cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2966
Views
4
Helpful
17
Replies

ISE UPgrade for CSCvd49829

lnorman
Cisco Employee
Cisco Employee

Ok, WTH does this mean:  https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvd49829

Releases 1.2, 1.3, 1.4 and 2.x are affected. A hot patch for these releases will be provided by the 18th of March.
The hot patch will only work on the latest release for each train. Customers need to upgrade to the latest release before applying the patch

Customers run 2.0 patch 4, is that the ‘latest release for that train’? Or are they demanding 2.2? Or 2.0.1? Or, we have to wait until March 18th to find out?

1 Accepted Solution

Accepted Solutions

Charlie Moreton
Cisco Employee
Cisco Employee

This means that you have to be running the latest patch for your version.

ISE 2.0 Patch 4

ISE 2.0.1 Patch 3

ISE 2.1 Patch 3

ISE 2.2 No Current Patches

You do NOT have to upgrade your version of ISE to install the Hotfix.

View solution in original post

17 Replies 17

Charlie Moreton
Cisco Employee
Cisco Employee

This means that you have to be running the latest patch for your version.

ISE 2.0 Patch 4

ISE 2.0.1 Patch 3

ISE 2.1 Patch 3

ISE 2.2 No Current Patches

You do NOT have to upgrade your version of ISE to install the Hotfix.

Thanks Charles!

Lou

gtilburg
Cisco Employee
Cisco Employee

Hi,

March 18 has passed, where can the hot patch be found?

Thanks

Gert

what version of ISE?

seems like multiple threads about this same defect

see this one

Re: CSCvd49829

hslai
Cisco Employee
Cisco Employee

No need to open TAC cases for this. The patches will be available at CCO. Please see the ISE entry @ Apache Struts2 Jakarta Multipart Parser File Upload Code Execution Vulnerability Affecting Cisco Products to track its availability.

peng083411147
Level 1
Level 1

My customer uses ISE version 1.2.1.198 ,is that the ‘latest release for that train’?

and I haven't installed all patch Version  ,Do I need to install the latest patch?

thank you

cheer

HI Jason,

My customer uses ISE version 1.2.1.198 ,is that the ‘latest release for that train’?

Do I need to upgrade the version before I install install the latest patch?

THANK YOU

As stated before please refer to the release notes, patch 8 is the latest patch and yes you will need to install that, 1.2.1.198 is the version of ISE not the patch version, please again read the release notes

http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/release_notes/ise12_rn.html#pgfId-637191

OK,Thank you for your patience

Releases 1.2, 1.3, 1.4 and 2.x are affected. A hot patch for these releases will be provided by the 24th of March.

but I don't find the hot patch in cisco.com

Refresh the browser? They are under Struts2-CVE-Fixes.

Screen Shot 2017-03-24 at 5.41.47 PM.png

execuse me,My customer users ISE version 1.2.1.198

but, I don't find the hot patch for this version?

only have Ftruts2Fix-1.3to14. and Struts2Fix-2.0to2.2.

So ,do I need to upgrade to version 1.3 before installing the patch?

Thanks

To patch ISE 1.2.x needs Cisco TAC assistant. Please open a TAC case, if not already done.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: