This patch (CSP-90495) has been superseded and is no longer available. Please install the latest cumulative update, CSP-102092, by following the instructions in KB 412021.
Vulnerabilities Addressed by This (Superseded) Patch
This article provides information on a previous patch (CSP-90495) that upgraded Angular XLTS to version 1.9.1 to address licensing requirements and fix the security vulnerabilities listed below.
Affected Product
VMware Identity Manager Appliance: 3.3.7
Applicable CVEs
CVE-2023-26116, CVE-2023-26117, CVE-2023-26118
Environment
VMware Identity Manager 3.3.x
Resolution
Prerequisites (for Superseded Patch CSP-90495)
Version Support: It is recommended to upgrade any unsupported product versions to a supported version before patching. Please refer to the VMware Product Lifecycle Matrix.
Snapshots/Backups: It is strongly recommended to take a snapshot or backup of the appliance(s) and the database server before proceeding.
Procedure (for Superseded Patch CSP-90495)
Log in to the VMware Identity Manager appliance via SSH as sshuser and elevate to the root user with sudo su -.
Download and transfer the CSP-90495-Appliance-3.3.7.zip file to a temporary location on the appliance.