VMware Aria Automation 8.16.2 through 8.18 updates for potential impact from CVE-2024-6387
search cancel

VMware Aria Automation 8.16.2 through 8.18 updates for potential impact from CVE-2024-6387

book

Article ID: 372561

calendar_today

Updated On:

Products

VMware Aria Suite

Issue/Introduction

  • VMware Aria Automation 8.16.2 through 8.18 are potentially impacted (ships with vulnerable versions of OpenSSH, but are 64-bit) to the issue reported in CVE-2024-6387. 

Environment

  • VMware Aria Automation 8.16.2
  • VMware Aria Automation 8.17
  • VMware Aria Automation 8.18
  • VMware Aria Automation Orchestrator 8.x

Cause

Resolution

Prerequisites

  • Ensure you have valid snapshots or backups of the Aria Automation appliance(s).

Procedure

  1. Download the following packages:
  2. Copy each file to each appliance in the cluster to the same folder such as /tmp.
  3. SSH into each appliance and run the following commands. Perform these steps once for each node:
    1. cd PathToRPMs
    2. rpm -U --nodeps openssh-clients-8.9p1-8.ph4.x86_64.rpm openssh-server-8.9p1-8.ph4.x86_64.rpm openssh-8.9p1-8.ph4.x86_64.rpm
    3. systemctl daemon-reload

Verification

  1. Run the following command to review the updated package:

rpm -qa | grep openssh

Expected Results:

openssh-clients-8.9p1-8.ph4.x86_64
openssh-server-8.9p1-8.ph4.x86_64
openssh-8.9p1-8.ph4.x86_64