Hi all, just installed a one machine Alteryx Server on Windows Server. So.... We then perform security scans with Qualys and the following vulnerability has come up, but I can find NO hardening guides from Alteryx, unlike Tableau whom have a good one....
What can I do to remove this vulnerability?
"CVE-2017-6168, CVE-2017-17382, CVE-2017-17427, CVE-2017-17428, CVE-2017-12373, CVE-2017-13098, CVE-2017-1000385, CVE-2017-13099, CVE-2016-6883, CVE-2012-5081
The TLS vulnerability is also known as Return of Bleichenbacher's Oracle Threat (ROBOT). ROBOT allows an attacker to obtain the RSA key necessary to decrypt TLS traffic under certain conditions.
An attacker could exploit this vulnerability by sending crafted TLS messages to the device, which would act as an oracle and allow the attacker to carry out a chosen-ciphertext attack.
For updates refer to the robot advisory ROBOT (https://robotattack.org/)
Patch:
Following are links for downloading patches to fix the vulnerabilities:
ROBOT (https://robotattack.org/)"