27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

with interactive access to the host may corrupt these scripts and programs during the<br />

installation process. This vulnerability exists only in the Linux archive version. If you<br />

installed Firefox using your Linux distribution packaging system, the vulnerability is likely<br />

not present on the remote system.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2004-0906<br />

BEA WebLogic < 8.1.0 SP 3 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 2282 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is missing a critical security patch or upgrade.\n\nThe<br />

remote host is running BEA WebLogic. Multiple undisclosed vulnerabilities have been<br />

reported in every version of WebLogic up to and including 8.1.0 SP2. An attacker may<br />

exploit these issues to gain unauthorized access or to gather information about the remote<br />

host. BEA WebLogic 8.1 Service Pack 3 addresses these vulnerabilities.<br />

Solution: Upgrade to WebLogic 8.1.0 SP3 or higher.<br />

CVE-2004-2320<br />

Microsoft WinErr Version Check<br />

<strong>PVS</strong> ID: 2283 FAMILY: Operating System Detection RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Microsoft has a functionality in which error messages are sent to Microsoft Corp. <strong>PVS</strong> has<br />

just noted a network client sending such an error to Microsoft. According to the error<br />

message, the network client is running Microsoft version %L<br />

Solution: Depending on corporate policy, you may wish to disable Windows Error Messages.<br />

CVE Not available<br />

Outbound Microsoft WinErr Message<br />

<strong>PVS</strong> ID: 2284 FAMILY: Operating System Detection RISK: INFO NESSUS ID:Not Available<br />

Description: The remote client has enabled automatic Windows Error Reporting. This functionality<br />

allows Microsoft to gather error reports from local clients. According to the error report,<br />

the remote client just had an error in %L and has sent an error report to Microsoft.<br />

realtime<br />

Solution: Ensure that such reporting is in alignment with existing corporate standards and policies.<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 574

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!