Trellix Enterprise Security Manager 11.6.9 addresses known issues.
This release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Release details of Trellix ESM 11.6.9
For release dates and version number, see KB90422.
Rating
The rating defines the urgency for installing this update.
This update is recommended for all environments. Apply this update at the earliest convenience.
Upgrade Considerations
Trellix ESM 11.6.x and higher does not support environments with Distributed TESM configurations.
When upgrading to 11.6.x for the first time the normal process to upgrade HA receivers through the UI needs to be slightly altered.
Refer to Upgrade HA receivers in Trellix Enterprise Security Manager 11.6.x Installation Guide.
Skip step 6.
On step 7a, select the primary receiver instead of the secondary receiver in Receiver Management.
Note
The above steps are only needed when upgrading to 11.6.x for the first time.
Resolved issues
This release provides resolution for the following issues.
Category | Reference | Resolution |
|---|---|---|
Software Upgrade | SIEM-33682 | Updated Wireshark package to resolve vulnerabilities. |
Software Upgrade | SIEM-33683 | Upgraded Samba libs to resolve vulnerabilities. |
Software Upgrade | SIEM-33723 | Updated rpcbind to version 1.2.6 for CVE-2017-8779. |
Software Upgrade | SIEM-39767 | Updated Python 3.x package to resolve CVE-2023-24329 and CVE-2019-20907. |
Software Upgrade | SIEM-33722 | Updated Python 2.x package to resolve CVE-2019-20907. |
Software Upgrade | SIEM-33685 | Updated Perl libraries to resolve vulnerabilities. |
Software Upgrade | SIEM-39434 | Updated log4j library version to resolve vulnerabilities. |
Alarms, Correlation, ERC Device | SIEM-39555 | Resolved an issue with the receiver showing a red flag when the event file dump limit is reached. |
Data Source | SIEM-28192 | Resolved an issue with Checkpoint opsec connect script when taking empty parameters. |
User Interface | SIEM-37425 | Resolved an issue that prevented time delta from loading on refresh. |
Correlation | SIEM-39748 | Fixed an issue that broke Time-based Correlation rules from working as expected. |
User Interface | SIEM-37142 | Fixed an issue that prevented the drag-and-drop feature from working on the Field Assignment of Advanced Syslog Parser UI. |
Device Flags | SIEM-39645 | Fixed an issue that caused a red flag in the receiver. |
User Interface | SIEM-39642 | Fixed an issue that prevented the properties UI for any data source from being opened. |
ACE Device, Correlation | SIEM-39749 | Fixed an issue with ACE that caused filter settings to be ignored. |
ACE Device | SIEM-39760 | Fixed an issue where rules failed to load when the rule manager name contained a '.'. |
ACE Device | SIEM-39732 | Fixed an issue that prevented correlation rules from being triggered for all events within a time period. |
User Interface | SIEM-39796 | Fixed an issue on Datasource configuration UI which could be exploited for remote command execution vulnerability. |
User Interface | SIEM-39781 | Resolved an issue with the Case Insensitive field being hidden for IN/NOT IN operators of field match alarm UI. |
ACE Device | SIEM-39725 | Resolved an issue that caused the decay settings to be used to calculate risk scores were being ignored. |
This release provides resolution for the following content issues through a rule update since Trellix ESM 11.6.8.
Category | Reference | Resolution |
|---|---|---|
3rd party | SIEM-39794 | Added rules to support new MNEMONICS required for the CISCO Wireless LAN. |
Known issues
For a list of known issues in this product release, see KB90422.