Streamworks Job Scheduler Release 7 Authentication Weakness
Posted by deepcore on January 17, 2019 – 9:24 am
Streamworks Job Scheduler Release 7 has all agents using the same X.509 certificates and keys issued by the vendor for authentication. The processing server component does not check received messages properly for authenticity. Agents installed on servers do not check received messages properly for authenticity. Agents and processing servers are vulnerable to the TLS Heartbleed attack.
Post a reply
You must be logged in to post a comment.