Vulnerabilities for Oracle Linux

230 views
Skip to first unread message

Kobus Bensch

unread,
Apr 23, 2024, 9:30:44 AM4/23/24
to Wazuh | Mailing List
Hi everyone

When Centos/IBM decided to change the Centos model from what it was to what it is now, as a company we decided to use Oracle Linux. At the time both Alma and Rocky was too new for us to consider.

We have a few Centos servers left that we have not yet converted to Oracle linux and for these I can see the Vulnerabilities, but we do not see any vulnerabilities for Oracle linux.

To try and get this working, I made the following changes:
in /var/ossec/etc/ossec.conf
I added
    <!-- Oracle Linux Server -->
    <provider name="oraclelinux">
      <enabled>yes</enabled>
      <os>5</os>
      <os>6</os>
      <os>7</os>
      <os>8</os>
      <os>9</os>
      <update_interval>1h</update_interval>
    </provider>

I also tried Oracle Linux and Oracle Linux Server as the provider name, but these 2 dont work. What other name can I try to get the vulnerabilities displayed for Oracle Linux?

Thank you
Kobus

Julio Gasco

unread,
Apr 23, 2024, 12:32:32 PM4/23/24
to Wazuh | Mailing List
Hi Kobus,
Oracle Linux is still an unsupported OS for Vulnerability detector by default But you can still scan for vulnerabilities using the unsupported systems scan as per the below documentation:

You will be using redhat for vulnerabilities and the configuration will look similar to the following one:
<provider name="redhat">
   <enabled>yes</enabled>
   <os allow="Oracle Linux-7">7</os>
   <update_interval>1h</update_interval>
   <update_from_year>2010</update_from_year>
</provider>


On the above documentation you can find more details on this configuration under Configuring Vulnerability Detector to include unsupported systems

Let me know if this helps,
Regards!

Kobus Bensch

unread,
Apr 25, 2024, 5:51:31 AM4/25/24
to Wazuh | Mailing List
Hi Julio
I have no tried so many different permutations of the code you sent and after reading the page ytou sent but none of them are working.

Thank you for your help though. Very much appreciated.
Kobus

Kobus Bensch

unread,
Apr 25, 2024, 5:51:49 AM4/25/24
to Wazuh | Mailing List
Hi

So it seems like I will not be able to get Oracle Linux Server scanned for vulnerabilities at all.

In the logs after trying a lot of different settings:
{
  "timestamp": "2024/04/24 15:00:20",
  "tag": "wazuh-modulesd:vulnerability-detector",
  "pid": 186785,
  "file": "wm_vuln_detector.c",
  "line": 6271,
  "routine": "wm_vuldet_collect_agents_to_scan",
  "level": "debug",
  "description": "(5485): Agent '030' has an unsupported OS: 'Oracle Linux Server'"
}

Is there any plans to get Oracle Linux supported?

On Tuesday 23 April 2024 at 17:32:32 UTC+1 Julio Gasco wrote:

Julio Gasco

unread,
Apr 25, 2024, 2:41:03 PM4/25/24
to Wazuh | Mailing List
Hi Kobus,
Can you give me the exact Oracle linux version you are trying to install ? 
I will replicate it in a lab and get back to you with the configurations you need to implement.

Regards!

Kobus Bensch

unread,
Apr 26, 2024, 5:20:19 AM4/26/24
to Wazuh | Mailing List
Hi Julio

Thank you so much. Here is an export from the Wazuh console:
ID Status Agent Last keep alive OS version architecture OS version build OS version minor OS name OS platform OS uname OS version
2 active Wazuh v4.7.3 2024-04-26T09:07:35+00:00 x86_64 9 3 Oracle Linux Server ol Linux |pdmsq002.internal.com |5.14.0-362.8.1.el9_3.x86_64 |#1 SMP PREEMPT_DYNAMIC Mon Nov 13 14:06:58 PST 2023 |x86_64 9.3
3 active Wazuh v4.7.3 2024-04-26T09:07:34+00:00 x86_64 9 3 Oracle Linux Server ol Linux |pdmsq003.internal.com |5.14.0-362.8.1.el9_3.x86_64 |#1 SMP PREEMPT_DYNAMIC Mon Nov 13 14:06:58 PST 2023 |x86_64 9.3
4 active Wazuh v4.7.3 2024-04-26T09:07:34+00:00 x86_64 9 3 Oracle Linux Server ol Linux |pdmsq001.internal.com |5.14.0-362.8.1.el9_3.x86_64 |#1 SMP PREEMPT_DYNAMIC Mon Nov 13 14:06:58 PST 2023 |x86_64 9.3
5 active Wazuh v4.7.3 2024-04-26T09:07:37+00:00 x86_64 7 9 Oracle Linux Server ol Linux |iiftp001.internal.com |3.10.0-1160.114.2.0.1.el7.x86_64 |#1 SMP Wed Mar 20 11:23:11 PDT 2024 |x86_64 7.9
6 active Wazuh v4.7.3 2024-04-26T09:07:34+00:00 x86_64 9 3 Oracle Linux Server ol Linux |diftp001.dev.com |5.14.0-362.8.1.el9_3.x86_64 |#1 SMP PREEMPT_DYNAMIC Mon Nov 13 14:06:58 PST 2023 |x86_64 9.3
7 active Wazuh v4.7.3 2024-04-26T09:07:36+00:00 x86_64 7 9 Oracle Linux Server ol Linux |tidns001.internal.com |5.4.17-2136.329.3.1.el7uek.x86_64 |#2 SMP Tue Mar 5 01:07:50 PST 2024 |x86_64 7.9
8 active Wazuh v4.7.3 2024-04-26T09:07:33+00:00 x86_64 9 3 Oracle Linux Server ol Linux |piitm001.internal.com |5.14.0-362.8.1.el9_3.x86_64 |#1 SMP PREEMPT_DYNAMIC Mon Nov 13 14:06:58 PST 2023 |x86_64 9.3
9 active Wazuh v4.7.3 2024-04-26T09:07:29+00:00 x86_64 7 9 CentOS Linux centos Linux |backup-master.internal.com |3.10.0-1160.108.1.el7.x86_64 |#1 SMP Thu Jan 25 16:17:31 UTC 2024 |x86_64 7.9
10 active Wazuh v4.7.3 2024-04-26T09:07:35+00:00 x86_64 7 9 Oracle Linux Server ol Linux |iintp001.internal.com |3.10.0-1160.108.1.0.1.el7.x86_64 |#1 SMP Fri Feb 23 17:06:24 PST 2024 |x86_64 7.9
11 active Wazuh v4.7.3 2024-04-26T09:07:38+00:00 x86_64 7 9 Oracle Linux Server ol Linux |iintp002.internal.com |3.10.0-1160.108.1.0.1.el7.x86_64 |#1 SMP Fri Feb 23 17:06:24 PST 2024 |x86_64 7.9
12 active Wazuh v4.7.3 2024-04-26T09:07:31+00:00 x86_64 7 9 Oracle Linux Server ol Linux |iintp003.internal.com |3.10.0-1160.108.1.0.1.el7.x86_64 |#1 SMP Fri Feb 23 17:06:24 PST 2024 |x86_64 7.9
13 active Wazuh v4.7.3 2024-04-26T09:07:35+00:00 x86_64 7 9 Oracle Linux Server ol Linux |iidhp001.internal.com |5.4.17-2136.326.6.el7uek.x86_64 |#2 SMP Thu Nov 30 22:28:19 PST 2023 |x86_64 7.9
14 active Wazuh v4.7.3 2024-04-26T09:07:36+00:00 x86_64 7 9 Oracle Linux Server ol Linux |iidhp002.internal.com |5.4.17-2136.326.6.el7uek.x86_64 |#2 SMP Thu Nov 30 22:28:19 PST 2023 |x86_64 7.9
15 active Wazuh v4.7.3 2024-04-26T09:07:34+00:00 x86_64 7 9 Oracle Linux Server ol Linux |inpxe001.internal.com |5.4.17-2136.326.6.el7uek.x86_64 |#2 SMP Thu Nov 30 22:28:19 PST 2023 |x86_64 7.9
16 active Wazuh v4.7.3 2024-04-26T09:07:33+00:00 x86_64 8 9 Oracle Linux Server ol Linux |digit001.priv.net |5.4.17-2136.327.2.el8uek.x86_64 |#2 SMP Fri Jan 5 14:55:52 PST 2024 |x86_64 8.9
17 active Wazuh v4.7.3 2024-04-26T09:07:33+00:00 x86_64 8 9 Oracle Linux Server ol Linux |mzmsc001.priv.net |5.4.17-2136.328.3.el8uek.x86_64 |#2 SMP Thu Jan 18 15:56:59 PST 2024 |x86_64 8.9
18 active Wazuh v4.7.3 2024-04-26T09:07:35+00:00 x86_64 8 9 Oracle Linux Server ol Linux |mzmsc002.priv.net |5.4.17-2136.328.3.el8uek.x86_64 |#2 SMP Thu Jan 18 15:56:59 PST 2024 |x86_64 8.9
19 active Wazuh v4.7.3 2024-04-26T09:07:29+00:00 x86_64 8 8 Oracle Linux Server ol Linux |pzmnt001.priv.net |5.4.17-2136.308.9.el8uek.x86_64 |#2 SMP Mon Jun 13 20:36:40 PDT 2022 |x86_64 8.8
20 active Wazuh v4.7.3 2024-04-26T09:07:35+00:00 x86_64 8 8 Oracle Linux Server ol Linux |pzmnt002.priv.net |5.4.17-2136.323.8.2.el8uek.x86_64 |#2 SMP Tue Sep 19 23:45:56 PDT 2023 |x86_64 8.8
21 active Wazuh v4.7.3 2024-04-26T09:07:35+00:00 x86_64 9 3 Oracle Linux Server ol Linux |iintp003.priv.net |5.14.0-362.18.0.2.el9_3.x86_64 |#1 SMP PREEMPT_DYNAMIC Thu Feb 8 17:46:03 PST 2024 |x86_64 9.3
22 active Wazuh v4.7.3 2024-04-26T09:07:31+00:00 x86_64 9 3 Oracle Linux Server ol Linux |iintp001.priv.net |5.14.0-362.18.0.2.el9_3.x86_64 |#1 SMP PREEMPT_DYNAMIC Thu Feb 8 17:46:03 PST 2024 |x86_64 9.3
23 active Wazuh v4.7.3 2024-04-26T09:07:36+00:00 x86_64 9 3 Oracle Linux Server ol Linux |iintp002.priv.net |5.14.0-362.18.0.2.el9_3.x86_64 |#1 SMP PREEMPT_DYNAMIC Thu Feb 8 17:46:03 PST 2024 |x86_64 9.3
24 active Wazuh v4.7.3 2024-04-26T09:07:31+00:00 x86_64 7 9 Oracle Linux Server ol Linux |dihap001.dev.com |5.4.17-2136.329.3.1.el7uek.x86_64 |#2 SMP Tue Mar 5 01:07:50 PST 2024 |x86_64 7.9
25 active Wazuh v4.7.3 2024-04-26T09:07:34+00:00 x86_64 8 9 Oracle Linux Server ol Linux |dikck001.dev.com |5.4.17-2136.329.3.1.el8uek.x86_64 |#2 SMP Mon Mar 4 23:56:08 PST 2024 |x86_64 8.9
26 active Wazuh v4.7.3 2024-04-26T09:07:37+00:00 x86_64 8 9 Oracle Linux Server ol Linux |dikck002.dev.com |5.4.17-2136.329.3.1.el8uek.x86_64 |#2 SMP Mon Mar 4 23:56:08 PST 2024 |x86_64 8.9
27 active Wazuh v4.7.3 2024-04-26T09:07:35+00:00 x86_64 7 9 CentOS Linux centos Linux |ddpsq001.dev.com |3.10.0-1160.90.1.el7.x86_64 |#1 SMP Thu May 4 15:21:22 UTC 2023 |x86_64 7.9
28 active Wazuh v4.7.3 2024-04-26T09:07:38+00:00 x86_64 7 9 CentOS Linux centos Linux |ddpsq002.dev.com |3.10.0-1160.90.1.el7.x86_64 |#1 SMP Thu May 4 15:21:22 UTC 2023 |x86_64 7.9
29 active Wazuh v4.7.3 2024-04-26T09:07:36+00:00 x86_64 7 9 Oracle Linux Server ol Linux |ddpsq003.dev.com |3.10.0-1160.105.1.0.1.el7.x86_64 |#1 SMP Tue Nov 21 18:07:48 PST 2023 |x86_64 7.9
30 active Wazuh v4.7.3 2024-04-26T09:07:37+00:00 x86_64 7 9 Oracle Linux Server ol Linux |iians001.priv.net |5.4.17-2136.330.7.1.el7uek.x86_64 |#2 SMP Thu Apr 4 18:11:10 PDT 2024 |x86_64 7.9

Kobus Bensch

unread,
Apr 26, 2024, 5:31:17 AM4/26/24
to Wazuh | Mailing List
Hi Julio
This is the current config I have:
    <!-- RedHat OS vulnerabilities -->

    <provider name="redhat">
      <enabled>yes</enabled>
      <os>5</os>
      <os>6</os>
      <os>7</os>
      <os>8</os>
      <os>9</os>
      <os allow="Oracle Linux-5" path="/opt/oval-data/rhel-5-including-unpatched.oval.xml.bz2">5</os>
      <os allow="Oracle Linux-6" path="/opt/oval-data/rhel-6-including-unpatched.oval.xml.bz2">6</os>
      <os allow="Oracle Linux-7" path="/opt/oval-data/rhel-7-including-unpatched.oval.xml.bz2">7</os>
      <os allow="Oracle Linux-8" path="/opt/oval-data/rhel-8-including-unpatched.oval.xml.bz2">8</os>
      <os allow="Oracle Linux-9" path="/opt/oval-data/rhel-9-including-unpatched.oval.xml.bz2">9</os>
      <update_interval>1h</update_interval>
    </provider>
But I have tried many different versions. 36 to be exact.

Kobus

Julio Gasco

unread,
Apr 26, 2024, 8:51:56 AM4/26/24
to Wazuh | Mailing List
Hi Kobus,
Thanks for the information. I will be deploying some Oracle's with those versions and come back to you with my findings.
I will update you as soon as my tests are completed.
Regards!

Kobus Bensch

unread,
Apr 26, 2024, 8:53:13 AM4/26/24
to Wazuh | Mailing List
Thank you so much.

Kobus Bensch

unread,
Aug 14, 2024, 12:04:52 PM8/14/24
to Wazuh | Mailing List
Hi Julio

I was wondering if you had a chance to look at the issue above yet?

Thank you
Kobus

Dhairya Shah

unread,
Nov 8, 2024, 5:30:17 AM11/8/24
to Wazuh | Mailing List
Hello,

I was facing a similar issue, did you find any kind of solution??

Kobus Bensch

unread,
Nov 8, 2024, 5:31:47 AM11/8/24
to Dhairya Shah, Wazuh | Mailing List
Hi

I have not as yet.



~~~~~~~~~~~~
Kobus Bensch - Senior Systems Engineer
Yospace - The Dynamic Ad Insertion Company
Church House, 18-20 Church Street, Staines TW18 4EP
Switchboard: +44 1784 466388 Ext. 217 | Fax: +44 1784 466387
Technical Support: +44 1784 818312 - sup...@yospace.com
http://www.yospace.com

--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh | Mailing List" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/xOsPuJbmxhw/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/wazuh/00b08e49-9623-4598-b5fb-f70fb31bfa4dn%40googlegroups.com.

Reply all
Reply to author
Forward
0 new messages