[R1] Stand-alone Security Patch Available for Tenable.sc versions 5.19.0 to 5.20.1: Patch 202204.1

Related Vulnerabilities: CVE-2022-0778   CVE-2022-23943  

Tenable.sc leverages third-party software to help provide underlying functionality. Two of the third-party components (Apache and OpenSSL) were found to contain vulnerabilities, and updated versions have been made available by the providers. Out of caution, and in line with best practice, Tenable has upgraded the bundled components to address the potential impact of these issues. Tenable.sc Patch 202204.1 updates OpenSSL to version 1.1.1n and Apache to version 2.4.53 to address the identified vulnerabilities.

Synopsis

Tenable.sc leverages third-party software to help provide underlying functionality. Two of the third-party components (Apache and OpenSSL) were found to contain vulnerabilities, and updated versions have been made available by the providers.

Out of caution, and in line with best practice, Tenable has upgraded the bundled components to address the potential impact of these issues. Tenable.sc Patch 202204.1 updates OpenSSL to version 1.1.1n and Apache to version 2.4.53 to address the identified vulnerabilities.

Solution

Tenable has released Tenable.sc Patch 202204.1 to address these issues. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/tenable-sc).