Download
Downloadable File
File link | File size | File description |
---|---|---|
Abstract
IBM Netcool Operations Insight 1.6.3.2 addresses a critical vulnerability that was reported against log4vj2. Arbitrary code execution and denial of service issues (CVE-2021-45046, CVE-45105, CVE-44832) were identified within the Apache Log4j library that is used by IBM Netcool Operations Insight 1.6.3.2. A patch is available to address these issues with package manifest naming.
Download Description
IBM Netcool Operations Insight 1.6.3.2 addresses a critical security fix.
Prerequisites
Check CSV
Verify the 1.6.3.2 CSV version by running the following commands:
oc get packagemanifest | egrep noi
oc get csv| egrep noi
oc get subscription
If the CSV is noi.v1.3.2, the updated catalog source can update the CSV. To update from the latest 1.6.3.2 CSV version, run the following commands:
# oc get packagemanifest | egrep noi
noi noi 35m
# oc get subscription
NAME PACKAGE SOURCE CHANNEL
noi noi noi1632 v1.5
# oc get installplan
NAME CSV APPROVAL APPROVED
install-9blbs noi.v1.3.2 Automatic true
If the CSV is noi-operator.v1.3.2, the updated catalog source will not be able to update the CSV.
To update from this 1.6.3.2 CSV version, run the following commands:
# oc get csv
NAME DISPLAY VERSION REPLACES PHASE
noi-operator.v1.3.2 IBM Cloud Pak for Watson AIOps Event Manager 1.3.2 Succeeded
# oc get installplan
NAME CSV APPROVAL APPROVED
install-s6grc noi-operator.v1.3.2 Automatic true
# oc get subscription
NAME PACKAGE SOURCE CHANNEL
ibm-noi-catalog-subscription noi-operator ibm-noi-catalog v1.5
Run the following commands to remove the obsolete subscription and CSV. An extra step is then required during installation to re-create the subscription and CSV for IBM Netcool Operations Insight on Red Hat OpenShift.
oc delete subscription ibm-noi-catalog-subscription
oc delete csv noi-operator.v1.3.2
Installation Instructions
OLM UI installation
Verify the existing catalog source used to deploy Netcool Operations Insight on Red Hat OpenShift.
Go to Operators > Installed Operators and select IBM Cloud Pak for Watson AIOps Event Manager. Click Subscription. Ensure that Automatic is selected for Update approval.
Check the CSV name by using the previous commands. If you followed the steps to delete the CSV and subscription, you must complete steps 5 - 9 to re-create the subscription and CSV: https://www.ibm.com/docs/en/noi/1.6.3?topic=installing-olm-ui
Online CASE installation
Complete steps 1 - 4 here: https://www.ibm.com/docs/en/noi/1.6.3?topic=installing-olm-ui-case
If you followed the steps to delete the CSV and subscription, you must also complete steps 5 and 6 to re-create the subscription and CSV.
Airgap installation
Complete steps 1 - 14 here: https://www.ibm.com/docs/en/noi/1.6.3?topic=installing-offline-airgap
If you followed the steps to delete the CSV and subscription, you must also complete steps 15 and 16 to re-create the subscription and CSV.
Download Package
See install steps
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
31 January 2022
UID
ibm16527810