Splunk Enterprise Security

Nessus scan shows CVE-2012-4930, CVE-2012-4929 vulnerabilities

phanichintha
Path Finder

Hello All,

In my organisation, the Nessus scanner scans the Splunk servers and other application servers. Scanner found the vulnerabilities CVE-2012-4930, CVE-2012-4929 with the port 8089. Splunk servers have open SSL certs and the other application servers have Splunk UF as well.
SSL Self-Signed Certificate
SSL Certificate Cannot Be Trusted
SSL Certificate with Wrong Hostname
Transport Layer Security (TLS) Protocol CRIME Vulnerability

Can anyone please share the inputs what I have to do to remove the above vulnerabilities.
1. For Splunk servers what are the changes that need to be done?
2. For application servers where UF is installed what are the changes that need to be done?
3. Or if we install the trusted SSL certs in Splunk servers is it enough to do to get remove the vulnerabilities.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...