if vulnerability has been patched?

This support forum board is for support questions relating to Nagios XI, our flagship commercial network monitoring solution.
Locked
User avatar
chicjo01
Posts: 194
Joined: Tue Jul 28, 2015 2:52 pm

if vulnerability has been patched?

Post by chicjo01 »

Our security team wants to know if the below vulnerability still exists or where they fixed in 5.2.8 or 5.2.9 updates?

Current Version We are using: 5.2.9

Nagios XI Command Injection
Check Point Reference CPAI-2016-0593

A Command Injection vulnerability exists in Nagios XI.
This protection detects attempts to exploit this vulnerability.

Nagios XI SQL Injection
Check Point Reference CPAI-2016-0594

An SQL injection vulnerability exists in Nagios XI.
This protection detects attempts to exploit this vulnerability.
rkennedy
Posts: 6579
Joined: Mon Oct 05, 2015 11:45 am

Re: if vulnerability has been patched?

Post by rkennedy »

I believe both of these have been fixed. You'll want to make sure all of your components are up to date as well, not just the software. Are they all up to date as well? (Admin -> Manage Components)

EDIT: I'd like to confirm this -- any way you can provide the CVE ID's for these? I can't seem to get it out of the check point references.

https://www.checkpoint.com/defense/advi ... -0593.html
https://www.checkpoint.com/defense/advi ... -0594.html
Former Nagios Employee
jomann
Development Lead
Posts: 611
Joined: Mon Apr 22, 2013 10:06 am
Location: Nagios Enterprises

Re: if vulnerability has been patched?

Post by jomann »

I can confirm that these are fixed in 5.2.8. The references you gave look like they are pointing at the advisory from security-assessment which were mostly fixed in 5.2.8 with the exception of the profile component upload which requires admin rights to do. That profile component upload was changed in 5.2.9 though, and you can no longer upload a profile component through the web UI.
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.
User avatar
chicjo01
Posts: 194
Joined: Tue Jul 28, 2015 2:52 pm

Re: if vulnerability has been patched?

Post by chicjo01 »

Thank you for the information and confirmation. I will let me security know.
tmcdonald
Posts: 9117
Joined: Mon Sep 23, 2013 8:40 am

Re: if vulnerability has been patched?

Post by tmcdonald »

Is it alright if we close this up?
Former Nagios employee
User avatar
chicjo01
Posts: 194
Joined: Tue Jul 28, 2015 2:52 pm

Re: if vulnerability has been patched?

Post by chicjo01 »

yes
Locked