[R1] Stand-alone Security Patch Available for Tenable.sc versions 5.16.0 to 5.19.1: Patch 202201.1

Related Vulnerabilities: CVE-2021-44224   CVE-2021-44790  

Tenable.sc leverages third-party software to help provide underlying functionality. One of the third-party components (Apache) was found to contain vulnerabilities, and updated versions have been made available by the providers. Out of caution, and in line with best practice, Tenable has upgraded the bundled components to address the potential impact of these issues. Tenable.sc Patch 202201.1 updates Apache to version 2.4.52 to address the identified vulnerabilities. Note: This fix is already included in Tenable.sc versions 5.20.0 and above. Please see https://www.tenable.com/security/tns-2022-01 for additional information.

Synopsis

Tenable.sc leverages third-party software to help provide underlying functionality. One of the third-party components (Apache) was found to contain vulnerabilities, and updated versions have been made available by the providers.

Out of caution, and in line with best practice, Tenable has upgraded the bundled components to address the potential impact of these issues. Tenable.sc Patch 202201.1 updates Apache to version 2.4.52 to address the identified vulnerabilities.

Note: This fix is already included in Tenable.sc versions 5.20.0 and above. Please see https://www.tenable.com/security/tns-2022-01 for additional information.

Solution

Tenable has released Tenable.sc Patch 202201.1 to address these issues. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/tenable-sc).