08-21-2012 11:42 AM
Can anyone point me to a CVE database for Netbackup and it's associated processes (OpsCenter specifically)?
We have two different vulnerabilities to check
CVE-2012-0022 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0022
CVE-2011-4858 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4858
Searches on the Symantec website returned null as does google
09-05-2012 10:51 AM
The version of tomcat bundled with OpsCenterAnalytics is 6.0.29, but that does not neccessarily mean that all the features of 6.0.29 are included.
No answers from Symantec or the community :(
09-12-2012 11:42 AM
Hi Chris,
Sorry! I haven't been by this forum lately.
OpsCenter 7.5.0.1 includes tomcat 6.0.35 so neither of these vulnerabilities should affect you if you are running 7.5.0.1 or 7.5.0.3.
Refer to page 58 (Etrack 2711164).
tomcat 6.0.35 is also included in OpsCenter 7.1.0.4:
Refer to page 64 (Etrack 2671949).
We take security concerns very seriously - we ARE a security company, after all! If you are ever worried about a particular vulnerability, please open a support case and you should get the information you need right away.
10-29-2012 06:36 AM
We've updated to OpsCenter 7.5.0.3 Therefore we are covered.
Thanks for your attention.