Loading
Skip Feed
  1. Our security scanner (Prisma Compute) detected that the FNMS Docker Monitor component:
    C:\Program Files (x86)\ManageSoft\Container\fnms-docker-monitor.exe

    is built with Go crypto/tls version 1.25.3, which is vulnerable to CVE‑2025‑68121.

    Subject: Request updated FNMS Docker Monitor binary built with Go 1.25.7+ (CVE‑2025‑68121)

    Hello Team,

    Our security scanner (Prisma Compute) detected that the FNMS Docker Monitor component:

    C:\Program Files (x86)\ManageSoft\Container\fnms-docker-monitor.exe

    is built with Go

    crypto/tls

    version 1.25.3, which is vulnerable to CVE‑2025‑68121.

    According to the Go project, the vulnerability is fixed only in:

    • Go 1.24.13
    • Go 1.25.7
    • Go 1.26.0‑rc.3

    Can you please provide the latest FNMS Container Monitor / Inventory Agent installer or updated

    fnms-docker-monitor.exe

    built with Go 1.25.7 or later, so we can apply the remediation?

    Expand Post

  2. Update for Adobe Acrobat DC, version 25.001.20693 (Continuous) failing on all PC's with error Returning 1642

    We have downloaded the latest application for adobe acrobat DC (Not reader), and it is failing on all machines with exit code 1642 and error 0x80070643. Please let me know if there is any known issue or what is the solution for this?

    @fawad_laiq​ 


    1 of 2
    • Maheshar_Ali (Flexera Software)

      Hi @deepaknr6​ ,

       

      Thank you for posting this. The issue has been resolved and conveyed to you through the support case.

       

      I hope this helped.

       

      Thanks.

      Expand Post

  3. TIMNPAWC likes this.
    • james_ellis (Flexera)

      Hello,

       

      I see that there is a support case open on this subject. The Engineer will work with you on this through your case. We will update this topic once concluded.

       

      Kind regards,

       

      James

      Expand Post

  4. Hello,
    I have installed WhatsApp for Windows for Windows on my laptop from the Microsoft Store. However, I do not see this as an installed product in SVM.

    Hello,

    I have installed WhatsApp for Windows for Windows on my laptop from the Microsoft Store. However, I do not see this as an installed product in SVM. Could it be that SVM see it as a generic Microsoft Redistributed Package. Is there something specific I can search for to find it?

    Any advice much appreciated.

    Howard


  5. Newbie, exploring svm patch

    Hey guys, im new here.

    Im exploring SVM patch publisher and im just trying to create filezilla patch to test.

    I have created the patch but when i go to patch deployment status i see the message "started" as status but i no see any progress on that.

    There is a way to see in real time the progress of the patchment?

    Checking the logs svmpatch.log i see an response "500: Internal Server Error".

    Can anyone give me some light?

    Thanks in advance.

    Expand Post

  6. 1 of 9
    • james_ellis (Flexera)

      Hi @sbristow ,

      The log file would be very useful. Thank you.

      Can you please try to send it via the community via direct message, if this fails then please let me know and I will email you directly with my details.

      I think I have in the meantime been able to replicate this. I will closely with engineering on this.

      This is what I get when configuring the schedule:

      sccm_schedule_import_error.png

      Kind regards,

      James Ellis

      Expand Post

End of Feed
8 Chatter Feed Items
ALL CONVERSATIONS
UNSOLVED
Unanswered Questions
Skip Feed
  1. Our security scanner (Prisma Compute) detected that the FNMS Docker Monitor component:
    C:\Program Files (x86)\ManageSoft\Container\fnms-docker-monitor.exe

    is built with Go crypto/tls version 1.25.3, which is vulnerable to CVE‑2025‑68121.

    Subject: Request updated FNMS Docker Monitor binary built with Go 1.25.7+ (CVE‑2025‑68121)

    Hello Team,

    Our security scanner (Prisma Compute) detected that the FNMS Docker Monitor component:

    C:\Program Files (x86)\ManageSoft\Container\fnms-docker-monitor.exe

    is built with Go

    crypto/tls

    version 1.25.3, which is vulnerable to CVE‑2025‑68121.

    According to the Go project, the vulnerability is fixed only in:

    • Go 1.24.13
    • Go 1.25.7
    • Go 1.26.0‑rc.3

    Can you please provide the latest FNMS Container Monitor / Inventory Agent installer or updated

    fnms-docker-monitor.exe

    built with Go 1.25.7 or later, so we can apply the remediation?

    Expand Post

  2. Hello,
    I have installed WhatsApp for Windows for Windows on my laptop from the Microsoft Store. However, I do not see this as an installed product in SVM.

    Hello,

    I have installed WhatsApp for Windows for Windows on my laptop from the Microsoft Store. However, I do not see this as an installed product in SVM. Could it be that SVM see it as a generic Microsoft Redistributed Package. Is there something specific I can search for to find it?

    Any advice much appreciated.

    Howard


  3. SVM Assesment base and integration limit

    Hello Team

    I have some concern about the following point and I need an argent replay please:

    -Does SVM detect configuration vulnerabilities based on CIS benchmarks?!

    -Does SVM integrate with other asset management tools and CMDB?!

    -Does SVM can generate system logs to SIEM solution?!

    Please Advise.

    Thanks, Regards

    Expand Post

  4. Firefox ESR 115.3 64-bit SPS Package

    We created via SVM Patch Publisher using the Flexera Package System, a Firefox 115.3 ESR update to publish to our WSUS.  We configured the package to only install ESR and use the default applicability path for detection (no modification to versioning).  When deployed to our clients, some had their Firefox Current Release version replaced by the ESR version.  We didn't want that to happen, so we recreated the package and changed the version checks for applicability to minimum version 102.0.0.0 and secure version to 115.3.0.0.  After publishing it and deploying, clients running current release were still getting the ESR update.  I checked .sdp files in the folder SVMPatch Cache and it seems the versioning we specified for applicability is getting ignored.  Can we not use this package to only upgrade ESR clients?  Are changes to minimum and secure version supported via SVM Patch Publisher?


  5. Elevate Security and Connectivity: Exploring VPNs on Routers Forum

    Here, we delve into the transformative realm of integrating VPN on router , enhancing both your online security and connectivity. Join discussions that uncover the synergy between Software Vulnerability Management and router-based VPNs. Explore how the combination of robust VPN setups and proactive vulnerability management can fortify your network against potential threats. Engage with experts and enthusiasts to understand how this dynamic duo can elevate your digital experience, safeguarding your data while maintaining seamless connectivity. Discover the potential at the intersection of VPNs on routers and software vulnerability management for a safer, more secure online journey.


  6. 0_Bob K (Flexera Software) asked a question.

    SVM and Log4j

    Your attention is called to this blog post for how SVR and SVM can help you deal with Log4j .

    SVM focuses exclusively on assessing known vulnerable software versions. It uses file signatures to determine the presence of known vulnerable software versions and matches that with research and patches to help you identify and remediate such. So, if Log4j is installed on a system, we will detect it, but that is not typically how Log4j is distributed—rather it is included as a component of another third-party application. In such a case, it will be identified as vulnerable if/when the software including it is disclosed as vulnerable, we write an advisory, and create a file signature to detect it.

    That said, we are prioritizing a potential product enhancement that would allow SVM to provide an awareness report to identify specific components like Log4j embedded within your installed software. This would be a new use case for SVM as it would help provide awareness, but you would not be able to remediate it by patching as SVM is traditionally leveraged. This is due to the fact that the product bundling the component is what needs to be patched, so this would be a new reporting-focused use case versus a patch-focused one. Actually patching a vulnerable component will continue to require targeting the application that is shipping the component, versus the component itself.

    Expand Post

End of Feed
8 Chatter Feed Items
Loading
Software Vulnerability Manager