OVAL vulnerability Criteria - All sorts of confusing... #260
Unanswered
wagner-robert
asked this question in
Q&A
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
All,
I am trying to use OpenSCAP for vulnerability analysis using OVAL files. One thing I have noticed is the vulnerability criteria is all sorts of confusing. Some examples:
Redhat 9: https://security.access.redhat.com/data/oval/v2/RHEL9/
This starts with an "OR" statement. It seems like you would want to say "If you have RHEL installed AND RHEL 9 installed AND you have any of the following conditions are TRUE - then you are vulnerable"
Oracle does this differently: https://linux.oracle.com/security/oval/
These seem overly complicated. Does something like this work:
If someone could write a PDF on how to create and debug the Criteria statements, it would be greatly appreciated.
Also, some of the tests are truly odd:
Why would they create a test that RHEL must be installed with a check="none satisfy"?????
Beta Was this translation helpful? Give feedback.
All reactions