vRealize Log Insight 4.8 Resolution for CVE-2020-3953, CVE-2020-3954
search cancel

vRealize Log Insight 4.8 Resolution for CVE-2020-3953, CVE-2020-3954

book

Article ID: 319589

calendar_today

Updated On:

Products

VMware Aria Suite

Issue/Introduction

CVE-2020-3953 and CVE-2020-3954 have been determined to affect vRealize Operations 4.8.

Environment

VMware vRealize Log Insight 4.8.x

Resolution

This issue is resolved in vRealize Log Insight 4.8 with the following security patch:
vRealize Log Insight 4.8 Security Patch

To apply the patch, complete the following.

Prerequisites

  • Create a snapshot or backup copy of the vRealize Log Insight virtual appliance.
  • Obtain a copy of the vRealize Log Insight upgrade bundle .pak file for the release you are upgrading to.  vRealize Log Insight 4.8 Hot Fix 3 can be downloaded here.
  • Verify that you are logged in to the vRealize Log Insight web user interface as a user with the Edit Admin permission. The URL format is https://log-insight-host, where log-insight-host is the IP address or host name of the vRealize Log Insight virtual appliance.
  • Make a note of any nodes you are upgrading that are in maintenance mode. When the upgrade is finished, you must move them from the state Connected to Maintenance mode.
 

Procedure

  1. Click the configuration drop-down menu icon  and select Administration.
  2. Under Management, click Cluster.
  3. Click Upgrade from PAK to upload the .pak file.
  4. Accept the new EULA to complete the upgrade procedure.
 

What to do next

  • After the primary node upgrade process is complete, you can view the remaining upgrade process, which is automatic.
  • Check for the email sent to the Admin to confirm the upgrade completed successfully.
  • After upgrade, all nodes are brought online even if they were in maintenance mode before the upgrade. Move these nodes back to maintenance mode as needed.


Additional Information

See VMSA-2020-0007.1 for more information.