Hi,
I'm looking for a systematic way to track CVEs and security vulnerabilities that may affect out DataMiner environment.
Ideally, we would like to be able to identify vulnerabilities affecting not only DataMiner itself, but also third-party components and dependencies that are part of or required by a DataMiner deployment.
Is there currently an official Skyline security advisory, CVE feed, mailing list or other recommended source that customers can use for this purpose?
If no such feed currently exists, what approach does Skyline recommend for continuously monitoring vulnerabilities that may affect a DataMiner installation?
Thanks!
Hi Maximiliano,
There is currently no authoritative list or feed of vulnerabilities affecting DataMiner or its third-party dependencies. At present, the best available way to monitor this is by reviewing the release notes, where security-related fixes are mentioned under Enhancements without disclosing specific vulnerability details.
Note that we are actively working towards Cyber Resilience Act (CRA) compliance. As part of this, we will be improving the disclosure of vulnerabilities affecting DataMiner and providing a Software Bill of Materials (SBOM) to allow the tracking and monitoring of the third party dependencies.
Kind regards,