Splunk Enterprise Security

Nessus scan shows CVE-2012-4930, CVE-2012-4929 vulnerabilities

phanichintha
Path Finder

Hello All,

In my organisation, the Nessus scanner scans the Splunk servers and other application servers. Scanner found the vulnerabilities CVE-2012-4930, CVE-2012-4929 with the port 8089. Splunk servers have open SSL certs and the other application servers have Splunk UF as well.
SSL Self-Signed Certificate
SSL Certificate Cannot Be Trusted
SSL Certificate with Wrong Hostname
Transport Layer Security (TLS) Protocol CRIME Vulnerability

Can anyone please share the inputs what I have to do to remove the above vulnerabilities.
1. For Splunk servers what are the changes that need to be done?
2. For application servers where UF is installed what are the changes that need to be done?
3. Or if we install the trusted SSL certs in Splunk servers is it enough to do to get remove the vulnerabilities.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...