Splunk Enterprise Security

Nessus scan shows CVE-2012-4930, CVE-2012-4929 vulnerabilities

phanichintha
Path Finder

Hello All,

In my organisation, the Nessus scanner scans the Splunk servers and other application servers. Scanner found the vulnerabilities CVE-2012-4930, CVE-2012-4929 with the port 8089. Splunk servers have open SSL certs and the other application servers have Splunk UF as well.
SSL Self-Signed Certificate
SSL Certificate Cannot Be Trusted
SSL Certificate with Wrong Hostname
Transport Layer Security (TLS) Protocol CRIME Vulnerability

Can anyone please share the inputs what I have to do to remove the above vulnerabilities.
1. For Splunk servers what are the changes that need to be done?
2. For application servers where UF is installed what are the changes that need to be done?
3. Or if we install the trusted SSL certs in Splunk servers is it enough to do to get remove the vulnerabilities.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...