I am in the process of hardening a RHEL7 webserver. This version ships with Apache 2.4.6, whereas the community current version is 2.4.41. It is my understanding that RHEL has backported all security updates from 2.4.41. RHEL even explains in detail that third party scanners do not take into account this backporting practice.
So my question is, does anyone have experience with tools that will not generate long lists of false positives? The current tool is Rapid7 Nexpose.
My security team does not know Linux, so I want to give them a reassurance that everything is patched without having to test CVE's one by one and send them screenshots (which is what they asked for). TIA
[link] [comments]
SOCIAL SHARE CARD GENERATOR