This patch (CSP-93316) has been superseded and is no longer available. Please install the latest cumulative update, CSP-102092, by following the instructions in KB 412021.
This article provides information on a previous patch (CSP-93316) that upgraded the Java version to fix the security vulnerabilities listed below.
CVE-2024-20918, CVE-2024-20919, CVE-2024-20921, CVE-2024-20926, CVE-2024-20932, CVE-2024-20945, CVE-2024-20952
Snapshots/Backups: It is strongly recommended to take a snapshot or backup of the appliance(s) and the database server before proceeding.
sshuser and elevate to the root user with sudo su -.CSP-93316-Appliance-3.3.7.zip file to a temporary location on the appliance.unzip CSP-93316-Appliance-3.3.7.zip -d CSP-93316-Appliance-3.3.7
cd CSP-93316-Appliance-3.3.7/CSP-93316-Appliance-3.3.7/
./CSP-93316-applyPatch.sh
Note: For a clustered deployment, repeat the steps above on all additional nodes sequentially.
After the patch deployment, perform the following steps to confirm it was applied successfully:
ls /usr/local/horizon/conf/flags/CSP-93316-3.3.7-hotfix.applied
https://<vidm-hostname>:8443.3.3.7.0 Build 23103647.