Security Finder

You can use the Security Finder to search for security issues and their impact on Riverbed products. This page is continuously updated, displaying the most current public security issues first. The search box can be used to look up records by specific CVE numbers or relevant search word, e.g. Apache, 8.5.0, Workaround. For additional search tips, refer to article S16165. Security issues listed here are categorized into three groups: fixed, workaround recommended and not applicable.

For general security topics, security best practices and other security related topics, try performing a general search.

BETA FEATURE: This feature is currently under development and is considered Beta Software. We are still enhancing the features and results so please exercise caution when interpreting and implementing the results. If you have any questions, please open a case with Riverbed Support. If you have feedback for this tool, please send it to supportfeedback@riverbed.com.

Riverbed Technology is committed to protecting customers against vulnerabilities in our supported products. Vulnerabilities are addressed in accordance to the software support policy. https://support.riverbed.com/content/support/about_support/end_of_life_policy.html

For search tips, read article S16165.

PreviousNext
TitleLast Modified
OpenSSL Security Advisory May 3, 2016 2017-03-14
CVE-2016-1979 and CVE-2016-1978 nss: Use-after-free during processing of DER-encoded keys and during SSL connections in low memory 2017-03-09
CVE-2014-9680: sudo may be vulnerable to attacks using the TZ environment variable. 2016-12-20
Login cookies are accessible via scripts, which can be exploited by XSS attacks targeting the user's session cookie 2016-12-08
Cross-Frame Scripting (XFS) vulnerabilities in path selection and QoS pages. 2016-12-08
Possible script execution in some of the error dialogs that appear in the Management Console. 2016-12-08
Monitor user on CMC can have inappropriate access to a Steelhead 2016-12-08
Vulnerabilities in Apache Tomcat 2016-12-08
Enhanced security for telemetry connections 2016-12-07
Cumulative Python 2.4 CVE patch 2016-12-07
Remote commands executed through SSH logins 2016-12-07
CWE-79: Cross Site Scripting (XSS) Vulnerability in management UI log display page 2016-12-07
CWE 400: A Fix was added to close an unbounded resource consumption vulnerability 2016-12-07
Improper information disclosed with certain verbose HTTP errors 2016-12-07
Issues with using a GET method instead of the POST method 2016-12-07
CVE-2010-0405: bzip2 BZ2_decompress crafted compressed file denial of service 2016-12-07
Security hole in the appliance auto-signon feature. 2016-12-07
CVE-2009-3555: SSL/TLS renegotiation handshakes man-in-the-middle attack (aka "Project Mogul" issue). 2016-12-07
CVE-2010-1321: krb5 invalid GSS-API Denial of Service 2016-12-07
Web Inactivity Timeout fixed for UI Services page 2016-12-07
A malicious authorized user can lock up the web UI of an appliance. 2016-12-07
CVE-2009-2698: UDP sendmsg MSG_MORE flag denial of service 2016-12-07
CVE-2009-3563: NTP ntp_request MODE_PRIVATE denial of service 2016-12-07
CVE-2010-2252: wget crafted filename 3xx redirect 2016-12-07
SSL private keys are logged at NOTICE level. 2016-12-07
CVE-2009-3555: SSL/TLS renegotiation handshakes man-in-the-middle attack (aka "Project Mogul" issue). 2016-12-07
Cumulative security update for base OS RPMs 2016-12-07
Stronger web cookie session keys 2016-12-07
Cross-site scripting vulnerability (XSS) on RSP Dataflow page and CRLF injection vulnerability on many pages 2016-12-07
CVE-2010-1205: libpng pngread buffer overflow. 2016-12-07
Cross-site scripting issue (XSS) in URLs containing /mgmt/xmldata 2016-12-07
A malicious authorized user can lock up the web UI of an appliance. 2016-12-07
Cross Frame Scripting (XFS) vulnerability in UI 2016-12-07
A potential XSS vulnerability in the Web UI 2016-12-07
CVE-2010-0734: libcurl callback data denial of service 2016-12-07
CVE-2009-1252: NTP crypto_recv buffer overflow when OpenSSL and autokey are enabled 2016-12-07
CVE-2010-0001: gzip unlzw array index error denial of service 2016-12-07
A malicious authorized user can lock up the web UI of an appliance. 2016-12-07
CVE-2010-0740, CVE-2010-0742: OpenSSL malformed TLS record DoS and CMS OriginatorInfo mishandling 2016-12-07
Monitor user might be able to execute disallowed commands. 2016-12-07
PreviousNext