<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IME includes old JRE and MySQL versions with known vulnerabilities? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ime-includes-old-jre-and-mysql-versions-with-known/m-p/1654024#M65685</link>
    <description>&lt;P&gt;Cisco IME experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I just installed IME, and noticed that it includes an old 2009-vintage MySQL version that has known security vulnerabilities.&amp;nbsp; It also uses a private JRE version that is fairly old (1.6u7, IIRC).&amp;nbsp; I would like to use IME, but I have to meet fairly stringent security requirements, and these vulnerable versions of bundled products are going to raise red flags.&amp;nbsp; Can I delete the private JRE directory and modify the .ini files to point to the 1.6u23 JRE installed on the system?&amp;nbsp; Can the MySQL version be upgraded to &amp;gt;= v5.1.52, or can you explain why it is not a threat to system security?&amp;nbsp; Granted, the system running IME is within a protected network, but we are trying to implement defense-in-depth principles, and attacks can sometimes come from insiders with a flash drive or CD.&amp;nbsp; Thanks for your answers in advance!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Martin&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:15:43 GMT</pubDate>
    <dc:creator>MARTIN GEIL</dc:creator>
    <dc:date>2019-03-10T12:15:43Z</dc:date>
    <item>
      <title>IME includes old JRE and MySQL versions with known vulnerabilities?</title>
      <link>https://community.cisco.com/t5/network-security/ime-includes-old-jre-and-mysql-versions-with-known/m-p/1654024#M65685</link>
      <description>&lt;P&gt;Cisco IME experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I just installed IME, and noticed that it includes an old 2009-vintage MySQL version that has known security vulnerabilities.&amp;nbsp; It also uses a private JRE version that is fairly old (1.6u7, IIRC).&amp;nbsp; I would like to use IME, but I have to meet fairly stringent security requirements, and these vulnerable versions of bundled products are going to raise red flags.&amp;nbsp; Can I delete the private JRE directory and modify the .ini files to point to the 1.6u23 JRE installed on the system?&amp;nbsp; Can the MySQL version be upgraded to &amp;gt;= v5.1.52, or can you explain why it is not a threat to system security?&amp;nbsp; Granted, the system running IME is within a protected network, but we are trying to implement defense-in-depth principles, and attacks can sometimes come from insiders with a flash drive or CD.&amp;nbsp; Thanks for your answers in advance!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Martin&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:15:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ime-includes-old-jre-and-mysql-versions-with-known/m-p/1654024#M65685</guid>
      <dc:creator>MARTIN GEIL</dc:creator>
      <dc:date>2019-03-10T12:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: IME includes old JRE and MySQL versions with known vulnerabi</title>
      <link>https://community.cisco.com/t5/network-security/ime-includes-old-jre-and-mysql-versions-with-known/m-p/1654025#M65688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Martin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Usually we don't support modifying the underlying subsystems, as they are not tested together and problems might happen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are already running on latest IME (7.0.3), please open a TAC Service request (you can do it from this thread). this way we can discuss with development about fixing this in IME to either upgrade the JRE/MYSQL or at least patch them to fix any known vulnerabilities there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Fadi.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Feb 2011 14:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ime-includes-old-jre-and-mysql-versions-with-known/m-p/1654025#M65688</guid>
      <dc:creator>fadlouni</dc:creator>
      <dc:date>2011-02-11T14:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: IME includes old JRE and MySQL versions with known vulnerabi</title>
      <link>https://community.cisco.com/t5/network-security/ime-includes-old-jre-and-mysql-versions-with-known/m-p/1654026#M65692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your response.&amp;nbsp; I created a TAC Service Request &lt;STRONG style="color: #00611c; font-size: 10pt; "&gt;616824527&lt;/STRONG&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Feb 2011 20:53:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ime-includes-old-jre-and-mysql-versions-with-known/m-p/1654026#M65692</guid>
      <dc:creator>MARTIN GEIL</dc:creator>
      <dc:date>2011-02-11T20:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: IME includes old JRE and MySQL versions with known vulnerabi</title>
      <link>https://community.cisco.com/t5/network-security/ime-includes-old-jre-and-mysql-versions-with-known/m-p/1654027#M65697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IME&amp;nbsp;7.1.1&amp;nbsp;is&amp;nbsp;going&amp;nbsp;to&amp;nbsp;include&amp;nbsp;JRE&amp;nbsp;1.6u23.&amp;nbsp;&amp;nbsp;We&amp;nbsp;do&amp;nbsp;not&amp;nbsp;support&amp;nbsp;any&amp;nbsp;modification&amp;nbsp;of&amp;nbsp;IME&amp;nbsp;like&amp;nbsp;replacing&amp;nbsp;the&amp;nbsp;JRE&amp;nbsp;as&amp;nbsp;you&amp;nbsp;have&amp;nbsp;suggested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We&amp;nbsp;have&amp;nbsp;entered&amp;nbsp;a&amp;nbsp;bug&amp;nbsp;to&amp;nbsp;make&amp;nbsp;sure&amp;nbsp;we&amp;nbsp;are&amp;nbsp;updating&amp;nbsp;the&amp;nbsp;database&amp;nbsp;on&amp;nbsp;a&amp;nbsp;schedule,&amp;nbsp;so&amp;nbsp;updates&amp;nbsp;like&amp;nbsp;these&amp;nbsp;can&amp;nbsp;be&amp;nbsp;made&amp;nbsp;periodically.&amp;nbsp;&amp;nbsp;The&amp;nbsp;bug&amp;nbsp;is&amp;nbsp;CSCtn26880.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We&amp;nbsp;think&amp;nbsp;that&amp;nbsp;the&amp;nbsp;current&amp;nbsp;version&amp;nbsp;of&amp;nbsp;MySQL&amp;nbsp;is&amp;nbsp;not&amp;nbsp;a&amp;nbsp;threat&amp;nbsp;to&amp;nbsp;system&amp;nbsp;security&amp;nbsp;for&amp;nbsp;several&amp;nbsp;reasons:&lt;/P&gt;&lt;P&gt;-&amp;nbsp;The&amp;nbsp;server&amp;nbsp;is&amp;nbsp;configured&amp;nbsp;to&amp;nbsp;accept&amp;nbsp;only&amp;nbsp;local&amp;nbsp;connections.&lt;/P&gt;&lt;P&gt;-&amp;nbsp;There&amp;nbsp;is&amp;nbsp;no&amp;nbsp;default&amp;nbsp;admin&amp;nbsp;login.&lt;/P&gt;&lt;P&gt;-&amp;nbsp;The&amp;nbsp;admin&amp;nbsp;password&amp;nbsp;is&amp;nbsp;unique&amp;nbsp;to&amp;nbsp;each&amp;nbsp;installation&amp;nbsp;and&amp;nbsp;is&amp;nbsp;not&amp;nbsp;available&amp;nbsp;to&amp;nbsp;the&amp;nbsp;user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However,&amp;nbsp;security&amp;nbsp;can&amp;nbsp;be&amp;nbsp;enhanced&amp;nbsp;by&amp;nbsp;installing&amp;nbsp;on&amp;nbsp;a&amp;nbsp;Win&amp;nbsp;7&amp;nbsp;box&amp;nbsp;since&amp;nbsp;only&amp;nbsp;admin&amp;nbsp;users&amp;nbsp;will&amp;nbsp;have&amp;nbsp;access&amp;nbsp;to&amp;nbsp;the&amp;nbsp;IME&amp;nbsp;files.&amp;nbsp;This&amp;nbsp;will&amp;nbsp;be&amp;nbsp;available&amp;nbsp;when&amp;nbsp;Windows&amp;nbsp;7&amp;nbsp;is&amp;nbsp;supported&amp;nbsp;in&amp;nbsp;IME&amp;nbsp;7.1(1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IME&amp;nbsp;7.1.1&amp;nbsp;is&amp;nbsp;due&amp;nbsp;out&amp;nbsp;this&amp;nbsp;month--maybe&amp;nbsp;even&amp;nbsp;this&amp;nbsp;week.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Feb 2011 19:31:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ime-includes-old-jre-and-mysql-versions-with-known/m-p/1654027#M65697</guid>
      <dc:creator>Ronald Anthony</dc:creator>
      <dc:date>2011-02-15T19:31:00Z</dc:date>
    </item>
  </channel>
</rss>

