Several vulnerabilities were discovered in the underlying OS packages in AlienVault USM Appliance and OSSIM v5.3.7 and earlier. All of the vulnerabilities below have been confirmed and fixed in the AlienVault v5.4. AlienVault encourages customers to upgrade all AlienVault appliances to eliminate the vulnerabilities.
See the v5.4 release notice for details on the release.
Random ramblings and findings whilst maintaining and supporting MS Active Directory and interfacing
Showing posts with label AlienVault. Show all posts
Showing posts with label AlienVault. Show all posts
Thursday, 29 June 2017
AlienVault v5.4 Addresses 72 vulnerabilities
Wednesday, 5 October 2016
LDAP Authentication issues in USM and OSSIM v5.3.2
If you are using LDAP authentication for your OSSIM or USM installation you may want to hold off the v5.3.2 upgrade.
In a recent message from AlienVault, an issue has been detected during the password reset process post upgrade. The Password reset process was initiated to improve the security of password storage within OSSIM and USM, however this process is not working correctly for LDAP authentication.
LDAP Authentication issues in USM and OSSIM v5.3.2
If you are using LDAP authentication for your OSSIM or USM installation you may want to hold off the v5.3.2 upgrade.
In a recent message from AlienVault, an issue has been detected during the password reset process post upgrade. The Password reset process was initiated to improve the security of password storage within OSSIM and USM, however this process is not working correctly for LDAP authentication.
Friday, 30 September 2016
Collecting McAfee ePO threat data using AlienVault OSSIM
If you are using AlienVault OSSIM you can collect ePO Threat Data and add it to your SIEM Security Events.
AlienVault have already development a database plugin to connect to the ePO Database, collect and parse the data into the OSSIM Database, but I have struggled to get this to work with our MS-SQL Database cluster, resulting in 'ParserDatabase [INFO]: Can't connect to MS-SQL database' errors.
The steps for enabling the plugin and collecting the data are:
AlienVault have already development a database plugin to connect to the ePO Database, collect and parse the data into the OSSIM Database, but I have struggled to get this to work with our MS-SQL Database cluster, resulting in 'ParserDatabase [INFO]: Can't connect to MS-SQL database' errors.
The steps for enabling the plugin and collecting the data are:
- Enabling the Plugin
- Creating a local configuration file
- Configuring the database connection
- Troubleshooting connection errors
Labels:
AlienVault,
ePO,
McAfee
Location:
St Neots, UK
Subscribe to:
Posts (Atom)