vrp-centos69_x86_64-Patch-3.3.2.14

 Basic information
Release type: Patch
Release date: 2019-08-06
OS update support: None
Technote: None
Documentation: None
Popularity: 272 viewed    downloaded
Download size: 148.23 MB
Checksum: 1712642139

 Applies to one or more of the following products:
Resiliency Platform 3.3.2 On CentOS 6.9 x86-64

 Obsolete patches, incompatibilities, superseded patches, or other requirements:
None.

 Fixes the following incidents:
3979293

 Patch ID:
None.

Readme file
                          * * * READ ME * * *
                 * * * Veritas Resiliency Platform Hot Fix 14 (3.3.2.14) * * *                         
                         Hotfix Date: 2019-08-2


This document provides the following information:

   * HOTFIX NAME
   * APPLIANCES SUPPORTED BY THE HOTFIX
   * BASE PRODUCT VERSION FOR THE HOTFIX
   * SUMMARY OF ISSUES FIXED BY THE HOTFIX
   * DETAILS OF ISSUES FIXED BY THE HOTFIX
   * INSTALLING THE HOTFIX
   * KNOWN ISSUES
   * NOTE


HOTFIX NAME
----------
Veritas Resiliency Platform Hotfix 14 (3.3.2.14)

APPLIANCES SUPPORTED BY THE HOTFIX
----------------------------------------
Resiliency Manager, Infrastructure Management Server

BASE PRODUCT VERSION FOR THE HOTFIX
-----------------------------------
Veritas Resiliency Platform 3.3.2


SUMMARY OF ISSUES FIXED BY THE HOTFIX
---------------------------------------
Hotfix 3.3.2.14:
* VRP-23981 - Arbitrary command execution issue in Add DNS functionality
* VRP-23956 - File traversal in AppSDK feature
* VRP-23928 - Arbitrary command execution issue in Resiliency Plans
* VRP-23893 - XSS issue in Resiliency Plans

DETAILS OF ISSUES FIXED BY THE HOTFIX
--------------------------------------------
This it as a critical security update for the above mentioned security vulnerabilies.
Refer to https://www.veritas.com/content/support/en_US/security/VTS19-002.html for additional information.

INSTALLING THE HOTFIX
--------------------
  1. Contact Veritas Technical Support for this Hot Fix and check if the hotfix is relevant to issue seen in your environment.
  2. Download the hotfix and copy it to any server having access to VRP appliances.
  3. Make sure there is no operation in progress while the hotfix is being applied.
  4. Perform the following steps to upload the hotfix
    a) Open the SFTP session from clish
	   utilities> sftp-session start put hotfix
	b) Provide the password for this temporary SFTP session
	c) Open SFTP session using the above created user information and upload the hotfix
  5. Perform the following steps to install the hotfix
    a) Verify that the hotfix is uploaded from clish
	   hotfix> list-available-hotfixes
	b) Apply the hotfix from clish
	   hotfix> apply-hotfix 3.3.2.14
  6. Verify hotfix is applied successfully from clish
     hotfix> list-applied-hotfixes
  7. Close the SFTP session opened earlier
     utilities> sftp-session stop
  8. Repeat the steps 4 to 7 for all the VRP RM & IMS appliances.
    

KNOWN ISSUES
-----------
None

NOTE
----
Make sure that hotfix 3.3.2.1 is installed before installing this hotfix.