This article provides instructions for upgrading VMware Identity Manager 3.3.7 to the CSP-102547 patch. It also covers the subsequent installation of VMware Aria Suite Lifecycle 8.18 Patch 6, which is a required step after patching Identity Manager.
Applying these patches addresses known issues, improves security, and enhances system stability.
Before proceeding, you must complete the following prerequisites to ensure a successful patch process and prevent service interruptions.
If the patch installation fails, collect log bundles from vIDM and Aria Suite Lifecycle Manager before reverting to snapshots, as reverting removes failure details to analyze the issue.
Table of Contents |
Note: This is a cumulative patch and will apply all previous fixes if they are not already installed.
Deployment Type Instructions
Patching Steps (perform on each node)
sudo su -
3. Download the CSP-102547-Appliance-3.3.7-Patch.zip file and transfer it to the appliance (e.g., into a /db/vidm-upgrade folder) using SCP or WinSCP.
4. Unzip the patch file:
unzip CSP-102547-Appliance-3.3.7-Patch.zip
5. (Optional) Clean up the zip file to reclaim space:
rm -f CSP-102547-Appliance-3.3.7-Patch.zip
6. Change to the patch directory:
cd CSP-102547-Appliance-3.3.7-Patch
7. Run the patch automation script:
./CSP-102547-patch-automation.sh -f CSP-102547-Appliance-3.3.7.zip -r
8. The system will reboot automatically after the patch installation is complete.
IMPORTANT: VMware Identity Manager services will not be operational until VMware Aria Suite Lifecycle 8.18 Patch 6 is also applied.
cd /data
chmod +x prep-for-upgrade-lcm.sh
./prep-for-upgrade-lcm.sh
2. (If upgrading from Patch 3 to Patch 6) Delete temporary folders from previous patch attempts by running the following commands:
rm -r /data/tmp-patch-8180
rm -r /data/tmp-patch-10318114
rm -r /data/tmp_patch_storage
3. Download the vrslcm-8.18.0-Patch6.patch patch from the Broadcom Support Portal:
4. Copy the downloaded patch file to the /data directory on the Aria Suite Lifecycle appliance.
5. Map the patch binary in the UI. Navigate to Lifecycle Operations > Settings > Binary Mapping and click Patch Binaries.
6. Install the patch. Navigate to Lifecycle Operations > Settings > System Patches and click Install Patch.
7. Wait for the installation to complete. The process takes approximately 20 minutes and will conclude with the appliance rebooting.
8. After the appliance reboots, log in to the VMware Aria Suite Lifecycle UI, navigate to the About page, and verify that the version is listed as 8.18.0 Patch 6.
9. SSH to the appliance and check the Photon OS version. Note that the build number will not change if you are patching from Patch 3 to Patch 6.
10. (VIDM Cluster Only) Patch Postgres Cluster in Aria Suite Lifecycle.
Logs to Monitor
You can monitor the progress of the patch installation by tailing the following log files on the Aria Suite Lifecycle appliance:
/var/log/vrlcm/os-package-update.log
/var/log/vrlcm/patchcli.log
Known Issue: /tmp Directory Space
Potential Issue
During the installation, you may encounter an error with code LCMPATCHUPDATE16002. This error indicates that there is not enough free space in the /tmp directory for the patch to be extracted.
If this occurs, please refer to KB 345990 for instructions on how to temporarily increase the space in the /tmp directory.
To revert this patch, restore the VMware Identity Manager appliance(s) and the Aria Suite Lifecycle appliance from the snapshots taken during the prerequisite phase.
Please review the attached file “CVEs_FIXED_CSP_102547.xlsx” for details of the CVEs that have been resolved in the current patch CSP-102547.
This cumulative update includes all fixes from the following previously released patches. For a detailed list of CVEs or components addressed by a specific patch, refer to its original knowledge base article.
| Patch ID | Summary of Fixes | Link |
|---|---|---|
| CSP-102092 | Addresses numerous security vulnerabilities in Photon OS and third-party components. | KB 412021 |
| CSP-99024 | Addresses numerous security vulnerabilities in Photon OS and third-party components. | KB 387748 |
| CSP-97727 | Upgrades Photon OS, Tomcat, and RabbitMQ to address vulnerabilities. | KB 380348 |
| CSP-97577 | Upgrades multiple platform components, including Java and Tomcat. | KB 404054 |
| CSP-96928 | Upgrades Photon OS, Tomcat, and RabbitMQ to address several vulnerabilities. | KB 377094 |
| CSP-95247 | Addresses two security vulnerabilities in Photon OS. | KB 373159 |
| CSP-93316 | Upgrades the Java version to address multiple vulnerabilities. | KB 369294 |
| CSP-91401 | Upgrades OpenSSH to fix CVE-2023-38408. | KB 327324 |
| CSP-90495 | Upgrades Angular XLTS to address licensing and CVEs. | KB 327323 |
| HW-189454 | Upgrades JQuery and Java versions to address multiple vulnerabilities. | KB 327326 |
| HW-170932 | Addresses VMSA-2023-0011 (CVE-2023-20884) and updates the connector. | KB 369609 |