This article provides important information for upgrading the Photon OS version to fix the below vulnerabilities.
List of affected version
Product Component |
Version(s) |
Applicable CVE(s) |
VMware Identity Manager Appliance |
3.3.7 |
CVE-2023-45853 CVE-2024-24806 |
VMware Identity Manager 3.3.x
Before You Begin:
Patch Deployment Procedure:
CSP-95247-Appliance-3.3.7.zip
" to the virtual appliance. This zip file can be saved anywhere on the file-system.VMware recommends SCP protocol to transfer the file to the appliance. Tools such as winscp can also be used to transfer the file to the appliance. unzip CSP-95247-Appliance-3.3.7.zip -d CSP-95247-Appliance-3.3.7.zip
cd CSP-95247-Appliance-3.3.7.zip
./CSP-95247-applyPatch.sh
Note: If you are running a cluster deployment, repeat the steps above on all additional nodes of the cluster.
Patch Deployment Validations:
After the patch deployment, perform below steps to confirm patch is applied successfully.
/usr/local/horizon/conf/flags
directory. "https://<vidm-ostname>:8443"
Note:
Product Component |
Version |
VMware Identity Manager Appliance |
3.3.7 |
Note : This is a cumulative patch and this will perform a installation other patches including CSP-93316,CSP-91401,CSP-90495
Related Information:
To revert this patch, you can revert to the appliance(s) snapshot and the database backup taken before applying these steps.
This article was created as per Product Management Team request to patch affected VMware Identity Manager