Vulnerability Scanning Overview (2024)

Oracle Cloud Infrastructure Vulnerability Scanning Servicehelps improve your security posture by routinely checking hosts and container images for potential vulnerabilities. The service gives developers, operations, and security administrators comprehensive visibility into misconfigured or vulnerable resources, and generates reports with metrics and details about these vulnerabilities including remediation information.

Tip

Watch a video introduction to the service.

All Vulnerability Scanning resources and reports are regional, but scan results are also visible as problems in your Cloud Guard global reporting region.

The Vulnerability Scanning service identifies vulnerabilities in the following resources:

  • Computeinstances (also known as hosts)
  • Container Registry images

The Vulnerability Scanning service can identify several types of security issues:

  • Ports that are unintentionally left open might be a potential attack vector to your cloud resources, or enable hackers to exploit other vulnerabilities.
  • OS packages that require updates and patches to address vulnerabilities.
  • OS configurations that hackers might exploit.
  • Industry-standard benchmarks published by the Center for Internet Security (CIS).

    The Vulnerability Scanning service checks hosts for compliance with the section 5 (Access, Authentication, and Authorization) benchmarks defined for Distribution Independent Linux.

  • Vulnerabilities in third-party applications such as log4j and spring4shell.

Note

Oracle Cloud Infrastructure Vulnerability Scanning Service can help you quickly correct vulnerabilities and exposures, but the service isn’t a Payment Card Industry (PCI) compliant scanner. Don’t use the Vulnerability Scanning service to meet PCI compliance requirements.

The Vulnerability Scanning service only supports Compute instances, or container images, created from supported platform images. Scanning isn’t available for any image with the label end of support.

To scan Compute instances for vulnerabilities, the instance must use an image that supports Oracle Cloud Agent. Port scanning on an instance's public IP address doesn’t require an agent.

Note

Vulnerability Scanning host and container image scans might pick up CVE results from other unsupported operating systems. The results are only covered by NVD data, and can be missing CVEs, or have other false positives. We don't support these other operating systems so use these results with caution.

The Vulnerability Scanning service detects vulnerabilities in the following platforms and using the following vulnerability sources.

PlatformNational Vulnerability Database (NVD)Open Vulnerability and Assessment Language (OVAL)Center for Internet Security (CIS)
Oracle LinuxYesYesYes
CentOSYesYesYes
UbuntuYesYesYes
WindowsYesNoNo

Note

Because Windows scanning doesn’t include OVAL data, we don't recommend you rely solely on Oracle Cloud Infrastructure Vulnerability Scanning Service to ensure that your Windows instances are up-to-date and secure.

Note

We don't recommend using the Vulnerability Scanning service to identify issues in Virtual Machine DB Systems, and then modifying the OS to address each issue. Instead, follow the instructions at Updating a DB System to apply the latest security updates to the OS.

Note

You can't use the Vulnerability Scanning service on hosts that weren't created directly with the Compute service, such as Exadata Database Service on Dedicated Infrastructure or the Database service. Use the features provided with those services to ensure that hosts have the latest security updates.

The Vulnerability Scanning service supports the following target options:

  • Individual Compute instances
  • All Compute instances within a compartment and its subcompartments.

    If you configure the Vulnerability Scanning service at the root compartment, then all Compute instances in the entire tenancy are scanned.

  • Images within a Container Registry repository
Vulnerability Scanning Overview (2024)
Top Articles
Binance impersonators target forex scam victims - Which? News
19 Best Cryptocurrency Mining Platforms [High Performing Pool]
4-Hour Private ATV Riding Experience in Adirondacks 2024 on Cool Destinations
Best Team In 2K23 Myteam
Craigslist Campers Greenville Sc
Www.metaquest/Device Code
Southeast Iowa Buy Sell Trade
Arrests reported by Yuba County Sheriff
Directions To 401 East Chestnut Street Louisville Kentucky
ds. J.C. van Trigt - Lukas 23:42-43 - Preekaantekeningen
Shariraye Update
10 Best Places to Go and Things to Know for a Trip to the Hickory M...
Michaels W2 Online
Rhinotimes
Busted Barren County Ky
7543460065
Price Of Gas At Sam's
Www.publicsurplus.com Motor Pool
Baja Boats For Sale On Craigslist
Morse Road Bmv Hours
Tips and Walkthrough: Candy Crush Level 9795
Inbanithi Age
Delectable Birthday Dyes
Hesburgh Library Catalog
Poochies Liquor Store
Narragansett Bay Cruising - A Complete Guide: Explore Newport, Providence & More
Gridwords Factoring 1 Answers Pdf
Audi Q3 | 2023 - 2024 | De Waal Autogroep
Pitco Foods San Leandro
Metro 72 Hour Extension 2022
Devin Mansen Obituary
Aliciabibs
Craigslist Mount Pocono
Sephora Planet Hollywood
Has any non-Muslim here who read the Quran and unironically ENJOYED it?
How to Get a Better Signal on Your iPhone or Android Smartphone
Janaki Kalaganaledu Serial Today Episode Written Update
California Craigslist Cars For Sale By Owner
Avatar: The Way Of Water Showtimes Near Jasper 8 Theatres
Candise Yang Acupuncture
Tom Kha Gai Soup Near Me
Craigslist Houses For Rent Little River Sc
Huntsville Body Rubs
The Sports Academy - 101 Glenwest Drive, Glen Carbon, Illinois 62034 - Guide
2294141287
Value Village Silver Spring Photos
Maurices Thanks Crossword Clue
Convert Celsius to Kelvin
Unbiased Thrive Cat Food Review In 2024 - Cats.com
Inloggen bij AH Sam - E-Overheid
Olay Holiday Gift Rebate.com
Latest Posts
Article information

Author: Dr. Pierre Goyette

Last Updated:

Views: 5904

Rating: 5 / 5 (50 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Dr. Pierre Goyette

Birthday: 1998-01-29

Address: Apt. 611 3357 Yong Plain, West Audra, IL 70053

Phone: +5819954278378

Job: Construction Director

Hobby: Embroidery, Creative writing, Shopping, Driving, Stand-up comedy, Coffee roasting, Scrapbooking

Introduction: My name is Dr. Pierre Goyette, I am a enchanting, powerful, jolly, rich, graceful, colorful, zany person who loves writing and wants to share my knowledge and understanding with you.