This article covers the fixes made in vRealize Operations 8.10 from previous versions.
The following issues have been resolved as of vRealize Operations 8.10:
- [List View] Few issues in "Summary" tab.
- Invalid alert "Kerberos Authentications are Failing" in AD app monitoring.
- Some issues regarding the user that does not have permission to any dashboard.
- Business hours in views is not working correctly when host time is changed other than default one.
- geode issue 'tcp message exceeded max size of 16777215'.
- [CP] Cloud Proxy is not getting IPv6 Unique Local Address (ULA) from the network.
- [Notification Rules] Issue in messagebox while trying to import multiple notification rules.
- [App-Monitoring] disable interval change for adapter and its objects.
- Dashboard which is set as home landing page using the "Set as Home landing page" disappears from the Home page, after the upgrade.
- [App Monitoring] Row expander button should be shown in front of the VM name on "Environment > Applications > Manage Telegraf Agents" page when the agent is stopped.
- Misconfigured sudoers file: Arbitrary local file read using fping tool.
- "Forgot password" link brings weird dialog.
- Information disclosure via unhandled exception at an unauthenticated endpoint.
- Local privilege escalation using sudo rights on binary /usr/bin/pidstat.
- [Super Metric] Combine function has been removed.
- "Naming Exception" in logs for the TEST connection of LDAP server, configured through admin UI.
- After a reboot of vRealize Operations nodes, alerts are no longer visible - error in logs Cannot retrieve all Recommendations: null.
- Environment tab for resource is not updated when clicking on other resource.
- [Cost Driver] Save message is not disappearing in some use cases.
- The Adapter instance credential update is taking too long through the UI and API.
- InvalidRequestException when running what-if scenario with any of the fields having 0 value.
- "Actions" is overlapped when compliance name is long in Optimize > Compliance page.
- Import cost driver pop-up shows invalid error messages in one scenario.
- Cost page in standard licensing should not appear.
- dbupgrade.py should wait for postgres ready signal before making queries.
- Invalid licensing watermark due to Management Pack for Horizon license keys conversion.
- Collector Thread leak during Orphaned Disks Collection.
- Auto collapse side navigation experience frustrates users.
- Incorrect CP upgrade status.
- [Reporting] The "Contents" page numbering is incorrect if page footer enabled and contains more than 1 page.
- [Views] "Select object" button works for "Data" tab metric/properties only.
- Unable to assign pricing cards to VMC, AVS, or GCVE vCenters or Clusters.
- Audit page loading timeout.
- Can't generate reports if permissions for views not allowed.
- Remove obsolete fields from cprc.upgrade.status and cprc.pak.status.
- vRealize Operations API for stats does not escape spaces in string array values.
- Remove Redundant step from Upgrade operations counter.
- [CloudProxy] Collector service in CP deployed in AWS restarts 5 times.
- XL collector exeeds max thread count with 10 AWS adapter instances.
- There is a pop-up window with NullPointerException error message, after logging out from admin UI.
- Audit logs issues related failed login attempts and empty USER_ARCHIVE logs.
- [Service Discovery] "Is Application Member" property for Service based application doesn't exist.
- Issues occur when Cloud Account name contains specific symbols.
- [Service Discovery] SDMP-created and manually-created Business Applications get mixed up when the service object which is part of SDMP-created BA is added to manually-created BA in some cases.
- Unable to switch the specific dc mode through pop-up from a few cost drivers.
- Main Page Certificate notifications not updating after changes, updating after page refresh.
- HTML tag appears in error message.
- [Core] "ShareExternal" is typo in Administration > Access Control > Roles page.
- In some cases price calculation is being skipped till the first datapoint of the period.
- Failed to replace 2 data nodes in the same FD in CA enabled vRealize Operations.
- [Views] The objects list in view is empty on decreasing "Preview source".
- Issues regarding view creation (update).
- For Peak and Percentile95 metering items the bill generation reports bigger price then expected.
- [Optimize] [Capacity] Uncaught type exception in console.
- [Reports] UI crash after left panel resizing.
- [Optimize] [Capacity] Uncaught type exception in console.
- Menus under Object Browser > Environments containing a lot of objects or some not existing objects could not be expanded.
The following CVEs have been resolved as of vRealize Operations 8.10:
Component Name | CVE |
---|
ant | CVE-2020-1945 |
consul | CVE-2020-28053 |
CVE-2021-41803 |
CVE-2022-29153 |
CVE-2022-24687 |
CVE-2020-25864 |
CVE-2021-28156 |
CVE-2021-3121 |
CVE-2020-25201 |
CVE-2021-41805 |
CVE-2021-37219 |
CVE-2021-38698 |
CVE-2021-32574 |
expat | CVE-2022-25315 |
CVE-2022-25314 |
CVE-2022-25313 |
CVE-2022-22823 |
CVE-2022-22824 |
CVE-2022-22825 |
CVE-2022-22826 |
CVE-2022-22822 |
CVE-2022-23852 |
CVE-2022-23990 |
CVE-2022-25236 |
CVE-2022-25235 |
CVE-2021-45960 |
CVE-2021-46143 |
CVE-2022-22827 |
freetype | CVE-2022-27405 |
CVE-2022-27404 |
CVE-2022-27406 |
giflib | CVE-2021-40633 |
CVE-2022-28506 |
gjson | CVE-2021-42248 |
CVE-2021-42836 |
glibc | CVE-2022-39046 |
CVE-2021-3998 |
gnupg | CVE-2022-34903 |
golang-runtime | CVE-2021-44717 |
CVE-2021-44716 |
CVE-2021-39293 |
CVE-2022-23806 |
CVE-2022-23773 |
CVE-2022-23772 |
CVE-2022-24921 |
CVE-2022-28327 |
CVE-2022-27536 |
CVE-2022-24675 |
CVE-2021-34558 |
CVE-2021-31525 |
CVE-2021-27918 |
CVE-2021-3115 |
CVE-2021-3114 |
CVE-2020-28367 |
CVE-2020-28366 |
CVE-2020-28362 |
CVE-2020-24553 |
CVE-2020-16845 |
CVE-2020-15586 |
CVE-2020-14039 |
CVE-2021-33198 |
CVE-2021-33194 |
CVE-2020-29510 |
CVE-2021-41771 |
CVE-2021-41772 |
CVE-2021-38297 |
CVE-2021-36221 |
CVE-2021-29923 |
CVE-2021-33195 |
CVE-2021-33196 |
CVE-2021-33197 |
jaeger | CVE-2020-10750 |
jdk-openjdk | CVE-2022-21540 |
CVE-2022-21434 |
CVE-2022-21426 |
CVE-2022-34169 |
CVE-2022-21541 |
jvm-hotspot-openjdk | CVE-2022-21434 |
CVE-2022-21426 |
CVE-2022-34169 |
CVE-2022-21541 |
CVE-2022-21540 |
libtirpc | CVE-2021-46828 |
linux_kernel | CVE-2022-21166 |
CVE-2022-21125 |
CVE-2022-21123 |
CVE-2022-33742 |
CVE-2022-33741 |
CVE-2022-33740 |
CVE-2022-26365 |
CVE-2021-33656 |
CVE-2021-33655 |
CVE-2022-36879 |
CVE-2022-36946 |
CVE-2022-26373 |
CVE-2021-4159 |
CVE-2022-0812 |
CVE-2022-39842 |
log4j | CVE-2021-44832 |
lxml | CVE-2020-27783 |
CVE-2021-28957 |
Mako | CVE-2022-40023 |
netty | CVE-2020-11612 |
CVE-2020-7238 |
CVE-2016-4970 |
CVE-2015-2156 |
openssl | CVE-2021-3711 |
pathtools | CVE-2015-8607 |
platform | CVE-2020-27225 |
CVE-2019-16374 |
CVE-2020-8775 |
CVE-2020-8773 |
postgresql | CVE-2021-43766 |
CVE-2022-2625 |
CVE-2021-43767 |
rpm | CVE-2021-3521 |
rsync | CVE-2022-29154 |
salt | CVE-2022-22934 |
CVE-2021-31607 |
CVE-2022-22941 |
CVE-2022-22936 |
CVE-2022-22935 |
scala | CVE-2022-36944 |
shiro | CVE-2020-1957 |
CVE-2020-17510 |
CVE-2020-13933 |
CVE-2020-11989 |
CVE-2019-12422 |
CVE-2022-32532 |
CVE-2021-41303 |
CVE-2020-17523 |
snakeyaml | CVE-2017-18640 |
spring-boot | CVE-2022-27772 |
stream | CVE-2021-24772 |
thrift | CVE-2016-5397 |
CVE-2015-3254 |
CVE-2018-11798 |
CVE-2019-0205 |
CVE-2018-1320 |
tomb | CVE-2020-28638 |
tomcat | CVE-2022-23181 |
CVE-2021-42340 |
CVE-2022-29885 |
vim | CVE-2022-2231 |
xalan | CVE-2022-34169 |
xerces-j | CVE-2022-23437 |