AppDetectivePRO and DbProtect Knowledgebase Update – June 17, 2014

The next update to the Knowledgebase for AppDetectivePRO and DbProtect is now available.

Knowledgebase version 4.37 includes checks for new vulnerabilities and configuration issues in IBM DB2 LUW, Microsoft SQL Server, Hadoop, and Sybase ASE.

This update also includes improvements to existing checks to determine whether you're correctly patching your IBM DB2 LUW and MySQL installations in accordance with your organization's security policy. See below for highlights.

New Vulnerability and Configuration Check Highlights

IBM DB2 LUW
  • IBM DB2 LUW GSKit Lucky Thirteen security vulnerability (CVE-2013-0169)
Sybase ASE
  • Password based on username
Microsoft SQL Server
  • Extended protection for authentication is not enabled
  • Netbios and/or SMB protocols enabled
  • Using self-signed certificate
Hadoop
  • RPC protocol implementation flaw (CVE-2013-2192)
  • Shared directory used by multiple NameNodes in an HA cluster

How to Update?

All AppDetectivePRO and DbProtect customers can download and install the latest update from the Customer Support Portal. AppDetectivePRO customers can receive the update by launching the "Updater" within the product.

Trustwave reserves the right to review all comments in the discussion below. Please note that for security and other reasons, we may not approve comments containing links.