VMware Response to CVE-2024-22280 (VMSA-2024-0017)
searchcancel
VMware Response to CVE-2024-22280 (VMSA-2024-0017)
book
Article ID: 325790
calendar_today
Updated On: 07-16-2024
Products
VMware Aria Suite
Issue/Introduction
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. VMware has evaluated the severity of this issue to be in the important severity range with a maximum CVSSv3 base score of 8.5.
This documents the process when patching the Automation appliance.
Upgrading to Aria Automation 8.17 can be performed using the normal upgrade process.
Please ensure that you have created a snapshot of the Aria Automation cluster of appliance(s) to be patched per the Prerequisites section of this article before proceeding with the next steps.
Login to Aria Suite Lifecycle (formerly vRealize Suite Lifecycle Manager)
Click Lifecycle Operations, navigate to Settings > Binary Mapping
Click Patch Binaries.
Download the patches for an offline installation. The patch must be downloaded and applied manually.
Download the patch for your version according to the chart in this article.
Using WinSCP or a similar tool, copy the patch to a location on the Aria Suite Lifecycle appliance. e.g. /data/patches/vra
Login to Aria Suite Lifecycle and navigate to Settings > Binary Mapping > Patch Binaries.
Select Add Patch Binary, enter the location of the patch on the appliance, click on the appropriate patch and select ADD.
Wait for the request to complete.
Go to Environments and select the environment where the Aria Automation cluster to be updated are hosted.
Select View Details, click on the 3 dots and navigate to Install patch.
Select the patch from the list of downloaded patches.
Click Next.
Review and Install the available patch.
The patch install request progress can be tracked under Requests. Note: Remove the snapshot once the patch installation has successfully completed and have verified you can access Aria Automation without errors.
Review Installed Patch History:
To view the history of patches, click Patches > History.
Click on History. Note: Alternatively, the vracli version patch command may be used to validate that the patch is installed. Note: The product version and build numbers reported via the Aria Automation GUI will not change after installing any patches. Please use the steps below to validate the patch installation.
Login to one of the Aria Automation appliances via an SSH session.
Run the following command: vracli version patch
Verify the patch installed matches the build number in the Validation column of the above chart.