vrp-centos610_x86_64-Patch-3.4.0.2

 Basic information
Release type: Patch
Release date: 2019-10-29
OS update support: None
Technote: None
Documentation: None
Popularity: 214 viewed    downloaded
Download size: 185.5 MB
Checksum: 2759514681

 Applies to one or more of the following products:
Resiliency Platform 3.4 On

 Obsolete patches, incompatibilities, superseded patches, or other requirements:
None.

 Fixes the following incidents:
3979293

 Patch ID:
None.

Readme file
                          * * * READ ME * * *
                 * * * Veritas Resiliency Platform Hot Fix 2 (3.4.0.2) * * *                         
                         Hotfix Date: 2019-10-29


This document provides the following information:

   * HOTFIX NAME
   * APPLIANCES SUPPORTED BY THE HOTFIX
   * BASE PRODUCT VERSION FOR THE HOTFIX
   * SUMMARY OF ISSUES FIXED BY THE HOTFIX
   * DETAILS OF ISSUES FIXED BY THE HOTFIX
   * INSTALLING THE HOTFIX
   * KNOWN ISSUES
   * NOTE


HOTFIX NAME
----------
Veritas Resiliency Platform Hotfix 3.4.0.2

APPLIANCES SUPPORTED BY THE HOTFIX
----------------------------------------
Resiliency Manager, Infrastructure Management Server and Data Mover Appliances

BASE PRODUCT VERSION FOR THE HOTFIX
-----------------------------------
Veritas Resiliency Platform 3.4


SUMMARY OF ISSUES FIXED BY THE HOTFIX
---------------------------------------
Hotfix 3.4.0.2: This hot fix addresses security issues reported in third party components used by Veritas Resiliency Platform.
Security Fixes:
Apache Batik:
CVE-2018-8013
CVE-2017-5662
CVE-2015-0250

Lo-Dash
CVE-2019-10744

Jackson-databind
CVE-2019-14540
CVE-2019-16943
CVE-2019-16335
CVE-2019-17267
CVE-2019-17531
CVE-2019-16942
CVE-2019-12384

Apache Http
CVE-2019-0211
CVE-2019-0217
CVE-2019-10082
CVE-2019-9517
CVE-2019-10081
CVE-2019-10097
CVE-2019-10092
CVE-2019-10098

Libevent
CVE-2016-10195
CVE-2016-10196
CVE-2016-10197


DETAILS OF ISSUES FIXED BY THE HOTFIX
--------------------------------------------
This hotfix resolves the above-mentioned security issues using following JIRA issues:

VRP-25638
VRP-25640
VRP-25752
VRP-25611
VRP-25639
VRP-25613


INSTALLING THE HOTFIX
--------------------
1. Contact Veritas Technical Support for this hotfix and check if the hotfix is relevant to issue seen in your environment.
2. Download the hotfix and copy it to any server having access to VRP appliances.
3. Extract the downloaded tar ball. Hotfix files for all applicable components will be extracted into the patches directory.
4. Make sure there is no operation in progress while the hotfix is being applied.
5. Perform the following steps to upload the hotfix on each of the applicable components.
    	a) Open the SFTP session from clish
	   utilities> sftp-session start put hotfix
b) Provide the password for this temporary SFTP session
	c) Open SFTP session using the above created user information, go to upload folder and upload the corresponding hotfix file for this component.
6. Perform the following steps to install the hotfix
    	a) Verify that the hotfix is uploaded from clish
	   hotfix> list-available-hotfixes
	b) Apply the hotfix from clish
	   hotfix> apply-hotfix 3.4.0.2
7. Verify hotfix is applied successfully from clish
     hotfix> list-applied-hotfixes
8. Close the SFTP session opened earlier
     utilities> sftp-session stop
9. Repeat the steps 5 to 8 on all applicable components. The hotfix functionality can fail if even one component is skipped. 
    

KNOWN ISSUES
-----------
None

NOTE
----
a)Make sure that hotfix 3.4.0.1 is installed before installing this hotfix.