vRealize Hyperic 5.x JRE update to include a fix for CVE-2014-6593
search cancel

vRealize Hyperic 5.x JRE update to include a fix for CVE-2014-6593

book

Article ID: 343921

calendar_today

Updated On:

Products

VMware VMware Aria Suite

Issue/Introduction

The Oracle (Sun) JRE package is updated to 1.7.0_76. The update addresses multiple security issues, also referred to as the SKIP-TLS vulnerability, that exist in the earlier releases of Oracle (Sun) JRE. Oracle has documented the CVE identifiers that are addressed in JRE 1.7.0_76 in the Oracle Java SE Critical Patch Update Advisory for January 2015. The JRE update includes a fix for CVE-2014-6593.
The Hyperic 5.x patches address the fix for CVE-2014-6593.


Environment

VMware vRealize Hyperic 5.8.4

Resolution

Before applying the patch on your Hyperic installation, take a snapshot of your virtual machine.<?xml:namespace prefix = o />

Applying the patch for vFabric Hyperic 5.0.x and vCenter Hyperic 5.7.x

1. Stop the Hyperic agent and the server.
The patch can only be applied when the agent and server are not running.

2. Back up your JRE directory, which is located in your server/agent installation.

· Agent: {agent}/

· Server:{server}/

3. Download the relevant patch and save it in the JRE directory.
vFabric Hyperic 5.0.x:

· Server download: https://customerconnect.vmware.com/web/vmware/details?downloadGroup=VFHQ_503_SERVER&productId=311&rPId=6848

· Agent download: https://customerconnect.vmware.com/web/vmware/details?downloadGroup=VFHQ_503_AGENT&productId=311&rPId=6848

vCenter Hyperic 5.7.x:

· Server download: https://customerconnect.vmware.com/web/vmware/details?downloadGroup=VFHQ_572&productId=346&rPId=6849

· Agent download: https://customerconnect.vmware.com/web/vmware/details?downloadGroup=VFHQ_572_AGENT&productId=346&rPId=6849

4. Start the Hyperic server and the agent.


Applying the patch for vRealize Hyperic 5.8.x

1. Stop the Hyperic agent and the server.
The patch can only be applied when the agent and server are not running.

2. Back up your JRE directory, which is located in your server/agent installation.

· Agent: {agent}/bundles/agent-x86-64-linux-5.8.x/ where "x" is the current installation version.
For example, Linux: /opt/hyperic/agent-5.8.4-EE/bundles/agent-x86-64-linux-5.8.4/
Windows:
C:\hyperic\hyperic-hqee-agent-5.8.4\bundles\agent-x86-64-win-5.8.4\

· Server:{server}/

3. Download the relevant file for your operating system.
Server download:
https://customerconnect.vmware.com/web/vmware/details?downloadGroup=VRHQ_584_SERVER&productId=378&rPId=7312
Agent download:
https://customerconnect.vmware.com/web/vmware/details?downloadGroup=VRHQ_584_AGENT&productId=378&rPId=7312

4. Extract the file to your JRE directory.

5. Start the Hyperic server and the agent.