Oracle Linux Virtualization Manager (OLVM) (MOSC)

MOSC Banner

OLVM 4.5 vulnerability

edited Jun 18, 2024 12:09PM in Oracle Linux Virtualization Manager (OLVM) (MOSC) 8 commentsAnswered ✓

after upgrading the OLVM cluster from version 4.4 to 4.5, a critical vulnerability was identified on the self-hosted engine ports as below and attached scan report.

Python Unsupported Version Detection on ports 6100, 9696 and 35357

also a medium vulnerability was identified on the self-hosted engine and KVM ports as the below and attached scan report

  1. Web Server Generic Cookie Injection on ports 54322 and 54323
  2. HSTS Missing From HTTPS Server (RFC 6797) on ports 54322, 54323, 443, 6100, 9696 and 35357
  3. SSL Self-Signed Certificate on ports 443, 54321, 54322, 54323, 6641 and 6642
  4. SSL Certificate Cannot Be Trusted on ports 443, 54321, 54322, 54323, 6641, 6642, 9696, 35357 and 16514

regarding the ssl certificate on ports should we dismiss it as a false positive or replace the internal certificate with on ssl certificate from CA authorities please advice on the process.

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center