Zum Inhalt springen

Tenable Release Notes

8 Einträge aus 2 Quellen. Zuletzt aktualisiert:

Folge Tenable, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nessus von Tenable

Tenable Nessus 10.12.5: Signaturpflicht für Plugin-Updates, Sicherheitsfixes

Tenable Nessus 10.12.5 verlangt für manuelle Plugin-Updates in Tenable Nessus und Tenable Nessus Manager nun die Signaturdatei und behebt mehrere Sicherheitslücken, darunter Speicherfehler im Plugin-Loader, fehlende Signaturprüfung beim Legacy-Update-Kanal und eine SQL-Injection beim Import von Scan-Policies.

ClosedChanged Functionality and Performance Enhancements

The following changes are included in Tenable Nessus 10.12.5:

  • Manual plugin updates for both Tenable Nessus and Tenable Nessus Manager now require the signature file to process plugin updates. This change does not impact Tenable Security Center plugin updates, Tenable Nessus Manager's agent plugin updates, or Tenable Nessus application updates.

ClosedSecurity Updates

The following are security updates included in Tenable Nessus 10.12.5:

  • Fixed multiple memory-safety flaws in the plugin file loader.

  • Fixed an out-of-bounds memory access in the plugin execution engine's logic.

  • Fixed a denial-of-service condition where a crafted plugin file could trigger a crash-restart loop.

  • Fixed an out-of-bounds read in the plugin file parser that could expose internal scanner memory in diagnostic output.

  • Fixed a double-free memory corruption that could be triggered by a crafted plugin.

  • Fixed a vulnerability where plugin archives pushed through the legacy update channel were installed without signature verification. Uploaded plugin archives are now required to carry a valid Tenable signature before they are extracted or loaded.

  • Fixed a SQL injection vulnerability in the scan policy import functionality. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Tenable Security Center von Tenable

Tenable Security Center 6.9.1: Fehlerbehebungen und PostgreSQL-Installer

Tenable Security Center 6.9.1 behebt mehrere Fehler (u. a. Upgrade-Abbruch auf 6.9.0 wegen defekter Trend-Diagramme, Scan-Ziele mit Bindestrichen fälschlich als IP-Bereiche, unvollständig gelöschte Scan-Ergebnisse, fehlschlagende Abfragen bei bestimmten HTTPS-Zertifikatskonfigurationen) und der PostgreSQL-Installer kommt nun mit nicht leeren public-Schemas mit Fremdtabellen zurecht.

Tenable Security Center 6.9.1 is now available, addressing several critical bug fixes and infrastructure improvements.

You can download the update files from the Tenable Security Center Downloads page.

ClosedChanged Functionality and Performance Enhancements

PostgreSQL Database Installer Enhancement

Tenable Security Center 6.9.1 updates the PostgreSQL database installer to handle non-empty public schemas that contain non-Tenable Security Center tables. This improvement ensures that installation succeeds in environments with existing PostgreSQL schemas, reducing deployment complexity in shared database environments.

ClosedBug Fixes

  • Fixed an upgrade failure where certain installations would abort during the migration to Tenable Security Center 6.9.0 due to broken trend charts.

  • Fixed an issue where some scan targets containing dashes could be incorrectly treated as IP ranges rather than domain names during scanning.

  • Fixed an issue where scan results were not completely deleted when they were removed from the application.

  • Fixed an issue where certain queries failed when specific HTTPS certificate configurations were in place.

ClosedFilenames and Checksums …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Tenable Security Center von Tenable

Tenable Security Center Patch 202608.1 behebt Lokalisierung und Schwachstellen

Der Patch 202608.1 für Tenable Security Center 6.6.0, 6.7.2 und 6.8.0 auf Oracle Linux 8 oder höher sowie Red Hat Enterprise Linux 8 oder höher behebt die fehlende lokalisierte Darstellung der Tenable One Web App Scanning Plugin-Ausgabe bei chinesischen Plugin-Sprachen (vereinfacht und traditionell) und schließt mehrere Anwendungsschwachstellen.

Apply this patch to Tenable Security Center installations running the following:

  • Tenable Security Center 6.6.0, 6.7.2, and 6.8.0 on Oracle Linux 8 or later.

  • Tenable Security Center 6.6.0, 6.7.2, and 6.8.0 on Red Hat Enterprise Linux 8 or later.

There is also a patch for Tenable Security Center 6.7.5 and 6.8.0 on Tenable Enclave Security. For those versions, see the Tenable Enclave Security Release Notes.

This patch fixes an issue where Tenable One Web App Scanning plugin output did not display localized text when the plugin locale was set to a Chinese character set (Simplified or Traditional).

Note: This patch also fixes several application vulnerabilities. For more information, see the Tenable Product Security Advisory.

Note: Tenable Security Center requires at least 8GB (8192MiB) of RAM on the host operating system to function.

ClosedSteps to Apply Patch

Apply the patch to a standalone Tenable Security Center or Tenable Core + Tenable Security Center:

  1. Download the patch from the Tenable Security Center Downloads page to Tenable Security Center. You can save the files in any location (for example, /tmp). …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nessus von Tenable

Tenable Nessus 10.12.4: Korrekturen bei Kerberos, Timeouts und PostgreSQL

Tenable Nessus 10.12.4 behebt Fehler, durch die Kerberos-Plugins keine Host-FQDNs abrufen konnten, Tenable Security Center bei vielen Agent-Berichten in Timeouts lief und bei PostgreSQL-Zertifikatsauthentifizierung nur das erste Zertifikat der Kette geladen wurde.

ClosedBug Fixes

Bug Fix

Defect ID

Fixed an issue that blocked Kerberos plugins from retrieving host FQDNs, causing plugin authentication failures.

02502988, 02506935

Fixed an issue that caused Tenable Security Center to suffer timeout-related errors while processing many Tenable Nessus Manager agent reports.

02492101

Fixed an issue where only the first (leaf) certificate was loaded when a plugin performed PostgreSQL client authentication using a certificate chain.

02502389

ClosedUpgrade Notes

  • Tenable One Vulnerability Management FedRAMP environments support Tenable Nessus scanners versions 10.5.0 and later.

  • If you are connecting to Tenable One Vulnerability Management through Tenable Nessus scanners, Tenable Agents, Tenable One Web App Scanning scanners, or Tenable Network Monitors (NNM) located in mainland China, you must connect through sensor.cloud.tenablecloud.cn instead of sensor.cloud.tenable.com.

  • You can upgrade to the latest version of Tenable Nessus from any previously supported version.

  • If your upgrade path skips versions of Tenable Nessus, Tenable recommends reviewing the release notes for all skipped versions to learn about new features and bug fixes. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Tenable Security Center von Tenable

Tenable Security Center 6.9.0

Tenable Security Center 6.9.0 steht zum Download bereit, enthält einen Fix für eine mögliche Schwachstelle und unterstützt direkte Upgrades ab Version 6.5.0 auf demselben Betriebssystem.

You can download the update files from the Tenable Security Center Downloads page.

Note: This release includes a fix for a potential vulnerability. For more information, see the Tenable Product Security Advisory.

ClosedUpgrade Notes

Note: Tenable Security Center requires at least 8GB (8192MiB) of RAM on the host operating system to function.

Compatibility and Requirements

  • Version Support: Tenable Security Center 6.9.0 supports direct upgrades from version 6.5.0 and later on the same operating system. If your upgrade skips versions (for example, 6.7.0 to 6.9.0), review the release notes for all skipped versions to identify necessary configuration updates.

  • Hardware: Tenable Security Center has updated hardware specifications as of version 6.7.0. While the upgrade does not block systems that fall below these specs, performance may degrade. Tenable Support may require hardware upgrades to resolve support cases.

    For more information, see Hardware Requirements in the Tenable Security Center User Guide. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nessus von Tenable

Tenable Nessus 10.12.3: SSL-Verbindung zu Tenable One nach Upgrade behoben

Tenable Nessus 10.12.3 behebt ein Problem, bei dem einige Scanner nach einem Upgrade keine SSL-Verbindung zu Tenable One Vulnerability Management aufbauen konnten und dadurch offline erschienen und keine Plugin-Updates erhielten.

ClosedBug Fixes

Bug Fix

Defect ID

Resolved an issue where some Tenable Nessus scanners could not establish SSL connections to Tenable One Vulnerability Management after an upgrade. This issue caused the scanners to appear offline and stopped plugin updates.

02526315, 02523672, 02525991, 02526826, 02525419, 02527133, 02524407

ClosedUpgrade Notes

  • Tenable One Vulnerability Management FedRAMP environments support Tenable Nessus scanners versions 10.5.0 and later.

  • If you are connecting to Tenable One Vulnerability Management through Tenable Nessus scanners, Tenable Agents, Tenable One Web App Scanning scanners, or Tenable Network Monitors (NNM) located in mainland China, you must connect through sensor.cloud.tenablecloud.cn instead of sensor.cloud.tenable.com.

  • You can upgrade to the latest version of Tenable Nessus from any previously supported version.

  • If your upgrade path skips versions of Tenable Nessus, Tenable recommends reviewing the release notes for all skipped versions to learn about new features and bug fixes.

  • If you want your scanners to update to the newest version before the GA date automatically, set your Tenable Nessus Update Plan to Opt in to Early Access releases. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nessus von Tenable

Tenable Nessus 10.12.2: Korrekturen bei Agents, Cluster-Scans und TLS 1.3

Tenable Nessus 10.12.2 behebt Fehler bei der angezeigten Plugin-Set-Version verknüpfter Agents (erfordert Tenable Agent 11.2.0 oder neuer), bei unvollständigen Cluster-Agent-Scans, beim sofortigen Auslösen von host_time_minutes sowie bei der Wirkung von ssl_cipher_list auf TLS-1.3-Cipher-Suites.

ClosedBug Fixes

Bug Fix

Defect ID

Fixed an issue that caused Tenable Nessus Manager to report the previously installed version of the plugin set on a linked agent.

This fix also requires Tenable Agent version 11.2.0 or later.

02317032, 02304552, 02503048, 02507161

Fixed an issue where cluster-based agent scans started but did not complete. For database records of these incomplete scans, the cleanup process now correctly considers their associated files as "in use" and preserves them.

02430539

Fixed an issue where the host_time_minutes parameter triggered immediately for a host, which caused the scan for that host to abort.

02441109

Fixed an issue where the ssl_cipher_list preference did not control the TLS 1.3 cipher suites.

02510984

ClosedUpgrade Notes

  • Tenable One Vulnerability Management FedRAMP environments support Tenable Nessus scanners versions 10.5.0 and later.

  • If you are connecting to Tenable One Vulnerability Management through Tenable Nessus scanners, Tenable Agents, Tenable One Web App Scanning scanners, or Tenable Network Monitors (NNM) located in mainland China, you must connect through sensor.cloud.tenablecloud.cn instead of sensor.cloud.tenable.com. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Tenable Security Center von Tenable

Tenable Security Center Patch 202607.1 aktualisiert Komponenten

Der Patch 202607.1 für Tenable Security Center 6.6.0, 6.7.x und 6.8.0 auf Oracle Linux 8 oder höher sowie Red Hat Enterprise Linux 8 oder höher aktualisiert Apache httpd auf 2.4.67, OpenSSL auf 3.5.4, PHP auf 8.2.31, PostgreSQL auf 16.14 und Redis auf 8.2.6 (nur 6.7.x und 6.8.0) und behebt mehrere Anwendungsschwachstellen.

Apply this patch to Tenable Security Center installations running the following:

  • Tenable Security Center 6.6.0, 6.7.x, and 6.8.0 on Oracle Linux 8 or later.

  • Tenable Security Center 6.6.0, 6.7.x, and 6.8.0 on Red Hat Enterprise Linux 8 or later.

This patch updates the following:

  • Apache httpd to version 2.4.67

  • OpenSSL to version 3.5.4

  • PHP to version 8.2.31

  • PostgreSQL to version 16.14

  • Redis to version 8.2.6 (Tenable Security Center 6.7.x and 6.8.0 only)

Note: This patch also fixes several application vulnerabilities. For more information, see the Tenable Product Security Advisory.

Note: Tenable Security Center requires at least 8GB of RAM on the host operating system to function.

ClosedSteps to Apply Patch

Apply the patch to a standalone Tenable Security Center or Tenable Core + Tenable Security Center:

  1. Download the patch from the Tenable Security Center Downloads page to Tenable Security Center. You can save the files in any location (for example, /tmp).

  2. Access the command line as a user with root-level permissions. …

Originalquelle(öffnet in neuem Tab)Problem melden