Comprehensive data protection for all workloads
Post Reply
duleepa
Influencer
Posts: 16
Liked: 1 time
Joined: Dec 31, 2018 6:44 am
Full Name: Harshana Fernando
Contact:

RE : Veeam Backup & Replication

Post by duleepa »

Hi

We have run Vulnerbility Assesment in one our customer's Veeam B&R server, after ran VA we found one issue on it. following the issue description which is show in the report. Recommendation said update TYPO3 or delete the "charts.swf" file so I want to clarify if I delete this file is it affected to Veeam portal ?. So appreciate if someone can advice on this.

Issue
-------


ExtJS charts.swf cross site scripting

Description
The ExtJS JavaScript framework that is shipped with TYPO3 also delivers a flash file to show charts. This file is susceptible to
cross site scripting (XSS). This vulnerability can be exploited without any authentication.

Impact
Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to
gather data from them. An attacker can steal the session cookie and take over the account, impersonating the user. It is also
possible to modify the content of the page presented to the user.

Recommendation
Update to TYPO3 versions 4.5.34, 4.7.19, 6.0.14, 6.1.9 or 6.2.3 that fix the problem described or delete the file
typo3/contrib/extjs/resources/charts.swf as it is not used by TYPO3 at all.

Thanks

Harshana
Mike Resseler
Product Manager
Posts: 8191
Liked: 1322 times
Joined: Feb 08, 2013 3:08 pm
Full Name: Mike Resseler
Location: Belgium
Contact:

Re: RE : Veeam Backup & Replication

Post by Mike Resseler »

Hi Harshana,

What portal are you talking about? Enterprise Manager or Veeam Availability Console? Also, what version and product of Veeam did you test?

Many thanks for letting us know. We will look into this asap

Thanks
Mike
duleepa
Influencer
Posts: 16
Liked: 1 time
Joined: Dec 31, 2018 6:44 am
Full Name: Harshana Fernando
Contact:

Re: RE : Veeam Backup & Replication

Post by duleepa »

Hi Mike

Thanks a lot for quick response, We have test "Enterprise Manager" & Veeam Backup & Replication v9.5.

Thanks

Harshana
Mike Resseler
Product Manager
Posts: 8191
Liked: 1322 times
Joined: Feb 08, 2013 3:08 pm
Full Name: Mike Resseler
Location: Belgium
Contact:

Re: RE : Veeam Backup & Replication

Post by Mike Resseler »

Hi Harshana,
I will pass this information to our security team for investigation. To be honest, I doubt you can delete that charts.swf file. If it is included, it probably is needed otherwise the charts will fail. But as said, I will pass this information to the correct teams and they will troubleshoot. We take security seriously so give us some time to go through this information.

PS: Is this v9.5 update 3?
duleepa
Influencer
Posts: 16
Liked: 1 time
Joined: Dec 31, 2018 6:44 am
Full Name: Harshana Fernando
Contact:

Re: RE : Veeam Backup & Replication

Post by duleepa »

Yes, We installed v9.5 update 3.

Thanks
Mike Resseler
Product Manager
Posts: 8191
Liked: 1322 times
Joined: Feb 08, 2013 3:08 pm
Full Name: Mike Resseler
Location: Belgium
Contact:

Re: RE : Veeam Backup & Replication

Post by Mike Resseler »

OK. I will sent the information through and update as soon as we know more.
Again, thanks for letting us know.
duleepa
Influencer
Posts: 16
Liked: 1 time
Joined: Dec 31, 2018 6:44 am
Full Name: Harshana Fernando
Contact:

Re: RE : Veeam Backup & Replication

Post by duleepa »

Okay, Thanks
Mike Resseler
Product Manager
Posts: 8191
Liked: 1322 times
Joined: Feb 08, 2013 3:08 pm
Full Name: Mike Resseler
Location: Belgium
Contact:

Re: RE : Veeam Backup & Replication

Post by Mike Resseler »

Hi Harshana,

Our software engineers just informed me that the file is not in use by Enterprise Manager so it can be safely deleted

Brgds,
Mike
duleepa
Influencer
Posts: 16
Liked: 1 time
Joined: Dec 31, 2018 6:44 am
Full Name: Harshana Fernando
Contact:

Re: RE : Veeam Backup & Replication

Post by duleepa »

Hi Mike

Thanks for your prompt reply & Thank you very much for your support....

Thanks

Harshana
Post Reply

Who is online

Users browsing this forum: Bing [Bot] and 123 guests