Hello Team,
we have a Sophos Q9 fwall.
Some days ago we were scaned due to PCI audit.
The result of this scan is that scanner found the next issue:
The service detected a database installation on the target. Databases like Oracle, MS-SQL, MySQL, IBM DB2, PostGgresql, Firebird and other are detected. The database instance is listed in the result section below.
Information disclosing database type will lead attacker to perform more targeted attacks.
Users are recommended to encrypt the database information and handle the situations where any error is leading to disclose some sensitive information like database type and its version.
PostgreSQL server instance detectedPOSTGRESQL instance detected on TCP port 5432.
We cheched Sophos instance and found active PostreSQL service on that Instance.
Can you please provide any information how we can close this item/vulnarebility?
Thank you.
This thread was automatically locked due to age.