Apr 13, 2022
This release includes new Microsoft Patch Tuesday content for April, a couple of improvements, and a few fixes.
New
- Microsoft Patch Tuesday coverage. This release includes updated scan coverage for April 2022. Check out our blog post for details.
- Coverage for SAP NetWeaver Application Server for Java. We added coverage for SAP NetWeaver as Java for:
- CVE-2022-22532
- CVE-2022-22536
- CVE-2022-22533
- Vulnerability category. We added a new vulnerability category, CISA KEV, to cover vulnerabilities that appear in the CISA Known Exploited Vulnerabilities Catalog.
Improved
- CIS benchmark for Windows. We updated the Center for Internet Security (CIS) policy content that provides a CIS benchmark for MS Windows 2012 R2, version 2.5.0.
- Hostname consistency. Policy detail reports are now more consistent by displaying the longest hostname available in the report.
Fixed
- SSL Enumeration no longer results in socket leaks in certain cases.
- AdoptOpenJDK fingerprinting now includes additional file paths to reduce false negatives.
- Red Hat Enterprise Linux Virtualization package checks have been updated to resolve false positives.