Geneos 5.x Security Updates

Overview Copied

This page contains security updates for all Geneos 5.x releases.

To learn more about the supported Geneos versions and new features in the Geneos 5.x release, see the following documents:

Geneos 5.14.x Copied

Issue Key CVE Number CVE Severity Description Affected Components Fix Version
COL-12050 CVE-2024-29025 (BDSA-2024-0720) High The Netty library has been upgraded to 4.1.109.Final to address the security vulnerability: CVE-2024-29025 (BDSA-2024-0720). Netprobe Geneos 5.14.8
COL-12066 CVE-2023-0464 (BDSA-2023-0610), CVE-2023-0466 (BDSA-2023-0691), CVE-2023-0465 (BDSA-2023-0692), CVE-2023-2650 (BDSA-2023-1337), CVE-2023-3446 (BDSA-2023-1866), CVE-2023-3817 (BDSA-2023-1972), CVE-2023-4807 (BDSA-2023-2389) High The Geneos components have been upgraded to OpenSSL version 1.1.1w to address the following security vulnerabilities:
  • CVE-2023-0464 (BDSA-2023-0610)
  • CVE-2023-0466 (BDSA-2023-0691)
  • CVE-2023-0465 (BDSA-2023-0692)
  • CVE-2023-2650 (BDSA-2023-1337)
  • CVE-2023-3446 (BDSA-2023-1866)
  • CVE-2023-3817 (BDSA-2023-1972)
  • CVE-2023-4807 (BDSA-2023-2389)
Netprobe Geneos 5.14.8
COL-12094 CVE-2023-6378 (BDSA-2023-3307), BDSA-2023-3341 Medium The Logback has been updated to 1.3.14 to address the following security vulnerabilities:
  • CVE-2023-6378 (BDSA-2023-3307)
  • BDSA-2023-3341
Netprobe Geneos 5.14.8
COL-12113 CVE-2023-33202 (BDSA-2023-3254), CVE-2023-33201 (BDSA-2023-1625), BDSA-2024-2378 Medium The BouncyCastle dependency has been updated to 1.78.1 to address the following vulnerabilities:
  • CVE-2023-33202 (BDSA-2023-3254)
  • CVE-2023-33201 (BDSA-2023-1625)
  • BDSA-2024-2378
Netprobe Geneos 5.14.8
COL-11350 CVE-2023-38545 Critical The libcurl version has been updated to version 8.5.0 to address the critical security vulnerability: CVE-2023-38545. Netprobe Geneos 5.14.7
COL-12023 CVE-2023-0286 (BDSA-2023-0226) High The Geneos components have been upgraded to OpenSSL version 1.1.t to address the security vulnerability: CVE-2023-0286 (BDSA-2023-0226). Netprobe Geneos 5.14.7
UTL-1267 BDSA-2019-4014 Minor The Apache Xerces C++ library has been upgraded to 3.2.5 to address the security vulnerability: BDSA-2019-4014. Netprobe Geneos 5.14.7
["Geneos"] ["Release Notes", "Upgrade Notes", "Security Updates"]

Was this topic helpful?