27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>PVS</strong> ID: 6396 FAMILY: Policy RISK: INFO NESSUS ID:Not Available<br />

Description: The following link to your web server was posted to Facebook : %P<br />

realtimeonly<br />

Solution: Solution Not Available<br />

CVE Not available<br />

Facebook Application Access<br />

<strong>PVS</strong> ID: 6397 FAMILY: Policy RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is accessing the following Facebook application: %L<br />

realtimeonly<br />

Solution: Solution Not Available<br />

CVE Not available<br />

Tivoli Provisioning Manager Express for Software Distribution Multiple SQL Injection<br />

Vulnerabilities<br />

<strong>PVS</strong> ID: 6398 FAMILY: CGI RISK: HIGH NESSUS ID:58529<br />

Description: Synopsis :\n\nThe remote web application is affected by multiple SQL injection<br />

vulnerabilities.\n\nThe remote web server hosts Tivoli Provisioning Manager Express for<br />

Software Distribution, a web-based application for distributing software. For your<br />

information, the observed version of Tivoli Provisioning Manager Express for Software<br />

Distribution is:\n %L\n\nTivoli Provisioning Manager Express for Software Distribution<br />

fails to properly sanitize user supplied input to the following servlets :\n\n -<br />

Printer.getPrinterAgentKey() in the SoapServlet servlet\n\n - User.updateUserValue() in<br />

the register.do servlet\n\n - User.isExistingUser() in the logon.do servlet\n\n -<br />

Asset.getHWKey() in the CallHomeExec servlet\n\n - Asset.getMimeType() in the<br />

getAttachment servlet\n\nAn unauthenticated, remote attacker, can leverage these issues to<br />

manipulate database queries, leading to disclosure of sensitive information, attacks against<br />

the underlying database, and the like.<br />

Solution: There is no replacement for Tivoli Provisioning Manager Express for Software<br />

Distribution. IBM recommends installing Tivoli Endpoint Manager for Lifecycle<br />

Management v8.1.<br />

CVE-2012-0199<br />

Opera < 11.62 Multiple Vulnerabilities<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 6399 FAMILY: Web Clients RISK: HIGH NESSUS ID:Not Available<br />

Family Internet Services 1748

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!