|
ASAP Update - 15 May 2008
ENHANCEMENTS IN THIS ASAP UPDATE INCLUDE:
Product: DbProtect Vulnerability Assessment Scan Engine (AppDetective)
IBM DB2
-
UPDATED! Latest FixPak not installed
Examines for latest Fixpak, FP1 for v9.5
Risk: High
SYBASE
-
NEW! Per login password expiration
Verifies that logins' passwords expiration are within the specified policy parameters
Risk Level: Medium
LOTUS NOTES/DOMINO
-
NEW! IBM Lotus Domino IMAP Cram-MD5 Buffer Overflow Vulnerability
Examines for this particular BoF vulnerability
Risk Level – High
-
NEW! Lotus Domino Web Server Unspecified Cross-Site Scripting Vulnerability
Examines for this particular XSS vulnerability
Risk Level – Medium
-
NEW! Lotus Domino IMAP Quota Manipulation Weakness
Examines for the IMPA quota manipulation weakness
Risk Level - Medium
-
NEW! Lotus Notes URL Handler Filtering Vulnerability
Examines for a URL handler filtering vulnerability
Risk Level - Medium
COMPLIANCE
- Added mapping of DISA-STIG ID's for Oracle and Microsoft SQL Server checks
|