Geneos 5.x Security Updates

Overview Copied

This page contains security updates for all Geneos 5.x releases. For the latest security updates, see Latest Geneos Security Updates.

To learn more about the supported Geneos versions and new features in the Geneos 5.x release, see the following documents:

Geneos 5.14.x Copied

Issue Key CVE Number CVE Severity Description Affected Components Fix Version
COL-12050 CVE-2024-29025 (BDSA-2024-0720) High The Netty library has been upgraded to 4.1.109.Final to address the security vulnerability: CVE-2024-29025 (BDSA-2024-0720). Netprobe Geneos 5.14.8
COL-12066 CVE-2023-0464 (BDSA-2023-0610), CVE-2023-0466 (BDSA-2023-0691), CVE-2023-0465 (BDSA-2023-0692), CVE-2023-2650 (BDSA-2023-1337), CVE-2023-3446 (BDSA-2023-1866), CVE-2023-3817 (BDSA-2023-1972), CVE-2023-4807 (BDSA-2023-2389) High Geneos components have been upgraded to OpenSSL version 1.1.1w to address the following security vulnerabilities:
  • CVE-2023-0464 (BDSA-2023-0610)
  • CVE-2023-0466 (BDSA-2023-0691)
  • CVE-2023-0465 (BDSA-2023-0692)
  • CVE-2023-2650 (BDSA-2023-1337)
  • CVE-2023-3446 (BDSA-2023-1866)
  • CVE-2023-3817 (BDSA-2023-1972)
  • CVE-2023-4807 (BDSA-2023-2389)
Netprobe Geneos 5.14.8
COL-12094 CVE-2023-6378 (BDSA-2023-3307), BDSA-2023-3341 Medium Logback has been updated to 1.3.14 to address the following security vulnerabilities:
  • CVE-2023-6378 (BDSA-2023-3307)
  • BDSA-2023-3341
Netprobe Geneos 5.14.8
COL-12113 CVE-2023-33202 (BDSA-2023-3254), CVE-2023-33201 (BDSA-2023-1625), BDSA-2024-2378 Medium The BouncyCastle dependency has been updated to 1.78.1 to address the following security vulnerabilities:
  • CVE-2023-33202 (BDSA-2023-3254)
  • CVE-2023-33201 (BDSA-2023-1625)
  • BDSA-2024-2378
Netprobe Geneos 5.14.8
COL-11350 CVE-2023-38545 Critical The libcurl version has been updated to version 8.5.0 to address the critical security vulnerability: CVE-2023-38545. Netprobe Geneos 5.14.7
COL-12023 CVE-2023-0286 (BDSA-2023-0226) High The Geneos components have been upgraded to OpenSSL version 1.1.t to address the security vulnerability: CVE-2023-0286 (BDSA-2023-0226). Netprobe Geneos 5.14.7
UTL-1267 BDSA-2019-4014 Minor The Apache Xerces C++ library has been upgraded to 3.2.5 to address the security vulnerability: BDSA-2019-4014. Netprobe Geneos 5.14.7

Disclaimer

The information contained in this document is for general information and guidance on our products, services, and other matters. It is only for information purposes and is not intended as advice which should be relied upon. We try to ensure that the content of this document is accurate and up-to-date, but this cannot be guaranteed. Changes may be made to our products, services, and other matters which are not noted or recorded herein. All liability for loss and damage arising from reliance on this document is excluded (except where death or personal injury arises from our negligence or loss or damage arises from any fraud on our part).
["Geneos"] ["Release Notes", "Upgrade Notes", "Security Updates"]

Was this topic helpful?