Splunk Enterprise Security

Nessus scan shows CVE-2012-4930, CVE-2012-4929 vulnerabilities

phanichintha
Path Finder

Hello All,

In my organisation, the Nessus scanner scans the Splunk servers and other application servers. Scanner found the vulnerabilities CVE-2012-4930, CVE-2012-4929 with the port 8089. Splunk servers have open SSL certs and the other application servers have Splunk UF as well.
SSL Self-Signed Certificate
SSL Certificate Cannot Be Trusted
SSL Certificate with Wrong Hostname
Transport Layer Security (TLS) Protocol CRIME Vulnerability

Can anyone please share the inputs what I have to do to remove the above vulnerabilities.
1. For Splunk servers what are the changes that need to be done?
2. For application servers where UF is installed what are the changes that need to be done?
3. Or if we install the trusted SSL certs in Splunk servers is it enough to do to get remove the vulnerabilities.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...