This patch (CSP-90495) has been superseded and is no longer available. Please install the latest cumulative update, CSP-102092, by following the instructions in KB 412021.
This article provides information on a previous patch (CSP-90495) that upgraded Angular XLTS to version 1.9.1 to address licensing requirements and fix the security vulnerabilities listed below.
CVE-2023-26116, CVE-2023-26117, CVE-2023-26118
Snapshots/Backups: It is strongly recommended to take a snapshot or backup of the appliance(s) and the database server before proceeding.
sshuser and elevate to the root user with sudo su -.CSP-90495-Appliance-3.3.7.zip file to a temporary location on the appliance.unzip CSP-90495-Appliance-3.3.7.zip -d CSP-90495-Appliance-3.3.7
cd CSP-90495-Appliance-3.3.7
./CSP-90495-applyPatch.sh
Note: For a clustered deployment, repeat the steps above on all additional nodes sequentially.
After the patch deployment, perform the following steps to confirm it was applied successfully:
ls /usr/local/horizon/conf/flags/CSP-90495-3.3.7-hotfix.applied
https://<vidm-hostname>:8443.3.3.7.0 Build 23103647.To revert this patch, you can revert to the appliance(s) snapshot and the database backup taken before applying these steps.