required Vulnerability Fix
Posted: Wed Jan 06, 2021 5:36 am
Hi Team,
we are getting a few Vulnerability issues in port 443 of Nagios XI,
Nagios XI SQL Injection vulnerability
SSL/TLS use of weak RC4(Arcfour) cipher
SSLv3 Padding Oracle Attack Information Disclosure Vulnerability (POODLE)
SSL Server Has SSLv3 Enabled Vulnerability
SSL/TLS Server supports TLSv1.0
Birthday attacks against TLS ciphers with 64bit block size vulnerability (Sweet32)
SSLv3.0/TLSv1.0 Protocol Weak CBC Mode Server Side Vulnerability (BEAST)
SSL Certificate - Subject Common Name Does Not Match Server FQDN
SSL Certificate - Signature Verification Failed Vulnerability
Sensitive form field has not disabled autocomplete
HTTP Security Header Not Detected
AutoComplete Attribute Not Disabled for Password in Form Based Authentication
Sensitive form field has not disabled autocomplete
TCP Sequence Number Approximation Based Denial of Service
Please suggest how to fix
Apache version:- Server version: Apache/2.4.6 (CentOS)
Nagios XI Version:- 5.7.5
we are getting a few Vulnerability issues in port 443 of Nagios XI,
Nagios XI SQL Injection vulnerability
SSL/TLS use of weak RC4(Arcfour) cipher
SSLv3 Padding Oracle Attack Information Disclosure Vulnerability (POODLE)
SSL Server Has SSLv3 Enabled Vulnerability
SSL/TLS Server supports TLSv1.0
Birthday attacks against TLS ciphers with 64bit block size vulnerability (Sweet32)
SSLv3.0/TLSv1.0 Protocol Weak CBC Mode Server Side Vulnerability (BEAST)
SSL Certificate - Subject Common Name Does Not Match Server FQDN
SSL Certificate - Signature Verification Failed Vulnerability
Sensitive form field has not disabled autocomplete
HTTP Security Header Not Detected
AutoComplete Attribute Not Disabled for Password in Form Based Authentication
Sensitive form field has not disabled autocomplete
TCP Sequence Number Approximation Based Denial of Service
Please suggest how to fix
Apache version:- Server version: Apache/2.4.6 (CentOS)
Nagios XI Version:- 5.7.5