This patch (CSP-91401) has been superseded and is no longer available. Please install the latest cumulative update, CSP-102092, by following the instructions in KB 412021.
This article provides information on a previous patch (CSP-91401) that upgraded OpenSSH to fix the security vulnerability listed below.
CVE-2023-38408
Snapshots/Backups: It is strongly recommended to take a snapshot or backup of the appliance(s) and the database server before proceeding.
sshuser and elevate to the root user with sudo su -.CSP-91401-Appliance-3.3.7.zip file to a temporary location on the virtual appliance.unzip CSP-91401-Appliance-3.3.7.zip -d CSP-91401-Appliance-3.3.7
cd CSP-91401-Appliance-3.3.7
./CSP-91401-applyPatch.sh
Note: For a clustered deployment, repeat the steps above on all additional nodes sequentially.
After the patch deployment, perform the following steps to confirm it was applied successfully:
ls /usr/local/horizon/conf/flags/CSP-91401-3.3.7-hotfix.applied
sshuser or root user from a new session to confirm access.