IMPORTANT:
What's New in This Patch:
If the patch installation fails, collect log bundles from vIDM and Aria Suite Lifecycle Manager before reverting to snapshots, as reverting removes failure details to analyze the issue.
Before proceeding, you must complete the following prerequisites to ensure a successful patch process and prevent service interruptions.
Note: This is a cumulative patch and will apply all previous fixes if they are not already installed.
'Rebooting system...' before moving to the next node.sshuser.sudo su -
/db/vidm-upgrade folder) using SCP or WinSCP.unzip CSP-102547-Appliance-3.3.7-Patch.zip
rm -f CSP-102547-Appliance-3.3.7-Patch.zip
cd CSP-102547-Appliance-3.3.7-Patch
./CSP-102547-patch-automation.sh -f CSP-102547-Appliance-3.3.7.zip -r
Example of Successful Console Output:
root@vidm-machine [ /db/CSP-102547-Appliance-3.3.7-Patch ]# 2026-01-20 05:16:57 - Checking Patch ZIP location, should not be at /db/data...
2026-01-20 05:16:57 - Patch ZIP location check passed: /db/CSP-102547-Appliance-3.3.7-Patch/CSP-102547-Appliance-3.3.7.zip
2026-01-20 05:16:57 - Disk space at /db/CSP-102547-Appliance-3.3.7-Patch: 14.38GB free
2026-01-20 05:16:57 - Disk space at /boot: 78MB free
2026-01-20 05:16:57 - All checks passed for ZIP '/db/CSP-102547-Appliance-3.3.7-Patch/CSP-102547-Appliance-3.3.7.zip'.
2026-01-20 05:16:57 - Running on node: vidm-machine
2026-01-20 05:16:57 - Checking grub2 presence
2026-01-20 05:16:57 - grub2 detected: /boot/grub2/grub.cfg exists
2026-01-20 05:16:57 - NOTE : Cluster size is displayed 0 , if prepare-vidm-patch.sh is run in a cluster
2026-01-20 05:16:57 - Cluster size detected: 1
2026-01-20 05:16:57 - Extracting patch bundle
Archive: CSP-102547-Appliance-3.3.7.zip
creating: CSP-102547-Appliance-3.3.7/
inflating: CSP-102547-Appliance-3.3.7/cleanup-rpms.sh
inflating: CSP-102547-Appliance-3.3.7/rabbitmq-server-3.12.4-2.ph3.noarch.rpm
inflating: CSP-102547-Appliance-3.3.7/CSP-102547-applyPatch.sh
inflating: CSP-102547-Appliance-3.3.7/prepare-vidm-patch.sh
inflating: CSP-102547-Appliance-3.3.7/rabbitmq-server-3.11.18-1.ph3.noarch.rpm
extracting: CSP-102547-Appliance-3.3.7/identity-manager-3.3.7.0-25163938-updaterepo.zip
2026-01-20 05:17:20 - Patch directory ready: CSP-102547-Appliance-3.3.7
2026-01-20 05:17:20 - Running patch script: CSP-102547-applyPatch.sh
2026-01-20 05:17:20 - Tail the log file /opt/vmware/var/log/update/vidm-CSP-102547-update.log for live logs..
2026-01-20 05:21:34 - Validating CSP-102547 patch status...
2026-01-20 05:21:34 - CSP-102547 Patch applied successfully and flag file /usr/local/horizon/conf/flags/CSP-102547-3.3.7.0-hotfix.applied is present.
2026-01-20 05:21:34 - CSP-102547-Appliance-3.3.7 directory cleanup complete
2026-01-20 05:21:34 - Rebooting system...
systemctl enable [email protected]
systemctl start [email protected]
IMPORTANT: VMware Identity Manager services will not be operational until VMware Aria Suite Lifecycle 8.18 Patch 7 is also applied.
(Optional step) You can monitor the progress of the patch installation by tailing the following log files on the Aria Suite Lifecycle appliance:
cd /var/log/vrlcm/
tail -f os-package-update.log patchcli.log
prep-for-upgrade-lcm.sh script (attached to the KB article) to the /data directory on the appliance and execute it:
cd /data
chmod +x prep-for-upgrade-lcm.sh
./prep-for-upgrade-lcm.sh
rm -r /data/tmp-patch-8180
rm -r /data/tmp-patch-10318114
rm -r /data/tmp_patch_storage
/data directory on the Aria Suite Lifecycle appliance./data) in the Source Location field and click Discover.cat /etc/photon-release
VMware Photon OS 5.0
PHOTON_BUILD_NUMBER=b9d98344d
/etc/init.d/opensearch status
/etc/init.d/opensearch start
Potential Directory Space Issue with /tmp:
LCMPATCHUPDATE16002. This error indicates that there is not enough free space in the /tmp directory for the patch to be extracted./tmp directory.https://<vidm-hostname>:8443) for full functionality.3.3.7.0 Build 25163938.To revert this patch, restore the VMware Identity Manager appliance(s) and the Aria Suite Lifecycle appliance from the snapshots taken during the prerequisite phase.
This cumulative update includes all fixes from the following previously released patches. For a detailed list of CVEs or components addressed by a specific patch, refer to its original knowledge base article.
| Patch ID | Summary of Fixes | Link |
|---|---|---|
| CSP-102092 | Addresses numerous security vulnerabilities in Photon OS and third-party components. | KB 412021 |
| CSP-99024 | Addresses numerous security vulnerabilities in Photon OS and third-party components. | KB 387748 |
| CSP-97727 | Upgrades Photon OS, Tomcat, and RabbitMQ to address vulnerabilities. | KB 380348 |
| CSP-97577 | Upgrades multiple platform components, including Java and Tomcat. | KB 404054 |
| CSP-96928 | Upgrades Photon OS, Tomcat, and RabbitMQ to address several vulnerabilities. | KB 377094 |
| CSP-95247 | Addresses two security vulnerabilities in Photon OS. | KB 373159 |
| CSP-93316 | Upgrades the Java version to address multiple vulnerabilities. | KB 369294 |
| CSP-91401 | Upgrades OpenSSH to fix CVE-2023-38408. | KB 327324 |
| CSP-90495 | Upgrades Angular XLTS to address licensing and CVEs. | KB 327323 |
| HW-189454 | Upgrades JQuery and Java versions to address multiple vulnerabilities. | KB 327326 |
| HW-170932 | Addresses VMSA-2023-0011 (CVE-2023-20884) and updates the connector. | KB 369609 |