Splunk Enterprise Security

Nessus scan shows CVE-2012-4930, CVE-2012-4929 vulnerabilities

phanichintha
Path Finder

Hello All,

In my organisation, the Nessus scanner scans the Splunk servers and other application servers. Scanner found the vulnerabilities CVE-2012-4930, CVE-2012-4929 with the port 8089. Splunk servers have open SSL certs and the other application servers have Splunk UF as well.
SSL Self-Signed Certificate
SSL Certificate Cannot Be Trusted
SSL Certificate with Wrong Hostname
Transport Layer Security (TLS) Protocol CRIME Vulnerability

Can anyone please share the inputs what I have to do to remove the above vulnerabilities.
1. For Splunk servers what are the changes that need to be done?
2. For application servers where UF is installed what are the changes that need to be done?
3. Or if we install the trusted SSL certs in Splunk servers is it enough to do to get remove the vulnerabilities.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...

Explore the Latest Educational Offerings from Splunk (November Releases)

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...