Remix.run Logo
romaniitedomum 2 days ago

Especially in environments where manglement mandate something like Qualys, leading to demands that systems must be patched to address the critical vulnerabilities that it's reported despite said vulnerabilities being unexploitable.

One that I trot out periodically as an example of this is a CVE that would only be exploitable if running on an IBM s390 with EBCDIC codepages. Our security team nevertheless wanted it patched, because Qualys said it was a vulnerability.

marysol5 2 days ago | parent [-]

Had that in /old job/ years ago, every security report would list off a load of packages that needed updating. Problem was, not only were they not actual vulnerabilities but they were all for some legacy software that was in the process of being removed.

Was always fun to purge a load of systems from old shit, and watch the counter drop.