- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Envision 4 --- Vulnerability in Apache Tomcat
We recently discovered a critical vulnerability in our Envision 4.0 system. After running a vulnerability assessment against our Envision 4.0 system we discovered that it is running Apache Tomcat 5.5.26 which has several vulnerabilities which are rated as critical / non PCI compliant. RSA support is aware of the problem but is not expecting to have a patch released until sometime in Q2 of 2010.
Has anyone else seen this?
Any suggestions or work arounds would be appreciated.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
We use Saint Scans which outlined the same issue with Apache.
Any more news about SP4 being released?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Service Pack's have been fixing this kind of stuff. It is known... Make sure you open a ticket with support so it can be tracked.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
What are the specific vulnerabilities and are there mitigation steps apart from waiting for the SP?
What are the specific vulnerabilities and are there mitigation steps apart from waiting for the SP?
David
