|
|
|
|
|
by romaniitedomum
10 days ago
|
|
Especially in environments where manglement mandate something like Qualys, leading to demands that systems must be patched to address the critical vulnerabilities that it's reported despite said vulnerabilities being unexploitable. One that I trot out periodically as an example of this is a CVE that would only be exploitable if running on an IBM s390 with EBCDIC codepages. Our security team nevertheless wanted it patched, because Qualys said it was a vulnerability. |
|
Was always fun to purge a load of systems from old shit, and watch the counter drop.