Some Nessus vulnerability scans may indicate that Commander is susceptible to generic SQL injection. This is triggered by a blind SQL injection test response code but does not represent an actual exploitable vulnerability.
Commander version 9.6.2 upgrades the included Apache Tomcat webserver to version 9.0.84. The change in HTTP response codes during scanning has caused certain tools, including Nessus, to detect a potential blind SQL injection issue.
After investigation and testing, it has been confirmed that this detection is a false positive. SQL scripts cannot be injected or executed in Commander, and the condition does not present a security risk.
The response code may be further optimized in Commander version 9.7.x to prevent incorrect vulnerability flags, but until then, reports identifying this as a CGI generic SQL injection should be disregarded as inaccurate.
Was this helpful?
Related Articles
MachineName Parameter can be used to Exploit a SQL Injection Vulnerability in App Broker 10Number of Views Best Practices for Handling False Positives During Audits 8Number of Views Nessus Reports Potential Vulnerability for lmadmin Web Server 6Number of Views What is a false positive? 8Number of Views Microsoft Defender Antivirus - False Positive Alerts in ReleasePackager.exe Utility 9Number of Views
Revenera Assistant
Online
Hi, I am Reva - Ask me anything.
Updates
No new updates
Chat
Home
Updates
/**/
Thanks for the feedback!
Your feedback has been saved.Rate this response:
1
2
3
4
5
Add Additional feedback ( Optional )
0/240
English
English
Language changed successfully
Something went wrong
Email sent successfully
Something went wrong
Case create successfully
Are you sure you want to cancel
the case creation?
Please select a product to submit the case.
Please select a product version to submit the case.
0/255
Upload Attachment
File Upload
Maximum file
size allowed is 3 MB.
File type
not supported.
Supported file types:
Documents (.txt, .doc, .docx, .pdf), Images (.jpg, .png), Comma Separated Files
(.csv) Speadsheets (.xlsx, .xls)
Are you sure you want to cancel the case creation?
Case closed successfully
File Upload
Maximum file size allowed is 3 MB.
File type not supported.
Supported file types:
Documents (.txt, .doc, .docx, .pdf), Images (.jpg, .png), Comma Separated Files
(.csv) Speadsheets (.xlsx, .xls)
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
File Upload
Maximum file
size allowed is 3 MB.
File type
not supported.
Supported file types:
Documents (.txt, .doc, .docx, .pdf), Images (.jpg, .png), Comma Separated Files
(.csv) Speadsheets (.xlsx, .xls)
Revenera Assistant
© 2026 Flexera Software. All Rights Reserved.
Case id: 00001065
Activity: Status change: 2 hours ago