VMware good2know [28.10.2024]

Newsletter

Release Notes

ProductVersionRelease DateRelease Notes
vCenter Server
(VMSA-2024-0019.2)
7.0 u3t10/21/24Release Notes
vCenter Server
(VMSA-2024-0019.2)
8.0 u2e10/21/24Release Notes
vCenter Server
(VMSA-2024-0019.2)
8.0 u3d10/21/24Release Notes
#Release Notes

VCF BOM

ProductVersionRelease DateBuild NumberRelease Notes
Cloud Builder VM5.2.110/0924307856Release Notes
SDDC Manager5.2.110/0924307856Releae Notses
vCenter Server8.0 u3c10/0924305161Release Notes
VMware ESXi8.0 u3b09/1724280767Release Notes
vSAN Witness8.0u3b09/1724280767Release Notes
NSX4.2.110/0924304122Release Notes
Aria Suite Lifecycle8.1807/2324029603Release Notes
# VCF 5.2.1  BOM (current Version) [Release Notes]

Security Advisory

VMSA-2024-0021 [HIGH][HCX][CVSSv3: 8.8]

CVE(s)

  • Authenticated SQL injection in VMware HCX (CVE-2024-38814)
  • VMware NSX local privilege escalation vulnerability (CVE-2024-38818) 
  • VMware NSX content spoofing vulnerability (CVE-2024-38815) 

Description:
VMware HCX contains an authenticated SQL injection vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.8. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perform unauthorized remote code execution on the HCX manager. To remediate CVE-2024-38814 apply the patches listed in the ‚Fixed Version‘ column of the ‚Response Matrix‘ found below. VMware would like to thank Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) working with Trend Micro Zero Day Initiative (ZDI) for reporting this issue to us.

Response Matrix:

VersionCVEFixed VersionWorkaround
4.10.xCVE-2024-388144.10.1None
4.9.xCVE-2024-388144.9.2None
4.8.xCVE-2024-388144.8.3None
VMSA-2024-0021 [HIGH][HCX][CVSSv3: 8.8]

Knowledge Base Article

SubjectKB Article
VMware Aria Operations upgrade from 8.17 to 8.18.1 fails with the error “error: Failedresource key=pak_manager.action_failed, resource args=[run sql db upgrade]“380654
Migration/Downtime for Aria Operations for Networks Appliance Registration server380652
Reconnecting a failed host Returns the error „Credentials for host need to be specified“380641
Can’t enable vSAN Performance Service on a new vSAN cluster380597
VM vNIC in disconnected state from VC UI.380565
SCSI Host Status H:0x7 observed in the vmkernel logs380530
NSX Manager reports Node Agent is down380524
ESXi hosts disconnecting after changing IP address of vCenter380515
Creating a segment on the NSX-T Manger is it not displayed on vCenter380490
Dynatrace shows following warning: VMware ESX server availability less than 90%380471
VMware Identity Manager: where there is a large number of psql database timeout errors waiting for the DC to respond, the vIDM system may be unable to provide authentication for users.380427
ESXi Host Domain Join Fails with LW_ERROR_DOMAIN_IS_OFFLINE Error380409
NCP authentication fails when using a complex password. Error: Authentication Failed: Empty Password380369
Unable to collect metrics for F5 BIG IP load balancer in Aria Operations for Networks.380345
During the update of vSAN Witness host, the files cannot be downloaded to the host380311
Unexpected reboot of ESXi hosts380152
Unable to remove missing resources from the deployment.380143
How to manage vSphere replication solution in cluster image manually380129
How to prevent passwords leaking when using pillar data of salt.
380125
VMware vCenter Converter Standalone xfs filesystem options support380112
Flow metrics in Aria Operations for Networks are showing unexpected values in Terabytes/Petabytes380107
Credential in Aria Operations cannot be edited380100

Schreibe einen Kommentar

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert