Release Notes for ExtremeSecurity V7.7.2.8 Patch 7

Extreme Networks is pleased to introduce the ExtremeSecurity V7.7.2.8 Patch 7.

Note

Note

We recommend that you review this document prior to installing or upgrading this product.

About this Patch

ExtremeSecurity V7.7.2.8 Patch 7 resolves 17 field issues reported from users and administrators. Before installing this update, there are important several changes that administrators should be aware of:
  • TLSv1 is disabled in ExtremeSecurity V7.7.2.8 Patch 7. This change was originally completed in QRadar 7.3.0 and has been ported to the ExtremeSecurity V7.7.2.8 software stream as of V7.7.2.8 Patch 7. This means that Tomcat will no longer listen and actively refuse browser connections using TLSv1.0 after updating to ExtremeSecurity V7.7.2.8 Patch 7. Browsers will be required to use TLSv1.1 or TLSv1.2 to authenticate to ExtremeSecurity SIEM. This should only impact users with older or legacy browsers.
  • The installation of ExtremeSecurity V7.7.2.8 Patch 7 updates the Java version to Java 8.
  • The Master Console v0.10.0 or v0.11.0 is not supported on ExtremeSecurity V7.7.2.8 Patch 7, ExtremeSecurity V7.7.2.8 Patch 8, or ExtremeSecurity V7.7.2.8 Patch 9 due to changes made with Java 8 and TLSv1.0 connections as described above. Administrators who require the Master Console should not upgrade to a version above ExtremeSecurity V7.7.2.8 Patch 6.

Fix packs are cumulative software updates to fix known software issues in your ExtremeSecurity deployment. ExtremeSecurity fix packs are installed by using an SFS file. The fix pack can update all appliances attached to the ExtremeSecurity Console. If your deployment is installed with any of the following ExtremeSecurity versions, you can install fix pack 7.2.8-QRADAR-QRSIEM-20170530170730 to upgrade to ExtremeSecurity V7.7.2.8 Patch 7.

Note

Note

The 7.2.8-QRADAR-QRSIEM-20170530170730 fix pack can upgrade ExtremeSecurity 7.7.2.4 (7.2.4.983526) and later to the latest software version. However, this document does not cover all of the installation messages and requirements, such as changes to memory requirements or browser requirements for ExtremeSecurity. To review any additional requirements, see the ExtremeSecurity Upgrade Guide. If you are on a version of ExtremeSecurity earlier than 7.7.2.4, you must upgrade to 7.7.2.4 before proceeding to 7.7.2.8.
Note

Note

A ExtremeSecurity V7.7.2.8 ISO is available on IBM Fix Central for administrators who to want to install a new appliance or virtual machine. Administrators who want to complete a new install need to review the ExtremeSecurity Installation Guide.

Resolved Issues

Note

Note

Some APAR links in the table below might take 24 hours to display properly after a software release.
Number Description
SECURITY BULLETIN IBM JAVA AS USED IN IBM EXTREMESECURITY SIEM IS VULNERABLE TO MULTIPLE CVES
IV84643 USERNAMES CONTAINING A ' . ' ARE TRUNCATED IN USER LOGINSIM AUDIT-2 EVENTS
IV86288 SOME EXTREMESECURITY SERVICES CAN FAIL TO START AFTER A 'DEPLOY FULL CONFIGURATION' IS PERFORMED
IV87510 REALTIME STREAMING CAN FAIL TO DISPLAY EVENTS WHEN FILTERING ON EVENTPROCESSOR
IV90889 DASHBOARD ITEM CAN SOMETIMES DISPLAY NO DATA IN SOME INSTANCES OF NETWORK HIERARCHY CONTAINING DOUBLE BYTE CHARACTERS
IV93256 EXTREMESECURITY RISK MANAGER PATH SEARCH CAN FAIL TO COMPLETE WHEN A SOURCEFIRE IPS EXISTS IN THE TOPOLOGY
IV93607 EXTREMESECURITY HOSTS RUNNING ON AMAZON WEB SERVICES (AWS) CAN FAIL TO UPGRADE TO QRADAR 7.2.8 DUE TO A MISSING DEPENDENCY
IV93948 'GENERAL FAILURE' ERROR WHEN PERFORMING SEARCHES AGAINST NUMERIC REFERENCE SET DATA
IV94508 POSTGRES DEADLOCKS CAN SOMETIMES LEAD TO SEARCH DATA RESULT INCONSISTENCY
IV94511 CONTENT PACK INSTALLATION CONTAINING SENSORPROTOCOLS CAN FAIL IF THE ID IS ALREADY IN THE SENSORPROTOCOL TABLE
IV94782 EXTREMESECURITY LOGGING REPORTS HOSTCONTEXT '...TOO MANY OPEN FILES' MESSAGES
IV94873 FLOW COLLECTOR APPLIANCES (12XX/13XX) WITH MULTI-THREADING ENABLED CAN STOP COLLECTING FLOWS AFTER PATCHING
IV95105 REPORTS CREATED FROM VULNERABILITY SCAN PROFILES CAN SOMETIMES BE BLANK
IV95106 REPORT DATA CAN DIFFER FROM SEARCH DATA DUE TO ACCUMULATOR ROLLUP FAILURE
IV95109 DSM EDITOR PREVIEW FUNCTION DOES NOT DISPLAY WHEN USING JAPANESE LOCALE
IV95242 PERFORMING A 'PATCH ALL' CAN DISPLAY MESSAGE 'THE FOLLOWING MANAGED HOSTS ARE NOT ACCESSIBLE VIA SSH...'
IV96155 NETWORK ACTIVITY EXPORT CAN FAIL WTIH ERROR 'THERE WAS A PROBLEM COMPLETING YOUR REPORT. PLEASE TRY AGAIN LATER.'
IV96294 EXTREMESECURITY NETWORK INSIGHT APPLIANCE NETWORK INTERFACE(S) CAN FAIL TO START/LOAD