galangtegar
7 years agoLevel 4
Vulnerable Enterprise Vault on IIS
Dear Guys
I have implement enterprise vault 12.2 in my customer and then when we want to go live, their security policy scan the ev server website with acunetix web scan, they found 3 issue, one issue is high and then two more is medium, we can't go live if the enterprise vault website has vulnerability, result of webscan is below
- Microsoft IIS tilde directory enumeration (this is high Risk)
- RC4 cipher suites detected (Medium Risk)
- The POODLE attack (SSLv3 supported) (medium risk)
so what i have to do to resolve this vulnerability ?
please help if you have experience about that, any help would be apreciated
Thanks