Translation Notice
Please note that this content includes text that has been machine-translated from English. Veritas does not guarantee the accuracy regarding the completeness of the translation. You may also refer to the English Version of this knowledge base article for up-to-date information.
NetBackup Appliance 5.3.0.1 Maintenance Release 1 Security Patch 2
Abstract
Description
NetBackup Appliance 5.3.0.1 Maintenance Release 1 Security Patch 2 is a package of security fixes specific to NetBackup Appliance 5.3.0.1 Maintenance Release 1 (5.3.0.1 MR1) and 5.3.0.1 Maintenance Release 1 Security Patch 1 (5.3.0.1 MR1 SP1).
5.3.0.1 MR1 SP2 can be installed only on NetBackup Appliance 5.3.0.1 MR1 and 5.3.0.1 MR1 SP1.
5.3.0.1 MR1 SP2 includes all fixes included in NetBackup Appliance 5.3.0.1 MR1 SP1.
By installing 5.3.0.1 MR1 SP2 on NetBackup Appliance 5.3.0.1 MR1, the appliance is upgraded directly to 5.3.0.1 MR1 SP2 in a single upgrade step, without first upgrading to 5.3.0.1 MR1 SP1.
Overview
NetBackup Appliance Maintenance Release 1 Security Patch 2 (henceforth also referred as 5.3.0.1 MR1 SP2) is a package of security fixes for 5.3.0.1 Maintenance Release 1 (5.3.0.1 MR1) and 5.3.0.1 Maintenance Release 1 Security Patch 1 (5.3.0.1 MR1 SP1). It is strongly recommended to install 5.3.0.1 MR1 SP2 on NetBackup Appliance 5.3.0.1 MR1 and 5.3.0.1 MR1 SP1 as quickly as possible to keep the NetBackup Appliances secure and operating efficiently.
Description
NetBackup Appliance 5.3.0.1 MR1 SP2 is a package of security fixes for NetBackup Appliance 5.3.0.1 MR1 and 5.3.0.1 MR1 SP1.
5.3.0.1 MR1 SP2 can be installed only on NetBackup Appliance 5.3.0.1 MR1 and 5.3.0.1 MR1 SP1.
5.3.0.1 MR1 SP2 includes all fixes included in NetBackup Appliance 5.3.0.1 MR1 SP1.
By installing 5.3.0.1 MR1 SP2 on NetBackup Appliance 5.3.0.1 MR1, the appliance is upgraded directly to 5.3.0.1 MR1 SP2 in a single upgrade step, without first upgrading to 5.3.0.1 MR1 SP1.
5.3.0.1 MR1 SP2 includes fix for the critical vulnerability affecting the crewjam/saml Go library. (CVE-2022-41912).
5.3.0.1 MR1 SP2 is supported on NetBackup 5240, 5250, 5340, 5340HA, 5350, 5350HA appliances.
A media server appliance with 5.3.0.1 MR1 SP2 installed is compatible with the primary server running NetBackup 10.3 or later release.
Customers can download 5.3.0.1 MR1 SP2 (VRTS_NBAPP_update-MR1-SP2-5.3.0.1-20240513020202.x86_64.rpm) from the following Veritas Download Center link: https://www.veritas.com/content/support/en_US/downloads/update.UPD824573
Appliance Management Server (AMS) Support
5.3.0.1 MR1 SP2 installation is supported with AMS 2.2.
Note:
- High Availability (HA) upgrade is not supported via AMS 2.2
NetInsights / System Health Insights (NI/SHI) Support
Upgrade via NetInsights / System Health Insights (NI/SHI) is not supported for 5.3.0.1 MR1 SP2.
Installation Time
Upgrading to 5.3.0.1 MR1 SP2 takes about 50 minutes per node including rebooting.
Pre-Installation steps
For installation on primary server
- Confirm that no backup jobs are scheduled during the upgrade period.
- Deactivate all policies to ensure no backups will target the appliance being upgraded.
- Cancel all active jobs from the NetBackup Java Administration Console or log in to the appliance as a NetBackupCLI user and run the following command: bpdbjobs –cancel
- Disable all reporting and monitoring tools using this server (OpsCenter, Aptare / NetBackup IT Analytics or other 3rd party tool).
For installation on media server
- Deactivate all policies to ensure no backups will target the appliance being upgraded.
- Cancel all active jobs running on the target appliance.
- Disable all Storage Life Cycle Policies that duplicate to/from the appliance on which 5.3.0.1 MR1 SP2 is being installed.
If there are SAN devices connected to the appliance, it is recommended to disable the SAN switch port before starting the upgrade to avoid potential long reboot times.
Installation Instructions
Before installing 5.3.0.1 MR1 SP2, note the following:
- Refer to the following article for installation instructions: https://www.veritas.com/support/en_US/article.100023444
- A reboot occurs automatically after installation.
- Installation requires IPMI connectivity to the appliance.
- If the installation is successful, an email notification is sent (if email notifications are configured) and the following message is broadcasted:
NetBackup Appliance has upgraded successfully!
Additional instructions for installing in a NetBackup Appliance 5340/5350 High Availability (HA) setup
Before installing 5.3.0.1 MR1 SP2 on both nodes, ensure that the two-node HA setup is fully configured. The HA status can be checked by using the following command:
Manage > HighAvailability > Status
If the status of HA services is not as follows, contact Veritas Support for assistance.
Ss | Status on Primary node | Status on Partner node |
---|---|---|
AdvancedDisk |
Online |
Online |
Fingerprint calculation |
Online |
Online |
MSDP |
Online |
Offline |
Virtual IP |
Virtual IP |
Offline |
For configuring a two-node HA setup, see the Veritas NetBackup Appliance High Availability Reference Guide.
Ensure that 5.3.0.1 MR1 SP2 is installed on a node only if it is offline. Refer to the following article for more information about how a node can be put in offline status:
- Install 5.3.0.1 MR1 SP2 on the partner node where the virtual IP is offline.
- Perform a switchover operation as per instructions given in the appliance prompt using the Manage > HighAvailability > Switchover command to bring the Virtual IP online on the node installed with 5.3.0.1 MR1 SP2.
- After the switchover, install 5.3.0.1 MR1 SP2 on the other node, where the virtual IP is now offline.
- Test the switchover to the original node to ensure correct functionality.
Post-Installation Instructions
The new installed version can be checked using either of the following commands.
(The expected output of each command is also listed)
Manage > Software > UpgradeStatus
The appliance version is 5.3.0.1 MR 1 SP 2 and not in upgrade state.
Manage > Software > List Version
Appliance Version: 5.3.0.1
NetBackup Version: 10.3.0.1
Build Date: 20240513020202
Maintenance Release Version: 1
Security Patch Version: 2
Appliance > Status
Appliance Model is NetBackup Appliance 5xxx.
Appliance Version is 5.3.0.1 MR 1 SP 2.
Vulnerabilities Fixed
5.3.0.1 MR1 SP2 fixes the following security vulnerabilities:
Security Risk |
Vulnerability id |
Critical |
CVE-2022-41912 |
High |
CVE-2023-28119, CVE-2023-34241, CVE-2023-50868, CVE-2023-50387, CVE-2023-28450, CVE-2022-48339, CVE-2022-48337, CVE-2023-3138, CVE-2023-40547, CVE-2023-3758, CVE-2024-31083, CVE-2024-31081, CVE-2024-31080, CVE-2024-1488 |
Medium |
CVE-2023-45683 (BDSA-2023-2813), CVE-2022-3094, CVE-2023-32324, CVE-2022-3287, CVE-2021-43618, CVE-2022-48624, CVE-2024-28834, CVE-2023-40551, CVE-2023-40550, CVE-2023-40549, CVE-2023-40548, CVE-2023-40546 |
Low |
CVE-2024-21094, CVE-2024-21068, CVE-2024-21012, CVE-2024-21011 |
Applies to the following product releases
Update files
|
File name | Description | Version | Platform | Size |
---|