Application Security, Inc.
home client login partner login online store contact us
search:
Solutions Products Partners Support News & Events About Us

Security Updates - ASAP™ Updates
(Application Security Automatic Protection)

ASAP Update: AppDetectivePro Update 5.4.1 - 21 April 2008

ENHANCEMENTS IN THIS ASAP UPDATE INCLUDE:

Product: AppDetectivePro


IBM DB2
  • NEW! DB2 DAS Memory Corruption Vulnerability
    Examines if the database is vulnerable to a critical vulnerability in the database manager service.
    Risk: High

  • NEW! Multiple DoS vulnerabilities in SQLJRA protocol
    Examines if the database is vulnerable to critical denial of service attacks.
    Risk: High

  • NEW! SRVCON_AUTH CLIENT authentication
    Examines if the authentication type in the SRVCON_AUTH parameter has been set to CLIENT.
    Risk: High

  • NEW! SRVCON_AUTH SERVER authentication
    Examines if the authentication type in the SRVCON_AUTH parameter has been set to SERVER.
    Risk: High

  • NEW! GSSPLUGIN authentication
    Examines if the authentication type has been set to GSSPLUGIN.
    Risk: Medium

  • NEW! SYSMAINT_GROUP configuration option
    Examines the value for the parameter SYSMAINT_GROUP set in the database manager configuration file.
    Risk Level: Informational

  • NEW! SYSMON_GROUP configuration option
    Examines the value for the parameter SYSMON_GROUP set in the database manager configuration file.
    Risk Level: Informational

  • NEW! SYSCTRL_GROUP configuration option
    Examines the value for the parameter SYSCTRL_GROUP set in the database manager configuration file.
    Risk Level: Informational

  • NEW! SYSADM_GROUP configuration option
    Examines the value for the parameter SYSADM_GROUP set in the database manager configuration file.
    Risk Level – Informational

MICROSOFT SQL SERVER

  • UPDATED! Latest service pack/hot fix not applied.
    Examines for the re-release of SP2 for SQL Server 2005 being applied
    Risk Level: High

ORACLE

  • UPDATED! Latest patchset not installed
    Examines for latest patchset 10.2.0.4 installed
    Risk Level – High

DISCOVERY

  • Performance enhancements on port scanning in discovery

COMPLIANCE

  • Added mapping of NIST 800-53 controls to checks