Cisco Unified Application Environment Developer Forums

« Back to Developers

PHP Vunnerabilities

Combination View Flat View Tree View
Threads [ Previous | Next ]
Hi,
We have a client that has mulitple PHP vulnerabilities when they had a 3rd party scan the CUAE server.  Are we able to upgrade PHP to the latest 5.2.x release, I think its 5.2.17? Or even to PHP 5.3.x?
 
Thanks
Tim

hi Tim,
 
The version of PHP which Core-Addendum installed is the one which has been tested. If you upgrade the latest version for PHP then the UI pages may or may not work as we have not tested that.
 
If you are using the CUAE version 2.5 and above then I would recommend to use the CUAEAdmin instead of mceadmin. In that case you can get rid of PHP folder if you think of the vulnerabilities as high risk, however mceadmin will not work at all if you remove PHP.
 
Thanks
Nabhonil
 
Hi,
We have a client that has mulitple PHP vulnerabilities when they had a 3rd party scan the CUAE server.  Are we able to upgrade PHP to the latest 5.2.x release, I think its 5.2.17? Or even to PHP 5.3.x?
 
Thanks
Tim