We're running SOI 4.2 with SO07205-WIN-SOI-4.2-JAN-2019-MONTHLY UPDATE KIT installed
Our security department informed us that some vulnerabilities have been found on two types of SOI connectors; Specifically the UIM CatalystContainer connector and the SNMP CatalystContainer connector.
Port 8101 TCP is involved; referring to SSH
The online publication about it is shown below:
Avoid using deprecated cryptographic settings.
Use best practices when configuring SSH.
Refer to
"https://csrc.nist.gov/publications/detail/nistir/7966/final"
Security of Interactive and Automated Access Management Using Secure Shell (SSH) .
Settings currently considered deprecated:
At the moment we do not know which of the above applies to the two mentioned SOI connectors.
Several files were found referring to port 8101. Like:
CA\Catalyst\CatalystConnector\registry\topology\physical\example_CatalystConnector\catalyst-features.xml
CA\Catalyst\CatalystConnector\container\system\org\apache\karaf\assemblies\features\standard\2.2.5\standard-2.2.5-features.xml
CA\Catalyst\CatalystConnector\container\registry-cache\__topology__physical__example_CatalystConnector__catalyst-features.xml
CA\Catalyst\CatalystConnector\container\etc\org.apache.karaf.shell.cfg
CA\Catalyst\CatalystConnector\container\data\cache\org.eclipse.osgi\bundles\5\data\config\org\apache\karaf\shell.config
CA\Catalyst\CatalystConnector\connector_registry\topology\physical\example_CatalystConnector\catalyst-features.xml
Please have a look at let us know what configuration changes we can make to get rid of this vulnerability.
Service Operations Insight (SOI) Manager: 4.2
Catalyst Container 3.x