20.02.02: Patch 2

This topic contains information about the updates in 20.02.02, Patch 2 for TrueSight Orchestration 20.02, and provides instructions for downloading and installing the patch.   

Updates

The following vulnerabilities are addressed in this patch: 

  • CVE-2021-44228
  • CVE-2021-4104
  • CVE-2022-23302
  • CVE-2019-17571
  • CVE-2020-9493
  • CVE-2022-23307
  • CVE-2022-23305
  • CVE-2020-9488

Downloading the patch

This patch contains a full installer. You can download the installation file from the BMC Electronic Product Downloads (EPD) Site. 

For more information, see Downloading the installation files

Installing the patch

If you are installing this patch as a fresh product installation, the process to install the patch is the same as installing any base version. 

For more information, see Installing – Classic mode.

Upgrading to the patch

You can upgrade to this patch from the following versions:

  • 8.2
  • 20.02.00
  • 20.02.01

For more information, see Upgrading.

Was this page helpful? Yes No Submitting... Thank you

Comments

  1. Scott Nelson

    Is there more detailed information about what this patch does in terms of which components are changed? For example, is log4j being upgraded and patched for the above listed vulnerabilities only or is there more to it?

    Mar 18, 2022 11:58
    1. Madhav Babaria

      Log4j-v1.x which was bundled as a Third party software in the product has been removed from TSO-Platform which helps address all the vulnerabilities associated to it.

      Mar 20, 2022 11:54
      1. Dan Curwin

        Does the product distribution include any version of Log4J now? If so, specifically what version?

        Mar 23, 2022 12:36
        1. Sonal Rajapurkar

          Hi Dan,

          The product distribution does not include Log4J. It has been replaced by Reload4J.

          Feb 28, 2024 05:00
  2. Daniel Bloom

    what is the next version? 20.02 seems to have been around for a while and goes out of support in 2023?

    Jun 06, 2022 09:36
    1. Dov Kaiser

      Hi, Daniel. Thank you for your interest in the next version. We are currently working on the next TSO platform release, version 22.2.00, expected to be released in the first quarter of the financial year 2023. 

      Jun 07, 2022 08:05