Developers: | Riverbed Technology |
Last Release Date: | 2022/03/14 |
Content |
2022: Fix vulnerabilities that allow the user to remotely embed and run malicious code
4 critical vulnerabilities were detected in the Riverbed network product. This became known on March 14, 2022.
Vulnerable software is SteelCentral AppInternals for monitoring and diagnosing application performance.
The Singapore team of Cyber Security Group IB experts discovered a total of seven dangerous vulnerabilities in Riverbed's network software, four of which were critical (CVE-2021-42786, CVE-2021-42787, CVE-2021-42853 and CVE-2021-42854).
Clients typically use this software data centers in and on cloudy servers to collect information performance information, transaction traces, etc.
In particular, the vulnerable code resides in a dynamic sampling agent, which is a component of AppInternals collection. The issue affects software version 10.x, version up to 12.13.0, and version up to 11.8.8.
Critical vulnerabilities received scores of 9.8, 9.4, 9.1 and 9.8 points, respectively, out of 10 on the CVSS scale. Operating the most dangerous of the problems allows an unauthorized user to remotely implement and run malicious code on the victim's system.
CVE-2021-42786 - a vulnerability of remote code execution in due to the lack of API software proper validation of input data - URL hop. CVE-2021-42787 is a vulnerability to the lack of proper name entry verification, file allowing attackers to use characters such as.. "/" as a name. Exploiting a vulnerability can lead to a potential directory bypass and unauthorized access to limited resources. CVE-2021-42853 and CVE-2021-42854 are also represented by directory vulnerabilities at endpoints. API
Experts told Riverbed about their findings, and the company has issued fixes for detected vulnerabilities. Riverbed Software Users are strongly Encouraged to Upgrade to the Latest[1].
2015
Riverbed SteelCentral AppInternals 10 certified for Microsoft Azure
On August 5, 2015, it became known about the Riverbed SteelCentral AppInternals 10 certification for monitoring and diagnostics of Microsoft Azure. This allows IT professionals, developers, and business leaders to monitor user experience and application performance in Azure and at the underlying infrastructure level.
Application window screenshot, 2015
SteelCentral AppInternals 10 monitors applications in the cloud and beyond, provides a comprehensive overview, and provides powerful analytics tools to help companies improve application performance, optimize user experience, and measure impact on business results. At the same time, the product provides detailed diagnostic information that helps developers resolve code or SQL failures. Users of AppInternals and Azure receive:
- Easy to implement and use. Installation takes minutes, setup and operation do not require special skills.
- interactive control panels. Easy-to-use, web-based panels offer different performance diagnostic criteria, and problem root-cause analysis is done in two clicks.
- accurate real-time monitoring. Unlike other products, SteelCentral AppInternals tracks absolutely all user or browser device to application experiences on the server and builds second-by-second system metrics in production environments. This allows you to detect and diagnose even the most invisible problems that affect the user's work.
- quick resolution of problems. SteelCentral AppInternals allows users to detect the root causes of problems in applications even at the code level and import diagnostic data directly into Visual Studio for quick resolution. Developers no longer have to spend much time recreating and validating error scenarios before they can identify, diagnose, and resolve their root cause.
The product is available for testing without downloading or installing it.
Released version SteelCentral AppInternals 10
On July 1, 2015, Riverbed Technology introduced SteelCentral AppInternals 10 (formerly OPNET AppInternals Xpert) to monitor application performance in a hybrid environment.
The SteelCentral AppInternals 10 solution is simple and easy to use: installation of the product takes minutes and does not require special skills, you can access the interactive control panel based on web technologies from a computer, tablet or smartphone.
SteelCentral AppInternals 10 helps you monitor applications in the cloud and traditional enterprise infrastructure. The solution provides full visibility and powerful analytics tools to help IT organizations improve application performance and leverage them to meet business challenges. Unlike other APM products, which often show transactions selectively and summarize meter readings at certain intervals (minutes or more), SteelCentral AppInternals 10 tracks absolutely all user or browser device to application calls on the server and builds second-by-second system metrics in IT environments. These capabilities provide accurate user experience, application performance, and root cause of problems.
"Today, applications form the basis of business functioning, companies need advanced APM solutions that can accurately identify and quickly diagnose the causes of problems before users encounter them," said Alexander Stulov, head of Riverbed Technology in Russia and the CIS. - SteelCentral AppInternals 10 helps IT professionals navigate all of the transactions and relationships that determine the availability and performance of information systems, preventing the business impact of organizations. "
SteelCentral AppInternals provides visibility and control, provides high performance applications in a hybrid environment.
In this solution, Riverbed combined the capabilities of the application performance management product with a single source of monitoring data on network performance, applications, and end-user performance: SteelCentral AppInternals 10 is integrated into the Riverbed SteelCentral Portal product. This ensures full visibility of performance and availability of analytics across all users, applications, and infrastructure networks. This combination creates a complete picture that point-based APM solutions cannot provide, and completely changes the IT team collaboration system to solve performance problems.
2013
New features and unique features of OPNET AppInternals Xpert 8.5
Moving to a service-oriented architecture and flexible development processes, on the one hand, helps accelerate the deployment of new solutions. On the other hand, this leads to their growth and rapid complication. New features of OPNET AppInternals Xpert 8.5 help to cope with this contradiction. They enable application development and support teams to gather information without which they cannot identify and resolve performance problems of complex tiered applications.
Support for integrated development environments
The new version of OPNET AppInternals Xpert introduced support for popular integrated development environments, including Microsoft Visual Studio and Eclipse. This enables two-way granularity and ultimately simplifies problem resolution and program debugging. Moreover, application development and operation teams gain full data transparency and can interact effectively with each other. For example, application teams can use transaction tracing to find calls or methods that cause problems, and then pass this information to the developer. And development and quality teams can determine exactly where and what component the code is used to debug new releases of programs.
Integrated end-user performance monitoring
End-user performance monitoring is combined with transaction tracing and application component processing. This allows you not only to better analyze the effectiveness of client programs, but also to find a specific transaction that is responsible for reducing response. Through this integration, support teams gain accurate and comprehensive information about application performance from a user perspective and can immediately begin troubleshooting. As a result, these commands receive all the necessary information immediately after the problem occurs. This data allows you to more deeply study the transactions performed by applications and analyze the source code.
Web application performance, including cloud systems, is monitored with a compact JavaScript script. It can be automatically inserted into AppInternals agents, as well as into the Stingray Traffic Manager application delivery controller, which allows organizations to create specialized functional components or implement traffic management policies for a specific application.
Improved Transaction Trace Log Store
In this release, OPNET AppInternals Xpert, a "big data" collector, has been enhanced to enable application development and support professionals to explore thousands of different types of unstructured data and performance metrics, as well as the context for quick and efficient analysis. This component records and indexes not just sample traces, but literally all transactions in progress, and stores them in a special store. Thanks to this, all the necessary data are always available to specialists. Simple search functions allow you to quickly find the right transaction among billions of objects, making it easier to resolve problems. The correlation mechanism helps automate this process by identifying causal relationships among hundreds of thousands of transactions and performance metrics that are collected from all application tiers. In addition, proprietary analytics tools automatically detect anomalies in performance and warn you in advance of possible problems.
Riverbed OPNET AppInternals Xpert 8.5
In April 2013, Riverbed Technology announced the release of Riverbed OPNET AppInternals Xpert 8.5, a unified system package that allows you to collect detailed information about the operation of complex layered solutions. Its new features provide complete transparency of performance data from browsers to server databases. The ability to track application response to user activity is combined with code-level transaction tracing and monitoring key performance indicators for programs and systems. This enables developers and support professionals to quickly collect all the necessary data and work together to identify, troubleshoot, and debug source code.
The efficiency of any company today depends on how fast the applications that users need to communicate with customers, manufacture goods, automate business processes and perform other business-critical tasks. But the higher the importance of applications, the more complex they become. This problem is addressed by Riverbed application performance management solutions, which enable IT professionals to collect and accelerate all program response data.
With the release of OPNET AppInternals Xpert 8.5, development teams, application support, and quality assurance have the ability to track all performance information. This gives them the opportunity to detect problems in advance that can affect business efficiency. In addition, application analysis before deployment allows you to determine which components of the production system can become performance bottlenecks. Finally, together with OPNET AppInternals Xpert 8.5, organizations can use other Riverbed technologies, including the Riverbed Stingray ® Traffic Manager, which allows you to collect additional information about program performance from a user perspective.