Commander 9.6.2 upgrades the included Apache Tomcat webserver to version 9.0.84. The HTTP Response code was changed as a response to a Blind SQL Injection test. Some security scanning tools may identify this as a vulnerability, as described in Nessus/42424.
Note that it has been investigated and tested, and does not pose a security risk, as SQL scripts cannot be injected and executed.
The response code may be updated in Commander 9.7.x but for now please consider these reports to be false positives.
Related Articles
Generating SQL Query results and pasting them into Microsoft Excel 24Number of Views Integrate Flexera One ITAM data with ReportsExecute REST API 22Number of Views MachineName Parameter can be used to Exploit a SQL Injection Vulnerability in App Broker 7Number of Views Is FlexNet Operations vulnerable to CVE?2014-6321? 3Number of Views Find your SVM Inventory Import scan results at the SCCM Console 5Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago