VMware Aria Operations 8.17 Hot Fix 2 is a public Hot Fix that addresses the following issues:
Chargeback: Can't delete scope after AI deletion
Automation Central Job is failing for snapshot deletion - Maximum Timeout Reached
[App Monitoring] Utilization metric of configured processes shows one extra zero
Reads per second(IOPS) have increased due to the Pricing calculation
Notification: test: Validate criteria sends wlp action notification for non vm objects
Notification: Action Type: Test: Test Passes for "Non VM" objects
[Cost-driver] Selected hosts are getting sorted on top as per selection instead of maintaining the real-order while selecting individual server for customization
[REST API]: potential NPE in GET /api/deployment/config/globalsettings
The following CVEs have been resolved as of version 8.17 Hot Fix 2:
Note: Inclusion of a given CVE in the following table does not imply exploitability of said CVE.
Component Name
CVE
apache
CVE-2023-38709
CVE-2023-6710
CVE-2024-24795
glibc
CVE-2023-6246
CVE-2023-6779
CVE-2023-6780
gnutls
CVE-2024-28834
CVE-2024-28835
httpd
CVE-2024-27316
linux_kernel
CVE-2023-52447
CVE-2023-52458
CVE-2023-52482
CVE-2023-52620
CVE-2023-52644
CVE-2023-52650
CVE-2023-52651
CVE-2023-7042
CVE-2024-26583
CVE-2024-26585
CVE-2024-26589
CVE-2024-26594
CVE-2024-26642
CVE-2024-26809
CVE-2024-26816
CVE-2024-26820
CVE-2024-26851
CVE-2024-26852
CVE-2024-26855
CVE-2024-26857
CVE-2024-26859
CVE-2024-26863
CVE-2024-26870
CVE-2024-26872
CVE-2024-26875
CVE-2024-26877
CVE-2024-26880
CVE-2024-26882
CVE-2024-26883
CVE-2024-26884
CVE-2024-26885
CVE-2024-26889
CVE-2024-26891
CVE-2024-26895
CVE-2024-26898
CVE-2024-26901
CVE-2024-26903
CVE-2024-26907
CVE-2024-26908
CVE-2024-27024
CVE-2024-27025
CVE-2024-27028
CVE-2024-27030
CVE-2024-27038
CVE-2024-27043
CVE-2024-27044
CVE-2024-27045
CVE-2024-27046
CVE-2024-27047
CVE-2024-27051
CVE-2024-27052
CVE-2024-27053
CVE-2024-27065
CVE-2024-27073
CVE-2024-27074
CVE-2024-27075
CVE-2024-27076
CVE-2024-27077
CVE-2024-27078
CVE-2024-27388
nghttp2
CVE-2024-28182
util-linux
CVE-2024-28085
Resolution
VMware Aria Operations 8.17 Hot Fix 2 can be applied to any 8.17.x environment. Note: Upgrading from older versions directly to this Hot Fix is not supported. You must upgrade to 8.17.x before applying this Hot Fix.
Log in to the primary node VMware Aria Operations Administrator interface of your cluster at https://primary-node-FQDN-or-IP-address/admin .
Click Software Update in the left panel.
Click Install a Software Update in the main panel.
Follow the steps in the wizard to locate and install your PAK file.
Install the product update PAK file. Wait for the software update to complete. When it does, the Administrator interface logs you out.
Log back into the primary node Administrator interface. The main Cluster Status page appears and cluster goes online automatically. The status page also displays the Bring Online button, but do not click it.
Clear the browser caches and if the browser page does not refresh automatically, refresh the page. The cluster status changes to Going Online. When the cluster status changes to Online, the upgrade is complete.
Note: If a cluster fails and the status changes to offline during the installation process of a PAK file update then some nodes become unavailable. To fix this, you can access the Administrator interface and manually take the cluster offline and click Finish Installation to continue the installation process.
Click Software Update to check that the update is done. A message indicating that the update completed successfully appears in the main pane.
Once the update is complete delete the snapshots you made before the software update.