AppDetectivePRO and DbProtect Knowledgebase Update – July 15, 2014

The next update to our AppDetectivePRO and DbProtect Knowledgebase is now available.

Knowledgebase version 4.38 includes checks for new vulnerabilities and configuration issues in IBM DB2 LUW, Hadoop and MySQL. See below for highlights.

New Vulnerability and Configuration Check Highlights

IBM DB2 LUW

  • Elevated privileges with DB2 executables (CVE-2014-0901)
  • Multiple TLS/SSL security vulnerabilities (CVE-2014-0693, CVE-2013-6747)
  • Privilege escalation via stored procedure infrastructure (CVE-2013-6744)

Hadoop

  • Permissions on logs/audit files

MySQL

  • Password based on username

How to Update?

All AppDetectivePRO and DbProtect customers can download and install the latest update from the Customer Support Portal. AppDetectivePRO customers can update their deployment by launching the "Updater" within the product.

Trustwave reserves the right to review all comments in the discussion below. Please note that for security and other reasons, we may not approve comments containing links.