vRealize Operations 8.10 Hot Fix 4
search cancel

vRealize Operations 8.10 Hot Fix 4

book

Article ID: 318406

calendar_today

Updated On:

Products

VMware Aria Suite

Issue/Introduction

This hot fix resolves CVE-2023-20877, CVE-2023-20878, CVE-2023-20879 and CVE-2023-20880.
For more information on the vulnerabilities and their impact on VMware products, see VMSA-2023-0009.  

vRealize Operations 8.10 Hot Fix 4 is a public Hot Fix that addresses the following issues:
  • Arbitrary file read & deserialize RCE after authentication.
  • Post-auth java bean el Expression inject RCE.
  • Local Privilege Escalation vulnerability in generateSupportBundle
  • Local Privilege Escalation vulnerability in activate_renewed_certificates
  • Bill generated only shows Tier 1 value and not Tier 2 on vapp that has enabled Tier 1,2 policy in VCD.
  • VMware Chargeback bills producing inconsistent results.

The following CVEs have been resolved as of version 8.10 Hot Fix 4:
Component NameCVE
bindCVE-2022-3094
CVE-2022-3924
CVE-2022-3924
CVE-2022-3924
glibcCVE-2023-25139
haproxyCVE-2023-25725
libarchiveCVE-2022-36227
linux_kernelCVE-2019-19319
CVE-2023-23454
postgresqlCVE-2021-43767
CVE-2022-41862
snappyCVE-2023-28115
spring-beansCVE-2022-22965
tarCVE-2022-48303
vimCVE-2023-0051
CVE-2023-0054
CVE-2023-0049
CVE-2023-0433
CVE-2023-1355
CVE-2023-1127


Environment

VMware vRealize Operations 8.10.x

Resolution

vRealize Operations 8.10 Hot Fix 4 can be applied to any 8.10 environment.
Note: Upgrading from older versions directly to this Hot Fix is not supported.  You must upgrade to 8.10 before applying this Hot Fix.

Important: Take snapshots of each of the vRealize Operations nodes before applying the Hot Fix by following How to take a Snapshot of vRealize Operations.

  1. Download the vRealize Operations 8.10 Hot Fix 4 PAK file .
Note: Select vRealize Operations Manager as the Product and select 8.10 as the version and click Search.
Select the option below.
Release Name Release Date Build Number UI Build Number File Name
vROps-8.10-HF4 5/11/2023 21553501 21553056 vRealize_Operations_Manager_With_CP-8.x-to-8.10.2.21553501.pak
  1. Log in to the primary node vRealize Operations Manager Administrator interface of your cluster at https://master-node-FQDN-or-IP-address/admin.
  2. Click Software Update in the left panel.
  3. Click Install a Software Update in the main panel.
  4. Follow the steps in the wizard to locate and install your PAK file.
  5. Install the product update PAK file.
    Wait for the software update to complete. When it does, the Administrator interface logs you out.
  6. Log back into the primary node Administrator interface.
    The main Cluster Status page appears and cluster goes online automatically. The status page also displays the Bring Online button, but do not click it.
  7. Clear the browser caches and if the browser page does not refresh automatically, refresh the page.
    The cluster status changes to Going Online. When the cluster status changes to Online, the upgrade is complete.

    Note: If a cluster fails and the status changes to offline during the installation process of a PAK file update then some nodes become unavailable. To fix this, you can access the Administrator interface and manually take the cluster offline and click Finish Installation to continue the installation process.
     
  8. Click Software Update to check that the update is done.
    A message indicating that the update completed successfully appears in the main pane.

Once the update is complete delete the snapshots you made before the software update.