Tenable SecurityCenter 5.2.x / 5.3.x < 5.3.1 Multiple Vulnerabilities (TNS-2016-07)
Medium Nessus Plugin ID 90429
SynopsisThe application installed on the remote host is affected by multiple vulnerabilities.
DescriptionAccording to its version, the Tenable SecurityCenter application installed on the remote host is 5.2.x or 5.3.x prior to 5.3.1. It is, therefore, affected by multiple vulnerabilities :
- Multiple cross-site scripting (XSS) vulnerabilities exist due to a failure to properly validate input before returning it to users. A remote attacker can exploit these, via a crafted request, to execute arbitrary script code in a user's browser session.
(CVE-2016-82008, CVE-2016-82009, CVE-2016-82010)
- An unspecified flaw exists that allows an authenticated, remote attacker to disclose the installation path of the application. (CVE-2016-82011)
- A flaw exists in Apache Felix due to a failure to use the HTTPOnly or Secure attribute for authentication cookies. An unauthenticated, remote attacker can exploit this to more easily disclose sensitive information.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
SolutionUpgrade to Tenable SecurityCenter version 5.3.1 or later.