This article covers the fixes made in VMware Aria Operations 8.18 from previous versions.
The following issues have been resolved as of VMware Aria Operations 8.18:
- Payload Template: Incorrect handling of string metric in notifications
- [Custom Groups] The "Update" button is not getting enabled
- Getting JavaScript error when trying to set filter criteria with not existing property value in Rule based application
- [Alert Clustering] Seems the cluster is created without parent object
- [Alert Clustering] Rendering issues of not existing resources.
- [APPOS]: ARC bootstrap operations with Rest API fails
- [Alert Clustering] Relationship tree issue, not all objects are displayed in the relationship tree
- [NSX Management Pack] Negative Stats Check for logical router
- To set Alert definition for tags with multiple values
- Workload efficiency figure calculation changes for Greenscore
- VMware Aria Operations Configuration window defects.
- [Global Settings, Data Retention] The system allows you to set -1 in the Deleted Objects retention field
- [UI Issue] Uninstall with invalid password doesn't show the enabled plugins on Manage Telegraf UI
- Agent management operations to be enabled only if Cloud Proxy (ARCFQDN) value populated in Manage Telegraf Agent page
- NullPointerException in Notification engine Resource Kind Filtering in 8.16.1
- List View Rollup transformation needs to do rollup based on calendar dates
- Notification text regarding out-of-the-box alerts needs to be updated
- Selecting Actions Notifications type disables Outbound method dropdown
- Missing Alert/Action label in step 4 of the Add Notifications wizard
- Showing null for "Affinity Rules" in the "Cluster Compute Resource" object Summary page
- Alerts: Super Metric name is not initialized in the alert details window
- Installing agent action on a machine whose mapped Cloud Proxy (CP) is in "Going online" state shows no error
- vSphere World Summary page: vSphere World widget: Counts are incorrect
- Cloud Proxy should have a mechanism to create a flag on CPs to figure out the haproxy's DNS should be disabled or not
- Swagger: Models: For some models clicking Arrow icons leads to error on the top of the swagger
- PolicyClient's assignPolicy Method doesn't sends policyID
- Cost Analysis: Incorrect behavior for TopN functionality
- Changing the advanced filter does not affect the Resource Grid result.
- Policy cache and database mismatch
- [Policy] Show the policy name in edit mode completely
- [Global Settings] The Save and Cancel buttons do not appear after changing the state of the Login Message section.
- REST: Notifications: Pagination doesn't work for notification APIs
- Add new options for Object Relationship and Object Relationship Advanced widgets, to do not select object by default.
- "The field is required " error icon appears always on top in filter
- [Alerts] The "Group By" option and filtering are not stateful in the "Alerts" page
- VCD Policies: digital precision should be changed
- Cost Analysis: No need to ask for saving analysis in the first run
- Incorrect value is being published for vSAN Capacity threshold properties
- VMwareInfraHealthAdapter logs flooded with "Login Failed to the VC" errors when VC is unreachable
- CapacityNew.action causes delays in multiple pages
- Launchpad: "The page you requested couldn't be found" message while accessing a link from the developer center page
- [What-If, Commit] Unsaved changes will be lost pop up occurs in the described case
- Analytics start up takes long in case of the huge amount of dynamic properties
- NullPointerException when sending Alert Notification
- Infrastructure Health: Excessive "The Response from the Json is coming null" Errors Flooding VMwareInfraHealthAdapter logs
- Test Notification: Notification Test Fails with Empty Data
- Job type is incorrect in job successful notification email template
- Allow Depreciation to have a max value of 7 years
- [APPOS]: The display of Agent Version is not consistent in the UI
- Toolbars have different paddings in Cloud Proxies and Integrations pages
- Need to include hsqldb related more files to support bundle
- Appropriate memory should be set to services
- [REST API]: update swagger samples for addProperty APIs
- Automation Central: Last Day Scheduled Job Not Working in "Daily" Recurrence
- Fix Ownership of Dynamic AI Credentials Created at Runtime by Parent AIs
- [Views]: remove obsolete transformations from Alert view
- Filtering by "Collector" doesn't work correctly in the Accounts page
- Add "Updated On" column in UI for Symptoms and Events
- Resource shard binding slow performance at resource creation
- Postgres health check result is missing from support bundle
- [Infra Health] OOTB dashboard fails to load with timeout exception
- Management Pack uninstall fails, if any Cloud Proxy task send fails
- [Platform]: incorrect collection state if exception from OnCollect
- ConcurrentModificationException in PropertyCacheMap
- [App Monitoring] Custom scripts instances appearing and disappearing in "Manage Telegraf Agents" page after an instance deletion during 5 collection cycles
- Inconsistency in Collection Status Page
- Telegraf agent installation showing invalid message while failing due to permissions issue
- The report is rendered empty when the report template contains a dashboard containing the "Metric Chart" widget with multiple charts
- [APPOS]: Filter is not functioning when searching for 'Agent not Installed' state
- Change the icons in Drag&Drop message box.
- "POST /internal/integrations/vcenters" API throws NullPointerException in case of collectorID
- [APP Monitoring] : vROPS Large Environment - The activation request for the application plugin is not being triggered.
- [APP Monitoring] : vROPS Large Environment - Unbootstrap operation takes 5 mins to complete for 1 VM
- Global Search not working with error "Unable to expand object path"
- Chargeback: Automate the steps for plugin re-registering
- Problem to Disable/Enable HA, Make Shard Rebalance or Download generated Reports on vROps 8.17 version
- [AWLP] [Backend] vRA calls, to get the advanced workload placement plan from vROps, fail on vROps side
- [WLP] [vSAN] During the Workload Optimization, the VM vSAN compatibility check calls are failing, when the endpoint vCenter version is 8.0 U2 and higher
- [Recent Tasks] "Source Host" and "Destination Host" column data is incorrect for the WLP task VMs, when the datastore configuration is Shared Datastore
- Unsafe Deserialization in vcops analyics service
- Custom property: Internal server Error is thrown on alerts timeline in the described case
- [Resources API Call] All resources in API response have resourceHealth and Value are GREY and -1 respectively on 8.17.x vROPs
- Chargeback: VCD Adapter: The VCD Adapter Object relationship is not reset when deleting objects from vRops
- Remove pdf bottom margin from pdf Reports cover page
- Rest API: Pricing settings: Quad Large is not returned via API
- Having "\" and other JSON special characters in notification template leads to invalid JSON payload.
- [VCF] [NSX] During the VCF cloud account registration the NSXT instance validation is failing, when the NSX is shared on that workload domain
- SNMP Trap Plugin: Multilingual Support for SNMP Trap Plugin
The following CVEs have been resolved as of VMware Aria Operations 8.18:
Note: Inclusion of a given CVE in the following table does not imply exploitability of said CVE.
Component Name |
CVE |
chromium |
CVE-2024-2400 |
CVE-2024-2625 |
CVE-2024-2626 |
CVE-2024-2627 |
CVE-2024-2628 |
CVE-2024-2629 |
CVE-2024-2630 |
CVE-2024-2631 |
CVE-2024-2883 |
CVE-2024-2885 |
CVE-2024-2886 |
CVE-2024-2887 |
CVE-2024-3156 |
CVE-2024-3157 |
CVE-2024-3158 |
CVE-2024-3159 |
CVE-2024-3515 |
CVE-2024-3516 |
CVE-2024-3832 |
CVE-2024-3834 |
CVE-2024-3838 |
CVE-2024-3839 |
CVE-2024-3840 |
CVE-2024-3841 |
CVE-2024-3843 |
CVE-2024-3844 |
CVE-2024-3845 |
CVE-2024-3846 |
CVE-2024-3847 |
CVE-2024-3914 |
CVE-2024-4058 |
CVE-2024-4059 |
CVE-2024-4060 |
CVE-2024-4331 |
CVE-2024-4368 |
CVE-2024-4559 |
CVE-2024-4761 |
CVE-2024-4947 |
CVE-2024-4948 |
CVE-2024-4949 |
CVE-2024-4950 |
CVE-2024-6291 |
com.fasterxml.woodstox:woodstox-core |
CVE-2022-40152 |
containerd |
CVE-2022-23471 |
CVE-2023-25153 |
CVE-2023-25173 |
dhcp |
CVE-2021-25217 |
libarchive |
BDSA-2021-2769 |
CVE-2023-30571 |
liblzo2 |
BDSA-2019-0204 |
linux_kernel |
CVE-2021-32078 |
CVE-2021-33061 |
CVE-2021-46970 |
CVE-2021-46987 |
CVE-2021-47028 |
CVE-2021-47070 |
CVE-2021-47076 |
CVE-2021-47094 |
CVE-2021-47101 |
CVE-2021-47105 |
CVE-2021-47125 |
CVE-2021-47135 |
CVE-2021-47140 |
CVE-2021-47182 |
CVE-2021-47183 |
CVE-2021-47188 |
CVE-2021-47199 |
CVE-2021-47200 |
CVE-2021-47205 |
CVE-2021-47211 |
CVE-2021-47212 |
CVE-2022-0480 |
CVE-2022-27672 |
CVE-2022-3344 |
CVE-2022-3523 |
CVE-2022-48628 |
CVE-2022-48633 |
CVE-2022-48645 |
CVE-2022-48646 |
CVE-2022-48666 |
CVE-2022-48673 |
CVE-2022-48698 |
CVE-2022-48699 |
CVE-2022-48703 |
CVE-2023-0597 |
CVE-2023-23586 |
CVE-2023-52476 |
CVE-2023-52479 |
CVE-2023-52480 |
CVE-2023-52481 |
CVE-2023-52506 |
CVE-2023-52530 |
CVE-2023-52531 |
CVE-2023-52561 |
CVE-2023-52565 |
CVE-2023-52568 |
CVE-2023-52569 |
CVE-2023-52572 |
CVE-2023-52608 |
CVE-2023-52621 |
CVE-2023-52633 |
CVE-2023-52639 |
CVE-2023-52652 |
CVE-2023-52660 |
CVE-2023-52664 |
CVE-2023-52666 |
CVE-2023-52674 |
CVE-2023-52677 |
CVE-2023-52680 |
CVE-2023-52682 |
CVE-2023-52824 |
CVE-2024-0564 |
CVE-2024-26639 |
CVE-2024-26650 |
CVE-2024-26654 |
CVE-2024-26668 |
CVE-2024-26669 |
CVE-2024-26676 |
CVE-2024-26686 |
CVE-2024-26687 |
CVE-2024-26700 |
CVE-2024-26706 |
CVE-2024-26718 |
CVE-2024-26726 |
CVE-2024-26745 |
CVE-2024-26765 |
CVE-2024-26769 |
CVE-2024-26774 |
CVE-2024-26780 |
CVE-2024-26789 |
CVE-2024-26792 |
CVE-2024-26798 |
CVE-2024-26803 |
CVE-2024-26810 |
CVE-2024-26812 |
CVE-2024-26813 |
CVE-2024-26814 |
CVE-2024-26821 |
CVE-2024-26828 |
CVE-2024-26830 |
CVE-2024-26844 |
CVE-2024-26865 |
CVE-2024-26886 |
CVE-2024-26893 |
CVE-2024-26896 |
CVE-2024-26905 |
CVE-2024-26915 |
CVE-2024-26921 |
CVE-2024-26923 |
CVE-2024-26938 |
CVE-2024-26954 |
CVE-2024-26981 |
CVE-2024-26984 |
CVE-2024-26993 |
CVE-2024-26994 |
CVE-2024-26996 |
CVE-2024-26999 |
CVE-2024-27000 |
CVE-2024-27001 |
CVE-2024-27002 |
CVE-2024-27004 |
CVE-2024-27008 |
CVE-2024-27019 |
CVE-2024-27034 |
CVE-2024-27035 |
CVE-2024-27037 |
CVE-2024-27054 |
CVE-2024-27389 |
CVE-2024-27393 |
CVE-2024-27437 |
CVE-2024-35803 |
CVE-2024-35817 |
CVE-2024-35818 |
CVE-2024-35839 |
CVE-2024-35840 |
CVE-2024-35844 |
CVE-2024-35923 |
CVE-2024-35941 |
CVE-2024-35965 |
lzo |
BDSA-2019-0204 |
net-snmp |
BDSA-2004-0008 |
org.apache.tomcat:tomcat-util |
CVE-2016-6817 |
CVE-2017-5650 |
CVE-2017-5651 |
CVE-2017-7675 |
CVE-2019-0199 |
CVE-2019-10072 |
CVE-2020-11996 |
CVE-2020-13943 |
CVE-2021-25122 |
CVE-2021-33037 |
CVE-2021-41079 |
CVE-2021-43980 |
CVE-2022-25762 |
CVE-2022-42252 |
CVE-2023-24998 |
CVE-2023-28708 |
CVE-2023-41080 |
CVE-2023-42795 |
CVE-2023-44487 |
CVE-2023-45648 |
CVE-2023-46589 |
org.bouncycastle:bcprov-jdk15on |
CVE-2024-30172 |
org.springframework:spring-core |
CVE-2023-20863 |
CVE-2024-22243 |
CVE-2024-22259 |
CVE-2024-22262 |
org.yaml:snakeyaml |
CVE-2017-18640 |
CVE-2022-1471 |
CVE-2022-25857 |
CVE-2022-38749 |
CVE-2022-38750 |
CVE-2022-38751 |
CVE-2022-38752 |
CVE-2022-41854 |
v8 |
CVE-2022-0457 |
CVE-2022-1096 |
CVE-2022-1134 |
CVE-2022-1314 |
CVE-2022-1364 |
CVE-2022-1869 |
CVE-2022-3045 |
CVE-2022-3723 |
CVE-2022-4262 |
CVE-2022-4906 |
CVE-2023-0696 |
CVE-2023-1214 |
CVE-2023-2724 |
CVE-2023-3079 |
CVE-2023-3216 |
CVE-2023-3420 |
CVE-2023-4352 |
CVE-2023-4355 |
CVE-2023-4762 |
CVE-2023-6702 |
CVE-2024-2625 |
CVE-2024-3156 |
CVE-2024-3159 |
CVE-2024-4059 |
CVE-2024-4947 |
CVE-2024-4949 |