RSCD Agent security vulnerability R2


BMC Software is alerting users to security vulnerabilities in RSCD Agents on all the platforms of versions 20.02.00 and 20.02.01 of TrueSight Server Automation.

If you have any questions about these vulnerabilities, contact  Customer Support.

December 5, 2022


Issues

The following RSCD Agent security vulnerabilities have been addressed in this hotfix:

Severity

Affected RSCD Agents 

Issue

High 

Windows and UNIX RSCD Agents

These previously fixed vulnerabilities got reintroduced in the product versions 20.02.00 and 20.02.01. This hotfix provides a fix for them.

We recommend that you immediately apply the hotfix as described in this topic.


Resolution

Download the hotfix required for your platform from the Patches tab of the following EPD website page and apply the hotfix. You must provide your BMC Support credentials to access the EPD website. You might also be prompted to complete the Export Compliance form.

EPD Download Link

Item name

File name

md5 checksum

Build number

TSSA 20.02.00 Server Automation [x64] RSCD Agent Hotfix 2

RSCD_SecurityFixes_20-02_HF2_V1.zip

e66ff507e4f260902b772251433b878b

20.02.00.44

TSSA 20.02.01 Server Automation [x64] RSCD Agent Hotfix 2

RSCD_SecurityFixes_20-02-01_HF2_V1.zip

7cf1e5cd1c8ead490bc9215b158f2416

20.02.01.130

Applying the hotfix

Depending on your requirements, apply the hotfix as described in the following sections:

Applying the hotfix to the standalone RSCD Agents

Upgrade the standalone existing RSCD Agents or install them.

 Upgrading an existing RSCD Agent that is installed on a target server

  1. Download and extract the RSCD_SecurityFixes_<version>_HF2_V1.zip file to a temporary directory.

    The extracted directory contains the TSSA<version>-RSCDAgents.zip file.

  2. Extract the TSSA<version>-RSCDAgents.zip file.

    The extracted directory contains the RSCD Agent installers (RSCD<version>-<platform>).

  3. Use one of the following methods to upgrade the RSCD Agent:
  4. If any of the Configuration Objects (COs) are missing after upgrade, distribute the COs again. For more information, see Creating-or-modifying-Distribute-Configuration-Objects-Jobs.

Installing (fresh) an RSCD Agent on a target server

  1. Download and extract the RSCD_SecurityFixes_<version>_HF2_V1.zip file to a temporary directory.

    The extracted directory contains TSSA<version>-RSCDAgents.zip.

  2. Extract the TSSA<version>-RSCDAgents.zip file.

    The extracted directory contains the RSCD Agent installers (RSCD<version>-<platform>).

  3. Use one of the following methods to install the RSCD Agent:

Applying the hotfix to the RSCD Agents installed on Application Servers and Repeaters

Depending on the platform, use the instructions described in one of the following tabs:

  1. Download and extract the RSCD_SecurityFixes_<version>_HF2_V1.zip file to a temporary directory.

    The extracted directory contains TSSA<version>-RSCDAgents.zip.

  2. Extract the TSSA<version>-RSCDAgents.zip file.

    The extracted directory contains the RSCD Agent installers ( TSSA<version>-RSCDAgents/ rscd/windows_64). 

  3. Use one of the following methods to upgrade the RSCD Agent on the Windows Application Server or Windows Repeater:
  4. If any of the Configuration Objects (COs) are missing after upgrade, distribute the COs again. For more information, see Creating-or-modifying-Distribute-Configuration-Objects-Jobs.
  1. Download and extract the RSCD_SecurityFixes_<version>_HF2_V1.zip file to a temporary directory.

    The extracted directory contains TSSA<version>-RSCDAgents.zip file and the Linux_Appserver_NSH directory.

  2. Do the following steps to upgrade the RSCD Agent on an Application Server:
    1. Copy and extract the /tmp/RSCD_SecurityFixes_<version>_HF2_V1 /Linux_Appserver_NSH/ RU3.zip file to temporary directory (for example /tmp1) on the Application Server.
    2. From the RU3 directory, execute the rollingUpdateInstaller.sh script by using the following command in shell terminal:

      sh rollingUpdateInstaller.sh

      The following message is displayed when the installation completes successfully and the logs also generated in same location.

      #### Rolling Update Completed Successfully #### 

    3. Repeat the steps a to c on every Application Server one by one.

      Error
      Warning

      Do not execute the steps on all Application Servers parallelly.

  3. If any of the Configuration Objects (COs) are missing after upgrade, distribute the COs again. For more information, see Creating-or-modifying-Distribute-Configuration-Objects-Jobs.

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*

TrueSight Server Automation 20.02