[R1] SecurityCenter 5.6.0 Fixes One Vulnerability

Related Vulnerabilities: CVE-2017-11508  

SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the password field of a diagnostic scan within SecurityCenter. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to the SecurityCenter database. CVE-2017-11508

Synopsis

SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the password field of a diagnostic scan within SecurityCenter. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to the SecurityCenter database.

CVE-2017-11508

Solution

Tenable has released SecurityCenter 5.6.0 to address this issue. The new version can be obtained from the Tenable Support Portal. https://support.tenable.com/support-center/index.php?x=&mod_id=160 Additionally, a patch has been created to address this issue for SecurityCenter 5.5.0, 5.5.1 and 5.5.2. The patch and associated checksums can be found at: http://static.tenable.com/prod_docs/upgrade_security_center.html