CVE-2023-38545/6 security vulnerability.
In trying to assess implications of the CURL hack upon Data Insight I see the \DataInsight\perl\site\lib\HTTP\Any\Curl.pm perl module lists libcurl 7.21.6 or newer. While that is a very old version and specifically the CVEs call out Affected Versions Affected versions: libcurl 7.69.0 to and including 8.3.0 Not affected versions: libcurl < 7.69.0 and >= 8.4.0 (where a patch has been identified) we are left to wonder as to ramifications of system software changes upon the Application. Our organization will be patching for the various applications utilizing http calls over Socks5 (mentioned as a proxy in the script) and I will need to know a few facts to enter discussions with our security team. Is DI affected by the vulnerability? Will DI be aversely affected by patching to the latest library version? Has Veritas released any statement on the vulnerability and its products? Thank you PixSolved1.3KViews0likes2CommentsApache Tomcat JNDI features used in DI <Pri:1>
With the release of a POC for the Apache Log4j2 CV can we confirm Data Insight is or is not affected? NIST- https://nvd.nist.gov/vuln/detail/CVE-2021-44228 Mitre - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228,== What effect will setting 'MsgNoLookups' or disabling 'trustURLCodebase' have on DI's operations and logging? ref: https://www.oracle.com/java/technologies/javase/8u121-relnotes.html Thank you PixSolved2.3KViews0likes5CommentsOpenSSL vulnerability <Security>
Can we claim Data Insight is not affected by these known issues? CVE-2021-3449: Crash can be provoked when connecting to a vulnerable server. CVE-2021-3450: Vulnerable client can be tricked into accepting a bogus TLS certificate. What, if any, affect will these exploits have on DI? thank you PixSolved1.3KViews0likes2CommentsI do not see mention of the NFSv4 for Data Insight in the documentation or knowledgebase.
The documents released for the 6.1 version up to 6.1.6 of DI have no mention of 'NFSv4', 'NFS4' and in the SCL only NFS3 version seems supported. Are there plans to update to the latest version available in the coming 6.2 release? The known issues with the older version need be avoided. We would also like to utilize the enhancements of increased performance, File locking, the Delete bits, and benefits of security, mixed mode operations, while removing user group limitations. Thank you Pix1KViews0likes1CommentMeta Read events in Data Insight
Hello Data Insight Experts, I did some searches already, and while I have found good information, I have yet to see a detailed explanation of the different file interactions that will trigger each type of Meta Access event (Report > Access Detail > Meta Access:Read Write Create Delete Rename Security ) I'm writing because I'm having a bit of trouble understanding what file interactions trigger each of the differen types of Meta Access types. As an example, when I search for a file, (e.g., *.log using the windows explorer after navigating to a NetApp filer), all the files that show up in the search list are listed as a READ in the report I run. If I navigate to a folder and open it, a READ event is registered against every file in that folder. Another quirk is that when I run a search for all 'Meta Access: SECURITY' events, I get back a number of 'Meta Access: WRITE' events. Is there a place where each Meta Access type is discussed in detail? I've seen it described at a high level in a number of places, but need something more granular.1.1KViews0likes0Comments