Tenable SecurityCenter 5.2.x / 5.3.x < 5.3.1 Multiple Vulnerabilities (TNS-2016-07)

Medium Nessus Plugin ID 90429


The application installed on the remote host is affected by multiple vulnerabilities.


According to its version, the Tenable SecurityCenter application installed on the remote host is 5.2.x or 5.3.x prior to 5.3.1. It is, therefore, affected by multiple vulnerabilities :

- Multiple cross-site scripting (XSS) vulnerabilities exist due to a failure to properly validate input before returning it to users. A remote attacker can exploit these, via a crafted request, to execute arbitrary script code in a user's browser session.
(CVE-2016-82008, CVE-2016-82009, CVE-2016-82010)

- An unspecified flaw exists that allows an authenticated, remote attacker to disclose the installation path of the application. (CVE-2016-82011)

- A flaw exists in Apache Felix due to a failure to use the HTTPOnly or Secure attribute for authentication cookies. An unauthenticated, remote attacker can exploit this to more easily disclose sensitive information.
(VulnDB 136592)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.


Upgrade to Tenable SecurityCenter version 5.3.1 or later.

See Also


Plugin Details

Severity: Medium

ID: 90429

File Name: securitycenter_5_3_1_xss.nasl

Version: $Revision: 1.8 $

Type: local

Family: Misc.

Published: 2016/04/12

Modified: 2017/03/07

Dependencies: 71158

Risk Information

Risk Factor: Medium


Base Score: 4.3

Temporal Score: 3.6

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Temporal Vector: CVSS2#E:F/RL:OF/RC:ND


Base Score: 4.7

Temporal Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:X

Vulnerability Information

CPE: cpe:/a:tenable:securitycenter

Required KB Items: Host/SecurityCenter/Version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2016/04/01

Vulnerability Publication Date: 2016/04/01

Reference Information

CVE: CVE-2016-82008, CVE-2016-82009, CVE-2016-82010, CVE-2016-82011

OSVDB: 136588, 136589, 136590, 136591, 136592