Sign In
Forgot Password

Don’t have an account? Create One.

NetBackup 8.1.2/3.1.2.0 Hotfix - NBA: Plugin: 84502 Vulnerability: HSTS Missing From HTTPS Server on Appliance (Etrack 4019187)

HotFix

Abstract

NBA: Plugin: 84502 Vulnerability: HSTS Missing From HTTPS Server on Appliance.

Description

Veritas Bug ID: ET 4019187

 

Issue: NBA: Plugin: 84502 Vulnerability: HSTS Missing From HTTPS Server on Appliance.

 

Version:  NetBackup 8.1.2

 

Problem Description: 
Security scanners detecting HSTS not being configured. This change enables HSTS for NetBackup web services.
 

Read me

Installation Location: Server (Master or media) 

 

Installation Instructions:
The NetBackup Web Management Console (nbwmc) process will need to be restarted in order for the change to take effect.

 

Using the NetBackup Emergency Engineering Binary (EEB) installer 
https://www.veritas.com/docs/100019405

 

Installing EEBs on a NetBackup 52x0 / 5330 Appliance 
https://www.veritas.com/docs/100023444

 

How to install client EEB's with VxUpdate 
https://www.veritas.com/content/support/en_US/doc/125240132-131571482-0/v130876036-131571482

 

Fix is available in NetBackup 8.3.0.2, 9.0 and later releases.

 

Downloads:
NB_8.1.2_ET4019187_1.zip
NBAPP_EEB_ET4019187-3.1.2.0-1.x86_64.rpm
 

Checksums of Files:

File                                     Checksum        Byte count
linuxR_x86/web.xml       1827545985    154277
linuxS_x86/web.xml       1827545985    154277
solaris/web.xml              1827545985    154277
solaris_x86/web.xml      1827545985    154277
AMD64/web.xml             1827545985    154277
zlinuxR/web.xml             1827545985    154277
zlinuxS/web.xml             1827545985    154277

Update files

File name Description Version Platform Size

Applies to the following product releases