Security Research
Showing results for 
Search instead for 
Do you mean 

HPSR Software security content update - Heartbleed bug detection

on ‎04-11-2014 03:08 PM

HP Security Research is pleased to offer new security content to detect the Heartbleed bug with HP WebInspect. The download is available immediately via SmartUpdate and includes the following features:

  • A new check for detecting the TLS Heartbeat extension buffer over-read vulnerability known to manifest in OpenSSL versions 1.0.1 and 1.0.2-beta
  • A dedicated "OpenSSL Heartbleed" policy

To most effectively leverage this security content update, configure HP WebInspect to execute a scan against your application server(s) in Audit Only mode and select the “OpenSSL Heartbleed” policy.

 

We recommend that customers verify their OpenSSL deployments and ensure that all of the library installations have been upgraded to either 1.0.1g or 1.0.2-beta2 and above. To verify the version of your existing OpenSSL installation, run the command openssl version.

0 Kudos
About the Author

joe_sechman

Labels
Events
Aug 29 - Sep 1
Boston, MA
HPE Big Data Conference 2016
Attend HPE’s Big Data Conference on August 29 - September 1, 2016 to learn from peers in every industry and hear from Big Data experts and thought lea...
Read more
Sep 13-16
National Harbor, MD
HPE Protect 2016
Protect 2016 is our annual conference on September 13 - 16, 2016, and is the place to meet the world’s top information security talent, discuss new pr...
Read more
View all