Summary
Nessus vulnerability scans indicate issues with ClickJackingSymptoms
Nessus vulnerability scans indicate FNM application potentially vulnerable to ClickjackingThe following pages do not use a clickjacking mitigation response header and contain a clickable event : - http://server:8888/flexnet/forgotPassword.do - http://server:8888/flexnet/logon.do
Port: www (8888/tcp)
Vulnerability Description:
The remote web server does not set an X-Frame-Options response header or a Content-Security-Policy 'frame-ancestors' response header in all content responses. This could potentially expose the site to a clickjacking or UI redress attack, in which an attacker can trick a user into clicking an area of the vulnerable page that is different than what the user perceives the page to be. This can result in a user performing fraudulent or malicious transactions. X-Frame-Options has been proposed by Microsoft as a way to mitigate clickjacking attacks and is currently supported by all major browser vendors. Content-Security-Policy (CSP) has been proposed by the W3C Web Application Security Working Group, with increasing support among all major browser vendors, as a way to mitigate clickjacking and other attacks. The 'frame-ancestors' policy directive restricts which sources can embed the protected resource. Note that while the X-Frame-Options and Content-Security-Policy response headers are not the only mitigations for clickjacking, they are currently the most reliable methods that can be detected through automation. Therefore, this plugin may produce false positives if other mitigation strategies (e.g., frame-busting JavaScript) are deployed or if the page does not perform any security-sensitive transactions.
Resolution
Please upgrade to FNMEA 2018 R to resolve this issue.Related Articles
Cognos Analytics is potentially vulnerable to CVE-2021-44228 (Apache Log4j 2 "Log4Shell") 4Number of Views Known Issue: Cognos Analytics is potentially vulnerable to CVE-2021-44228 (Apache Log4j 2 "Log4Shell") (IOJ-2236946) 4Number of Views How to enable FlexNet Manager Suite diagnostic tracing 270Number of Views FlexNet Manager Suite log files and locations 182Number of Views Is FlexNet Operations vulnerable to CVE?2014-6321? 3Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago