack Developer at Wuerth Phoenix. I love questioning myself, find new challenges to learn and new adventures to grow up. PHP lover trying to expand my skills studying new languages and tools to improve my professional life.
Author
Gianluca Piccolo
Full Stack Developer at Wuerth Phoenix. I love questioning myself, find new challenges to learn and new adventures to grow up. PHP lover trying to expand my skills studying new languages and tools to improve my professional life.
Important: Keycloak security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the keycloak packages is now available for NetEye 4. Security Fix for NetEye 4.49 26.7.3_neteye1.46.1-1 Summary This Keycloak update (version 26.7.3) Read More
Icinga 2 live-creation requests are no longer lost during reload During a Director deployment, Icinga 2 reloads its configuration in the background. Previously, live-creation requests could still be processed for a short time after a reload had been requested. This Read More
Important: Elastic Stack security update Type/Severity NetEye Product Security has rated this update as having a High security impact. Topic Updates for the Elastic Stack packages are now available for NetEye 4. Security Fix for NetEye 4.49 9.4.6_neteye3.103.8-1 CVEs Elastic Read More
Important: Keycloak security update Type/Severity NetEye Product Security has rated this update as having a critical security impact. Topic An update for the keycloak packages is now available for NetEye 4. Security Fix for NetEye 4.49 26.7.2_neteye1.46.1-1 Summary This vulnerability, tracked as CVE-2026-18963 Read More
Important: Icinga 2 security update Type/Severity NetEye Product Security has rated this update as having a medium security impact. Topic An update for the icinga package is now available for NetEye 4. Security Fix for NetEye 4.49 2.15.6_neteye1.73.1-1 Summary This release fixes authorization Read More