Question & Answer
Can QRadar Vulnerability Manager detect systems vulnerable to CVE-2014-6172 (Shellshock Bash Vulnerability)?
Yes, the QRadar daily auto update has been released and includes signatures for detecting the Bash vulnerability for CVE-2014-6172 (Shellshock). The daily auto update for QRadar Vulnerability Manager has been added the vulnerability database, along with a series of detection tools (patch, authenticated check, unauthenticated check). Customers who want to retrieve the latest updates can force an automatic update from the QRadar Admin tab of QRadar.
Most administrators can use the Get New Updates button to retrieve the latest auto updates.
- Log in to the QRadar Console as an administrator.
- Click the Admin tab.
- Click the Auto Update icon.
- Click Get New Updates.
If the auto update system for your QRadar appliance has already run today, the administrator might want to force the system to check again for all available updates. To force an update, the administrator can run the following commands:
- Using SSH, log in to the Console as the root user.
- Navigate to the following directory: cd /opt/qradar/bin.
- Run each of the following commands to clear the auto update timestamps for each download category.
- ./UpdateConfs.pl -ds lastpatch 0
- ./UpdateConfs.pl -ds lastwau 0
- ./UpdateConfs.pl -ds lastdau 0
Where do you find more information?
Was this topic helpful?
21 June 2018