<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>http://ab.edge-technologies.com/docs/index.php?action=history&amp;feed=atom&amp;title=Enportal%2F5.6%2Ffaq%2Fsecurity</id>
	<title>Enportal/5.6/faq/security - Revision history</title>
	<link rel="self" type="application/atom+xml" href="http://ab.edge-technologies.com/docs/index.php?action=history&amp;feed=atom&amp;title=Enportal%2F5.6%2Ffaq%2Fsecurity"/>
	<link rel="alternate" type="text/html" href="http://ab.edge-technologies.com/docs/index.php?title=Enportal/5.6/faq/security&amp;action=history"/>
	<updated>2026-04-06T23:53:27Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.38.4</generator>
	<entry>
		<id>http://ab.edge-technologies.com/docs/index.php?title=Enportal/5.6/faq/security&amp;diff=8546&amp;oldid=prev</id>
		<title>imported&gt;Jason.nicholls: 1 revision</title>
		<link rel="alternate" type="text/html" href="http://ab.edge-technologies.com/docs/index.php?title=Enportal/5.6/faq/security&amp;diff=8546&amp;oldid=prev"/>
		<updated>2015-12-04T05:14:10Z</updated>

		<summary type="html">&lt;p&gt;1 revision&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 05:14, 4 December 2015&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-notice&quot; lang=&quot;en&quot;&gt;&lt;div class=&quot;mw-diff-empty&quot;&gt;(No difference)&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>imported&gt;Jason.nicholls</name></author>
	</entry>
	<entry>
		<id>http://ab.edge-technologies.com/docs/index.php?title=Enportal/5.6/faq/security&amp;diff=8545&amp;oldid=prev</id>
		<title>imported&gt;Doug yeager: /* Does enPortal provide protection against cross-site scripting attacks? */</title>
		<link rel="alternate" type="text/html" href="http://ab.edge-technologies.com/docs/index.php?title=Enportal/5.6/faq/security&amp;diff=8545&amp;oldid=prev"/>
		<updated>2015-11-24T17:58:14Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Does enPortal provide protection against cross-site scripting attacks?&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 17:58, 24 November 2015&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-notice&quot; lang=&quot;en&quot;&gt;&lt;div class=&quot;mw-diff-empty&quot;&gt;(No difference)&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>imported&gt;Doug yeager</name></author>
	</entry>
	<entry>
		<id>http://ab.edge-technologies.com/docs/index.php?title=Enportal/5.6/faq/security&amp;diff=8544&amp;oldid=prev</id>
		<title>imported&gt;Mike.berman: fix several grammatical errors and change to more formal tone</title>
		<link rel="alternate" type="text/html" href="http://ab.edge-technologies.com/docs/index.php?title=Enportal/5.6/faq/security&amp;diff=8544&amp;oldid=prev"/>
		<updated>2015-07-16T21:15:38Z</updated>

		<summary type="html">&lt;p&gt;fix several grammatical errors and change to more formal tone&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 21:15, 16 July 2015&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l70&quot;&gt;Line 70:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 70:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Does Adobe Flash Have Security Vulnerabilities? ===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Does Adobe Flash Have Security Vulnerabilities? ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;As you may have seen in the news &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;recently&lt;/del&gt;, there has been some discussion around security vulnerabilities in Adobe Flash Player, &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;and in particular &lt;/del&gt;about Mozilla disabling Flash Player in Firefox. &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;We would like to &lt;/del&gt;clarify the &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;following items about &lt;/del&gt;Adobe Flash:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;As you may have seen in the news, there has been some discussion around security vulnerabilities in Adobe Flash Player, &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;such as articles &lt;/ins&gt;about Mozilla disabling Flash Player in Firefox. &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;The following items should help &lt;/ins&gt;clarify the &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;status of security concerns with &lt;/ins&gt;Adobe Flash:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Mozilla did disable all older versions of Flash Player in Firefox, but Adobe has already released a fixed version that is not blocked.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Mozilla did disable all older versions of Flash Player in Firefox, but Adobe has already released a fixed version that is not blocked.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;We &lt;/del&gt;always recommend that &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;our customers &lt;/del&gt;upgrade to the very latest version of Flash Player. For AppBoard 2.5.2.2 &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;we &lt;/del&gt;require at least version 11.2, but &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;we support &lt;/del&gt;releases up to the current version &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;(18)&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;You should &lt;/ins&gt;always recommend that &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;your users &lt;/ins&gt;upgrade to the very latest version of Flash Player. For AppBoard 2.5.2.2 &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;you should &lt;/ins&gt;require at least version 11.2, but &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;the product supports &lt;/ins&gt;releases up to the current version.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Google Chrome includes &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;it&amp;#039;s &lt;/del&gt;own Flash Player (&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;i.e. &lt;/del&gt;it&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;#039;s &lt;/del&gt;not a separately installed plugin) and this is automatically updated with the browser, which they do any time there are serious security issues.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Google Chrome includes &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;its &lt;/ins&gt;own Flash Player (it &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;is &lt;/ins&gt;not a separately installed plugin) and this is automatically updated with the browser, which they do any time there are serious security issues.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Microsoft&amp;#039;s new Edge browser includes &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;it&amp;#039;s &lt;/del&gt;own Flash Player and automatically updates in the same manner as Chrome.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Microsoft&amp;#039;s new Edge browser includes &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;its &lt;/ins&gt;own Flash Player and automatically updates in the same manner as Chrome.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Customers on older Internet Explorer versions and Firefox need to install the up-to-date plugin or have the plugin auto-update.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Customers on older Internet Explorer versions and Firefox need to install the up-to-date plugin or have the plugin auto-update.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;In reality, security &lt;/del&gt;vulnerabilities are constantly being introduced in operating systems, browsers, libraries (like SSL), and plugins (like Flash). What is most important is that the responsible parties take it seriously and address the problems as quickly as possible&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;, and &lt;/del&gt;Adobe &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;have &lt;/del&gt;continued to &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;do that&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Security &lt;/ins&gt;vulnerabilities are constantly being introduced in operating systems, browsers, libraries (like SSL), and plugins (like Flash). What is most important is that the responsible parties take it seriously and address the problems as quickly as possible&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;. &lt;/ins&gt;Adobe &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;has &lt;/ins&gt;continued to &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;provide updates to address these issues, as confirmed by the continued support of the latest Flash plugin in the above noted browsers&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>imported&gt;Mike.berman</name></author>
	</entry>
	<entry>
		<id>http://ab.edge-technologies.com/docs/index.php?title=Enportal/5.6/faq/security&amp;diff=8543&amp;oldid=prev</id>
		<title>imported&gt;Cmace: added section about adobe flash vulnerability</title>
		<link rel="alternate" type="text/html" href="http://ab.edge-technologies.com/docs/index.php?title=Enportal/5.6/faq/security&amp;diff=8543&amp;oldid=prev"/>
		<updated>2015-07-16T20:37:10Z</updated>

		<summary type="html">&lt;p&gt;added section about adobe flash vulnerability&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 20:37, 16 July 2015&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l67&quot;&gt;Line 67:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 67:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;With SSLv3 enabled, you will get a telnet type cursor waiting for you to issue a HTTP request. If it is properly disabled, then you will get a handshake failure and returned to the command prompt.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;With SSLv3 enabled, you will get a telnet type cursor waiting for you to issue a HTTP request. If it is properly disabled, then you will get a handshake failure and returned to the command prompt.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;=== Does Adobe Flash Have Security Vulnerabilities? ===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;As you may have seen in the news recently, there has been some discussion around security vulnerabilities in Adobe Flash Player, and in particular about Mozilla disabling Flash Player in Firefox. We would like to clarify the following items about Adobe Flash:&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* Mozilla did disable all older versions of Flash Player in Firefox, but Adobe has already released a fixed version that is not blocked.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* We always recommend that our customers upgrade to the very latest version of Flash Player. For AppBoard 2.5.2.2 we require at least version 11.2, but we support releases up to the current version (18).&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* Google Chrome includes it&#039;s own Flash Player (i.e. it&#039;s not a separately installed plugin) and this is automatically updated with the browser, which they do any time there are serious security issues.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* Microsoft&#039;s new Edge browser includes it&#039;s own Flash Player and automatically updates in the same manner as Chrome.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* Customers on older Internet Explorer versions and Firefox need to install the up-to-date plugin or have the plugin auto-update.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* In reality, security vulnerabilities are constantly being introduced in operating systems, browsers, libraries (like SSL), and plugins (like Flash). What is most important is that the responsible parties take it seriously and address the problems as quickly as possible, and Adobe have continued to do that.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>imported&gt;Cmace</name></author>
	</entry>
	<entry>
		<id>http://ab.edge-technologies.com/docs/index.php?title=Enportal/5.6/faq/security&amp;diff=8542&amp;oldid=prev</id>
		<title>imported&gt;Jason.nicholls: 1 revision</title>
		<link rel="alternate" type="text/html" href="http://ab.edge-technologies.com/docs/index.php?title=Enportal/5.6/faq/security&amp;diff=8542&amp;oldid=prev"/>
		<updated>2015-04-30T11:18:25Z</updated>

		<summary type="html">&lt;p&gt;1 revision&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 11:18, 30 April 2015&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-notice&quot; lang=&quot;en&quot;&gt;&lt;div class=&quot;mw-diff-empty&quot;&gt;(No difference)&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>imported&gt;Jason.nicholls</name></author>
	</entry>
	<entry>
		<id>http://ab.edge-technologies.com/docs/index.php?title=Enportal/5.6/faq/security&amp;diff=8541&amp;oldid=prev</id>
		<title>imported&gt;Mike.berman: Add question about SSLv3 POODLE vulnerability</title>
		<link rel="alternate" type="text/html" href="http://ab.edge-technologies.com/docs/index.php?title=Enportal/5.6/faq/security&amp;diff=8541&amp;oldid=prev"/>
		<updated>2014-11-29T05:15:09Z</updated>

		<summary type="html">&lt;p&gt;Add question about SSLv3 POODLE vulnerability&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{DISPLAYTITLE:enPortal 5.6 FAQ - Security}}&lt;br /&gt;
[[Category:enPortal 5.6]]&lt;br /&gt;
&lt;br /&gt;
This page answers Frequently Asked Questions (FAQ) about enPortal and AppBoard security.&lt;br /&gt;
&lt;br /&gt;
== Security ==&lt;br /&gt;
&lt;br /&gt;
=== What is Single-Sign and how is it implemented? === &lt;br /&gt;
&lt;br /&gt;
Single Sign-on (SSO) is a feature of enPortal where a User&amp;#039;s credentials to integrated applications are securely stored in the enPortal system.  This allows Users to access and display information from back-end applications without having to manually log in to each of these applications.  By allowing administrators to assign authentications to Roles, Domains, and Users, this &amp;quot;single login&amp;quot; capability eliminates the need for users to log in separately to integrated resources displayed in the web interface.  If no credentials exist for a User in an integrated application, the User can manually log in to the application and enPortal will capture the credentials for future use.&lt;br /&gt;
&lt;br /&gt;
Single Sign-on tokens are managed by the enPortal administrator in the &amp;#039;&amp;#039;Provisioning&amp;#039;&amp;#039; section of the administrator UI.&lt;br /&gt;
&lt;br /&gt;
=== How is CAC/PKI authentication configured? ===&lt;br /&gt;
&lt;br /&gt;
Common Access Card (CAC, also referred to as PKI) authentication is a special custom login mechanism used by certain organizations, including the United States Department of Defense.  It restricts access to certain computer systems, such that only Users with an appropriate card can log in to the system.&lt;br /&gt;
&lt;br /&gt;
enPortal and AppBoard support CAC/PKI authentication through the use of an add-on authentication module.  This module can be implemented as long as the following requirements are satisfied:&lt;br /&gt;
&lt;br /&gt;
* The client has the necessary middleware installed to support the PKI infrastructure, providing the ability to read the CAC card information and submit the login details to the server.&lt;br /&gt;
* A valid SSL server certificate is installed on the AppBoard/enPortal server and AppBoard/enPortal is running with the HTTPS protocol.&lt;br /&gt;
* The AppBoard/enPortal server has connectivity established, via Firewall exceptions, to an Online Certificate Status Protocol (OCSP) Responder.&lt;br /&gt;
**  Note that enPortal can be configured to failover to alternate OCSP responder URLS. To configure this feature, update the &amp;lt;tt&amp;gt;[INSTALL_HOME]/server/webapps/enportal/WEB-INF/config/custom.properties&amp;lt;/tt&amp;gt; to contain:&lt;br /&gt;
::: &amp;lt;tt&amp;gt;ocsp.responder.0=&amp;#039;&amp;#039;&amp;lt;url&amp;gt;&amp;#039;&amp;#039;&amp;lt;/tt&amp;gt;&lt;br /&gt;
::: &amp;lt;tt&amp;gt;ocsp.responder.1=&amp;#039;&amp;#039;&amp;lt;url&amp;gt;&amp;#039;&amp;#039;&amp;lt;/tt&amp;gt;&lt;br /&gt;
::where &amp;#039;&amp;lt;url&amp;gt;&amp;#039; is replaced with the URL corresponding to your OCSP Responder URL. enPortal will each URL in sequence until it finds an available responder, or has tried all specified responders. Ensure that the list of responders starts with &amp;quot;0&amp;quot; and increments by 1 for each listed. If it doesn&amp;#039;t find ocsp.responder.0 it will try to look for the prior config &amp;#039;ocsp.resonder&amp;#039; and if that fails it will default to &amp;quot;http://ocsp.disa.mil&amp;quot;.&lt;br /&gt;
* The root CA and Intermediate CAs are collected and packaged for the custom PKI module to use for communicating with the OCSP Responder to validate a User’s certificate.&lt;br /&gt;
&lt;br /&gt;
=== How Are Usernames and Passwords Stored? === &lt;br /&gt;
&lt;br /&gt;
During an active session, credentials are stored in memory for use in authenticating to back-end integrated applications.  Credentials are stored in a reversible form, so they can be submitted to integrated applications on behalf of the User.  These credentials are stored using AES encryption.  Credentials for accessing AppBoard/enPortal are stored using a salted hash per database security best practices.&lt;br /&gt;
&lt;br /&gt;
Users cannot extract or access usernames or passwords for back-end applications.  The client never receives any version of these credentials.  These are only communicated directly between AppBoard/enPortal and the back-end application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Does enPortal encrypt communications between the client and server? ===&lt;br /&gt;
&lt;br /&gt;
HTTPS can be enabled for either or both of (a) browser to AppBoard/enPortal communications, and (b) AppBoard/enPortal to back-end application communications.  This option requires the installation of an SSL certificate on the AppBoard/enPortal server.&lt;br /&gt;
&lt;br /&gt;
enPortal serves as a proxy and reverse proxy for all applications it manages.  All communications between the client and the portal pass through a single port, so only one port needs to be opened in the server firewall, regardless of how many applications are being proxied.  enPortal manages all communications to and from the back-end applications, which are never exposed to the outside world.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Does enPortal provide protection against cross-site scripting attacks? ===&lt;br /&gt;
&lt;br /&gt;
AppBoard/enPortal provides comprehensive protection against cross-site scripting attacks.  All aspects of the HTTP communication are tested by the proxy, including request, headers, and body.  Captures cause display of HTTP 500 responses.  Updates to the output encoding scheme are also implemented to improve system efficiency and to eliminate cross-site scripting attacks.  The default behavior is to deny requests that contain malicious characters if the page that initiated the request is not from the AppBoard/enPortal server.&lt;br /&gt;
&lt;br /&gt;
More information is available on the [[enportal/5.6/admin/system_administration/security|enPortal Security]] page.&lt;br /&gt;
&lt;br /&gt;
=== How is the content which is accessed and rendered inside AppBoard/enPortal secured? ===&lt;br /&gt;
&lt;br /&gt;
Content is secured primarily at three levels.  On the user interface side, the set of visual components that a given User can access is determined by the content provisioning provided by the user model.  A User will see only the tabs of content that have been assigned to its Role(s), which in turn can be assigned directly to the User or to the Domain of the User.  The data sets (called Data Collections) that drive each visual component can be secured by applying filters on the AppBoard server to allow or prevent individual records from being presented to an end user (e.g. filter on company name, where company name is pulled from the User’s LDAP attributes).  Finally, the connections to the remote data sources can be secured by specifying User- or Domain-specific credentials for the connections (e.g. a database connection may require a username and password that is unique to each Domain/customer account).&lt;br /&gt;
&lt;br /&gt;
=== Is enPortal or AppBoard vulnerable to the SSLv3 (POODLE) exploit? ===&lt;br /&gt;
&lt;br /&gt;
This vulnerability is a problem with the SSLv3 protocol itself. It does not matter the implementation, so Tomcat, Apache, and any other web server that supports HTTPS could be vulnerable.&lt;br /&gt;
The solution is to disable SSLv3 support in Tomcat and only allow TLS connections. The browsers are also doing the same by releasing or planning to release updates that completely disable SSLv3 to avoid this issue.&lt;br /&gt;
We have resolved this issue in our enPortal/AppBoard v5.5.1 / v2.5.1 release by ensuring that only TLS is enabled. For releases prior to v5.5.1 / v2.5.1, the administrator can disable SSLv3 by doing the following steps:&lt;br /&gt;
&lt;br /&gt;
# Edit &amp;lt;tt&amp;gt;[INSTALL_HOME]/server/conf/server.xml&amp;lt;/tt&amp;gt;&lt;br /&gt;
# Find the line with: ... &amp;lt;tt&amp;gt;SSLEnabled=&amp;quot;${http.ssl}&amp;lt;/tt&amp;gt;&lt;br /&gt;
#* (this should be line 80 in a default server.xml)&lt;br /&gt;
# Add below this line a new line with:&lt;br /&gt;
#* &amp;lt;tt&amp;gt;sslEnabledProtocols = &amp;quot;TLSv1,TLSv1.1,TLSv1.2&amp;quot;&amp;lt;/tt&amp;gt;&lt;br /&gt;
# Restart enPortal/AppBoard&lt;br /&gt;
# Test to see whether SSLv3 is enabled/disabled before and after using the openssl client and specifying the protocol, by a procedure sch as the following:&lt;br /&gt;
#* &amp;lt;tt&amp;gt;$ openssl s_client -connect enportal_server:443 -ssl3&amp;lt;/tt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
With SSLv3 enabled, you will get a telnet type cursor waiting for you to issue a HTTP request. If it is properly disabled, then you will get a handshake failure and returned to the command prompt.&lt;/div&gt;</summary>
		<author><name>imported&gt;Mike.berman</name></author>
	</entry>
</feed>