Jul 08, 2021
05:45 AM
Hi,
Would you mind checking if the following path is not a part of your scan path block list rule? If the rule is added to the blocklist, the SVM agent will not scan and report the installed software.
Please note: You need to check from the SVM account used for SVM agent deployment.
-Raheel
... View more
Jul 07, 2021
07:48 AM
Problem
Customer migrated all users from username/password to Azure SSO with conditional access, and they planned to change on tenant level "Disable standard login (Ensure SSO is working first, to prevent a lockout.)."
The problem is after changing all users, the API scripts fail now as the login does not work anymore, and we see in the logs a failing on login my manual login as obviously the account is SSO configured for our security baselines. Customers need to be able to lock down SSO on tenant level and all account levels for security baseline requirements and still support API functionality we use to generate PowerBI dashboards etc.
Solution
This API access is the reason we have the ability to mark accounts as not SSO enabled.
So even though their setting will be to disable SSO for users. They can individually keep some account SSO disabled so it can be used via patch daemon etc. When clients enable these settings , In such a situation, a login page will not allow standard login, but it can be accessed via API.
Expectation is all logins can only be via SSO, and our login screens behave that way by disabling standard login.
Please Note: A root can disable its or other users' SSO requirement individually in user management.
So, although such a user can still use standard login, but the same user could be used by patch daemon or API to bypass SSO. When the “Disable standard login” option is selected. The disable SSO option is for all users except Root admin and Partition Admin. User Management can do “Use SSO for authentication” which will disable standard login for user and login authentication type available in User Management tab, and they can switch all accounts to SSO.
... View more
Jun 28, 2021
03:22 AM
Hi,
We call SVR as per year release, for example, SVR 2021. But we do maintain the current and old release notes in the below link.
https://docs.flexera.com/?product=Software%20Vulnerability%20Research&version=Current
-Raheel
... View more
May 31, 2021
04:28 AM
1 Kudo
Hello,
If you are using the SVM on-premise version and you can get the installed and missing KB's from the following table csi_scan_kb,If you are using the SVM cloud version, get installed. Missing kb's from SVM > Reporting > Database Access > Database console > csi_scan_kb > right click and show data > you can then export the data in CSV.
Regards,
Raheel
... View more
May 17, 2021
02:29 AM
Hi,
Please try to use event viewer in windows to see what happened when it is reverted. Please look at the below article, which might help you how you can use event viewer.
https://www.dummies.com/computers/operating-systems/windows-10/how-to-use-event-viewer-in-windows-10/
Regards,
Raheel
... View more
Apr 23, 2021
09:36 AM
Summary
This article will help our SVM customers with how they integrate the Azure SSO with SVM.
Steps
Create a sample SVM user with specific SVM modules, which you want to use to copy permissions for Azure AD users to create in SVM
Enable SVM SSO from SVM > Configuration > Service Provider Configuration
Check the Automatically create new user check box and select the SVM user to copy for permissions.
Create an SSO(SAML) application in Azure Portal
Edit the Basic SAML Configuration
Copy the Metadata URL and SAML URL from the SVM SSO configuration and paste them into the Identifier (Entity ID), Reply URL (Assertion Consumer Service URL).
Edit the User Attributes & Claims and add the attributes as mentioned below and use the account key from the SVM SSO configuration section
Add and assign users or groups from the Users and Groups in the Azure SSO configuration section.
Copy the App Federation Metadata URL from Azure and paste it into Provide IdP Metadata URL section of SVM SSO configuration.
Try to login in from the Azure user account to test if you are successfully logging into the SVM.
... View more
Apr 22, 2021
02:34 AM
Hello,
We have checked VERITAS NetBackup 9.x in our product database, and this product version was added on February 7, 2021. If you have any vulnerability information after this date, we advise you to share any vendor advisory URL or detail with us. We will check with Secunia Research and will get back to you.
Please note: We only issue an advisory if the product version is added to our product database.
Regards,
Raheel
... View more
Apr 21, 2021
09:41 AM
It seems like we have a limit on how many CSV file data rows you can upload at the watchlist creation page. Please split the CSV file into multiple files and then test again to add the CSV file for watchlist creation.
-Raheel
... View more
Apr 20, 2021
02:59 AM
Hi,
Can you please elaborate a little bit more about what exactly you are trying to achieve? Do you mean you have a list of Softwares and you are trying to add to the watchlist, or you are trying to submit a software suggestion?
Regards,
Raheel
... View more
Apr 20, 2021
02:57 AM
1 Kudo
Hamish,
If the product name has been changed from SP2 and SP3 to 'SUSE Linux Enterprise Module for Basesystem 15-SP2' and 'SUSE Linux Enterprise Module for Development Tools 15-SP2'), then you need to suggest the new software along with vendor URL etc. via your software suggestion page. Please add more detail while suggesting how the product has been changed. We have noticed the 15-SP3 product is not available in our DB at all.
We don't have a policy of changing all the old advisory retroactivity for a specific product. If the product naming has been changed recently, then we will cover the new advisories accordingly.
Regards,
Raheel
... View more
Apr 07, 2021
06:52 AM
Please contact the person who owns the root admin account of SVR. He will assign the ticket manager role to your account and then you will be able to create a ticket for any advisory.
-Raheel
... View more
Apr 06, 2021
05:15 AM
Hello,
Do you mean you are not getting the below option to create a ticket for the advisory? If yes, then you need to check your account permission for proper entitled roles to perform this action. For example, if you have a ticket manager role assigned then you should be able to create a ticket.
-Raheel
... View more
Apr 06, 2021
03:16 AM
Hello Aftab,
Unfortunately, this is not possible to run the SVM agent scan on the endpoint from the SVM on-premise server CLI interface.
Regards,
RAheel
... View more
Mar 23, 2021
03:33 AM
1 Kudo
Hello Sabu,
It seems like your SVM on-premise database service is down. Please login to your SVM on-premise via putty and run the below command.
service mariadb start
Make sure the service is running fine
service MariaDB status
Please also make sure you don't have a space issue at the server df -h. If there is not enough space available at the server, the SVM on-premise will not work as expected.
Regards,
Raheel
... View more
Mar 17, 2021
08:02 AM
1 Kudo
Hamish,
We have created the following support ticket 02404201 for you to track this properly. We will update you via ticket ASAP.
cheers
Raheel
... View more
Latest posts by raslam
Subject | Views | Posted |
---|---|---|
53 | Feb 07, 2023 03:57 AM | |
291 | Jan 05, 2023 03:00 AM | |
292 | Dec 05, 2022 03:05 AM | |
273 | Dec 02, 2022 04:15 AM | |
398 | Nov 02, 2022 05:02 AM | |
351 | Oct 04, 2022 03:52 AM | |
341 | Sep 21, 2022 06:32 AM | |
331 | Sep 20, 2022 08:56 AM | |
517 | Jul 06, 2022 03:10 AM | |
612 | Jun 10, 2022 04:20 AM |
Activity Feed
- Posted Monthly Vulnerability Insights: Janurary 2023 on Software Vulnerability Management Blog. Feb 07, 2023 03:57 AM
- Tagged Monthly Vulnerability Insights: Janurary 2023 on Software Vulnerability Management Blog. Feb 07, 2023 03:57 AM
- Got a Kudo for Monthly Vulnerability Insights: December 2022. Jan 05, 2023 08:37 AM
- Got a Kudo for Monthly Vulnerability Insights: December 2022. Jan 05, 2023 05:16 AM
- Got a Kudo for Monthly Vulnerability Insights: December 2022. Jan 05, 2023 03:14 AM
- Got a Kudo for Monthly Vulnerability Insights: December 2022. Jan 05, 2023 03:08 AM
- Posted Monthly Vulnerability Insights: December 2022 on Software Vulnerability Management Blog. Jan 05, 2023 03:00 AM
- Tagged Monthly Vulnerability Insights: December 2022 on Software Vulnerability Management Blog. Jan 05, 2023 03:00 AM
- Posted Monthly Vulnerability Insights: November 2022 on Software Vulnerability Management Blog. Dec 05, 2022 03:05 AM
- Tagged Monthly Vulnerability Insights: November 2022 on Software Vulnerability Management Blog. Dec 05, 2022 03:05 AM
- Got a Kudo for Re: Flexera user issue. Dec 02, 2022 11:11 AM
- Posted Re: Flexera user issue on Software Vulnerability Management Forum. Dec 02, 2022 04:15 AM
- Got a Kudo for Monthly Vulnerability Insights: October 2022. Nov 03, 2022 05:21 AM
- Kudoed Re: Monthly Vulnerability Insights: October 2022 for ALK_AGUES. Nov 02, 2022 10:39 AM
- Got a Kudo for Monthly Vulnerability Insights: October 2022. Nov 02, 2022 05:38 AM
- Posted Monthly Vulnerability Insights: October 2022 on Software Vulnerability Management Blog. Nov 02, 2022 05:02 AM
- Tagged Monthly Vulnerability Insights: October 2022 on Software Vulnerability Management Blog. Nov 02, 2022 05:02 AM
- Posted Monthly Vulnerability Insights: September 2022 on Software Vulnerability Management Blog. Oct 04, 2022 03:52 AM
- Tagged Monthly Vulnerability Insights: September 2022 on Software Vulnerability Management Blog. Oct 04, 2022 03:52 AM
- Kudoed SVM Inventory-Based Vulnerability Assessment for kmantagi. Sep 21, 2022 07:21 AM