Trellix Enterprise Security Manager 11.6.11 addresses known issues.
This release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Release details of Trellix ESM 11.6.11
For release dates and version number, see KB90422.
Rating
The rating defines the urgency for installing this update. This update is recommended for all environments. Apply this update at the earliest convenience.
Upgrade considerations
Trellix ESM 11.6.x and higher do not support environments configured with distributed Trellix ESM. See Upgrade HA receivers to upgrade to 11.6.x version for the first time.
New or changed
Trellix ESM has implemented the AES algorithm for encrypting login usernames and passwords. As a result, the ESM Login API call now requires the username and password to be AES encrypted.
User sessions will be cleared if a user enters an incorrect password multiple times, resulting in account lockout.
When a user changes their account password in one browser, it automatically logs out of all active sessions in other browsers.
Trellix ESM now prevents users from interacting with the HTML UI if any modifications are done in the browser debugger.
The file download size limit for ELM is now increased from 1 GB to 5 GB.
Resolved issues
This release provides resolution for the following issues.
Category | Reference | Resolution |
|---|---|---|
User Interface | SIEM-39738 | Fixed an issue where the ASP rule was enabled at the default policy level when copied into Policy Auditor. |
ACE Health Check | SIEM-39899 | Fixed the issues identified in Snowflex during an ACE health check. |
Software Upgrade | SIEM-39953 | Fixed a vulnerability with log4j files in the ESM environment. |
User Interface | SIEM-39996 | Fixed the issue where no view was available for selection despite the user having appropriate permissions. |
This release provides resolution for the following content issues through a rule update.
Category | Reference | Resolution |
|---|---|---|
3rd party ASP | SIEM-39297 | Fixed an issue where SSH events were displaying an incorrect protocol. |
3rd party | SIEM-40027 | Fixed an issue that prevented automatic parsing from functioning after upgrading to version 11.6.10. |
Known issues
For a list of known issues in this product release, see KB90422.