===================================================== = Changes between 9.5.24.55 and 9.5.25.11 = ===================================================== Security enhancements: Issue BFP-31914 - CVE-2024-23554 Issue BFP-32560 - CVE-2024-23583 Issue BFP-33153 - CVE-2024-23556 Issue BFP-33260 - CVE-2024-0853 Defect Articles (DAs) addressed: Issue BFP-33602 KB0111293 - (doc) Number of "Estimated targeted computers" may not be accurate Issue BFP-33576 KB0111160 - (doc) Missing information about _BESClient_Comm_IPCommunicationsMode Issue BFP-33341 KB0110552 - (doc) Mailbox behavior switching server in a DSA deployment Issue BFP-33315 KB0110465 - (doc) Relay Health Dashboard documentation update Issue BFP-32996 KB0109891 - Failure in Adding Parameter to Registry by Registry Wizard ===================================================== = Changes between 9.5.23.65 and 9.5.24.55 = ===================================================== Security enhancements: Issue BFP-31308 - CVE-2023-38545 Issue BFP-31302 - CVE-2023-37531 Issue BFP-31303 - CVE-2023-37530 Issue BFP-31304 - CVE-2023-37529 Issue BFP-31305 - CVE-2023-37528 Issue BFP-31306 - CVE-2023-37527 Issue BFP-31301 - CVE-2023-45706 Issue BFP-31917 - CVE-2023-45715 Issue BFP-32923 - CVE-2023-48795 Issue BFP-32535 - CVE-2023-46219 Issue BFP-31904 - CVE-2024-23552 Issue BFP-31916 - CVE-2024-23553 Defect Articles (DAs) addressed: Issue BFP-32324 KB0108971 -(doc) Restart is needed to apply UDP control settings Issue BFP-32147 KB0108798 - Console login fails until BigFix Server service is restarted Issue BFP-32109 KB0108719 - Maintenance Windows Dashboard generates faulty relevance Issue BFP-31533 KB0108414 - Agent crashes when using "adapter of network" inspector Issue BFP-31522 KB0108416 - BESClient files owned by non-existing user and group Issue BFP-31492 KB0108400 - Enable Enhanced Security failure Issue BFP-30770 KB0107629 - Error in opening an imported report from Web Reports Issue BFP-30755 KB0107573 - "(local)" DSN cannot be edited Issue BFP-30754 KB0107572 - (doc) Recovery procedure for the Master BigFix Server is incomplete Issue BFP-30660 KB0107407 - (doc) RHEL Install Instructions need SELinux clarification Issue BFP-30436 KB0107234 - (doc) Ambiguous documentation on throttle groups Issue BFP-30323 KB0106552 - Command "restart [delay-seconds]" not working on RHEL 8 Issue BFP-30230 KB0106291 - Some relay diagnostic pages are not working Issue BFP-29933 KB0105901 - Unable to delete Computer Assignments using the console ===================================================== = Changes between 9.5.22.34 and 9.5.23.65 = ===================================================== Security enhancements: Issue BFP-29170 - CVE-2023-37536 Issue BFP-29600 - CVE-2023-0464, CVE-2023-0465, CVE-2023-0466, CVE-2023-2650 Issue BFP-29604 - CVE-2023-28321 Issue BFP-30704 - CVE-2023-2953 Issue BFP-29778 - CVE-2023-37519 Issue BFP-30657 - CVE-2023-37520 Issue BFP-30866 - CVE-2020-22218 Defect Articles (DAs) addressed: Issue BFP-30651 - KB0107394 - Description Tab displays an incorrect link Issue BFP-30649 - KB0107382 - (doc) Broken link in the "_BESClient_Comm_ListenEnable" configuration setting documentation Issue BFP-30648 - KB0107375 - "BES Relay Cache Information" Analysis containing wrong URLs Issue BFP-30343 - KB0106671 - PDF export fails after upgrade of Ghostscript 9 to 10 Issue BFP-30217 - KB0106282 - Content not relevant for BigFix Labs Issue BFP-30168 - KB0106257 - FillDB intermittent crash on Linux Issue BFP-30120 - KB0106107 - Request to change the doc and fixlet ID 168 about CPU usage Issue BFP-29992 - KB0105955 - Validation is missing when importing with multiple fixlets Issue BFP-29693 - KB0105603 - (doc)Obsolete "DisableReplicationOfNextTables" setting Issue BFP-29215 - KB0104895 - Console and WebReports may not show site content Issue BFP-29173 - KB0104834 - Change of os inspector for RHEL8 not tracked in the fullchangelist-95.txt Issue BFP-29157 - KB0104796 - (doc) Missing folders in AV exclusion documentation Issue BFP-29156 - KB0104789 - Unwanted BigFix swidtags generated for shared sites Issue BFP-29063 - KB0104563 - Wrong command for fixlet 250 Issue BFP-28912 - KB0104196 - NMOs may fail deploying content from the WebUI Issue BFP-28860 - KB0104100 - (doc)Linux upgrade fails if a connection is opened to database Issue BFP-28695 - KB0103817 - (doc)Wrong registry path for 64bit machines in the documentation Issue BFP-28666 - KB0103775 - (doc) Missing information about not using % char in the DB2 password Issue BFP-28169 - KB0102967 - BigFix Console "Starts/Ends On" refreshes while editing Issue BFP-28047 - KB0102941 - Reports are unprocessed due to some corrupted reports Issue BFP-27954 - KB0102585 - Incorrect translation in French for Automatic Computer Groups menu Issue BFP-27826 - KB0102307 - BESClient uses PeerNest download logic when not registered Issue BFP-27775 - KB0102072 - Linux BESClient does not close softly at the system reboot Issue BFP-26213 - KB0099940 - The "current network of wifis" inspector returns on some macOS computers Issue BFP-26154 - KB0099830 - Transcoding errors for Danish chars in Presentation Debugger Other Bugs fixed: Issue BFP-29076 - Download Plugin uses an invalid string reference Issue BFP-28763 - On a relay a corrupted compressed report stops processing the remaining ones Issue BFP-27342 - Prefetch download with size limit Issue BFP-23089 - Missing online help for hide/showFromFiledFromMasthead Issue BFP-29030 - During the BESAdmin db upgrade, retry the force stop running applications to prevent temporary delay and errors Issue BFP-27583 - Error creating/updating an operator via REST API when the Retrieved Property belongs to an external site Issue BFP-28864 - Admin tool updatepassword command doesn't check for invalid chars ===================================================== = Changes between 9.5.21.78 and 9.5.22.34 = ===================================================== Security enhancements: Issue BFP-28167 - CVE-2023-0215, CVE-2022-4304 Issue BFP-28612 - CVE-2023-23916 Defect Articles (DAs) addressed: Issue BFP-28589 - KB0103637 - (doc) Add _BESClient_ActionManager_SSAv2Mode into documentation Issue BFP-28190 - KB0103003 - (doc) "Embedding in a Common Build" procedure not maintaining the Relay settings of the BESClient Issue BFP-28170 - KB0102914 - (doc) Fixlet 5294 fails when BES Installer Generator is not installed Issue BFP-28063 - KB0102820 - (doc) Unexpected reboot if Windows Fast Startup feature is enabled Issue BFP-27982 - KB0102619 - (doc) Server_audit log messages for BigFix 9.5 release Issue BFP-27977 - KB0102597 - Maintenance Window Dashboard not working as expected Issue BFP-27955 - KB0102587 - Memory usage of BigFix Server process may grow too much Issue BFP-27869 - KB0102476 - Upgrade to 10.0.8 or 9.5.21 may fail on Linux ===================================================== = Changes between 9.5.20.34 and 9.5.21.78 = ===================================================== Security enhancements: Issue BFP-25645 - CVE-2022-38659 Issue BFP-26334 - CVE-2022-35252 Issue BFP-25646 - CVE-2022-42453 Issue BFP-26339 - CVE-2017-7867, CVE-2017-7868 Issue BFP-27495 - WS-2019-0513 Issue BFP-27635 - CVE-2022-32208, CVE-2022-32206, CVE-2022-42915 Issue BFP-27636 - CVE-2022-31160 Defect Articles (DAs) addressed: Issue BFP-27552 - KB0101684 - (doc) Client installation/upgrade on AIX requires to disable Digital Signature Policy Issue BFP-27281 - KB0101482 - (doc) Incorrect supported OS-es for "service"-related inspectors Issue BFP-26935 - KB0101006 - ClientIdentityMatch increases number of required database connections Issue BFP-26852 - KB0100917 - (doc) Missing information about disabling DEP with Asset Discovery Issue BFP-26633 - KB0100681 - BigFix Server install with remote SQL DB fails Issue BFP-26231 - KB0099951 - Information missing in Pre Upgrade Check fixlet description Issue BFP-26215 - KB0099954 - Broken link in Registration List Size health check Issue BFP-26182 - KB0099879 - (doc) Forwarder component not clearly documented Issue BFP-26145 - KB0099781 - Missing platform in "Windows Software Distribution Wizard" Issue BFP-26111 - KB0099683 - (doc) Mac Installation Instructions missing MCM information Issue BFP-26103 - KB0099717 - BES Client might not honor the download size limit setting Issue BFP-26102 - KB0099715 - Not working "default web browser" inspector Issue BFP-25978 - KB0099416 - (doc) Wrong link in the Upgrading the installation generator topic Issue BFP-25788 - KB0099229 - Upgrade on Linux may fail requiring too high DB2 privileges Issue BFP-25738 - KB0099138 - Active Directory Inspector could not produce expected result Issue BFP-25737 - KB0099127 - Delay on action deployment Issue BFP-25378 - KB0098731 - REST API request on operators or roles may fail Issue BFP-25185 - KB0098442 - Agent properties not refreshed when reconnecting after deletion Issue BFP-23484 - KB0095968 - BESConsole login fails after removing deleted certificates Issue BFP-21876 - KB0093217 - _BESGather_UnsubscribeSiteOnDBError option error Issue BFP-17185 - KB0079913 - (doc) Fixlet marked as Not Relevant and sent to the sidelining Issue BFP-16558 - KB0078406 - Client on MacOS crashes if _BESClient_SecureRegistration configured with a password containing special characters Other Bugs fixed: Issue BFP-26153 - The stop of WebReports service is not logged on the WebReports log file Issue BFP-25659 - webreports error:Type: TypeError; Message: YAHOO.util.Dom.get(...) is null Issue BFP-20661 - Server upgrade may fail on Linux, if automatic db backup is enabled ===================================================== = Changes between 9.5.19.131 and 9.5.20.34 = ===================================================== Security enhancements: Issue BFP-25122 - CVE-2022-22576, CVE-2022-27775, CVE-2022-27776 Issue BFP-24942 - CVE-2022-27545 Issue BFP-24941 - CVE-2022-27544 Defect Articles (DAs) addressed: Issue BFP-26031 - KB0099496 - (doc) Remove Optional sentence from our documentation about CDT Issue BFP-25687 - KB0099098 - (doc) Incorrect note about installing client compliance library Issue BFP-25575 - KB0098922 - Settings on a Relay changed to the default after the upgrade Issue BFP-25374 - KB0098711 - RPMHelper CPU usage Issue BFP-25209 - KB0098496 - Wrong data in Relay Health dashboard Issue BFP-25200 - KB0098512 - (doc) Documentation about ODBC tool usage is unclear Issue BFP-25187 - KB0098481 - Multiple database collations may cause the upgrade to fail Issue BFP-25184 - KB0098411 - (doc) Clarification required for "the time action is relevant" message Issue BFP-25166 - KB0098391 - (doc) Incorrect Client Deploy Tool Wizard documentation Issue BFP-25163 - KB0098389 - The CDT Wizard fails to deploy BES Clients on Linux and Raspbian Issue BFP-25093 - KB0098419 - BigFix Agent may fail to download directly from HTTPs URLs Issue BFP-25066 - KB0098273 - REST API api/operator may not return expected data Issue BFP-25052 - KB0098210 - "Baseline synchronization" Dashboard Error Issue BFP-25051 - KB0098219 - Tasks fail once and complete minutes later incorrectly Issue BFP-24822 - KB0097751 - Enable Enhanced Security may fail Issue BFP-24674 - KB0097423 - Relay Health Dashboard can fail to retrieve hierarchy of relays Issue BFP-24667 - KB0097449 - Content-Type is missing performing a query REST API request Issue BFP-21512 - KB0091961 - Registry Wizard tasks not adding values under HKEY_CURRENT_USER ===================================================== = Changes between 9.5.18.74 and 9.5.19.131 = ===================================================== Security enhancements: Issue BFP-22779 - CVE-2021-27761 Issue BFP-22781 - CVE-2021-27762 Issue BFP-22302 - CVE-2021-27767, CVE-2021-27766, CVE-2021-27765 Issue BFP-24634 - CVE-2022-0778 Issue BFP-24803 - CVE-2018-25032 Defect Articles (DAs) addressed: Issue BFP-24496 - KB0097159 - In a DSA deployment some WebUI content may be truncated Issue BFP-24298 - KB0096917 - (doc) Missing path for AV exclusion Issue BFP-24274 - KB0096886 - Persistently connected Relays error if Authenticating parent Issue BFP-24258 - KB0096861 - On Linux the Web Reports service may crash Issue BFP-24253 - KB0096839 - Automatic Relay Selection fails when the ping response time is high Issue BFP-24178 - KB0096759 - Fixlet ID 518 can take a long evaluation time Issue BFP-24158 - KB0096756 - (doc) Incorrect documentation for Linux server and Active Directory integration Issue BFP-24122 - KB0096633 - BigFix Console doesn't start because of the Windows Error 0x2 Issue BFP-24035 - KB0096548 - (doc) Feature 'Stop Other Operator's Actions' not clearly documented Issue BFP-24011 - KB0096499 - (doc) Misleading information in Windows AV exclusion page Issue BFP-23977 - KB0096465 - BES Support fixlet #2696 low performance in large deployment Issue BFP-23888 - KB0096381 - Relay Health Dashboard not loads information Issue BFP-23813 - KB0096319 - (doc) Wrong link in the Web Reports documentation Issue BFP-23796 - KB0096272 - Missing analysis information when running Health Dashboard Issue BFP-23673 - KB0096004 - Platform documentation change for Task 2245 Issue BFP-23672 - KB0096004 - (doc) 'Platform documentation change for Task 2245 Issue BFP-23660 - KB0096148 - [Action][Status][is] not working in Web Reports in Japanese Issue BFP-23659 - KB0096153 - (doc) Relay requirement for Internet Explorer is still mentioned Issue BFP-23560 - KB0096048 - (doc) Missing description for "-noverify" option Issue BFP-23478 - KB0095902 - (doc) - Wrong information in the Managing Licenses documentation Issue BFP-23473 - KB0095848 - 'Multiple action group members' section is duplicated copying an offer generated from a Baseline Issue BFP-23453 - KB0095809 - (doc) Incorrect documentation for silent installation on Linux Issue BFP-23419 - KB0095724 - (doc) Missing details about mailbox action limits Issue BFP-23416 - KB0095965 - Linux installation with remote database may fail Issue BFP-23401 - KB0095693 - Fixlet to install WebUI 9.5 supports only RHEL 7 Issue BFP-23386 - KB0095687 - (doc) Inaccuracies about "Tiny Core Linux - BigFix Virtual Relay" Issue BFP-23253 - KB0095415 - Incorrect result of match (regex) inspector Issue BFP-23223 - KB0095333 - (doc) SQL Server AlwaysOn support is not reported in BigFix Documentation Issue BFP-23195 - KB0095256 - Fixlet ID 518 may take long time to evaluate Issue BFP-23075 - KB0095091 - Replication may fail with error CLI0109E Issue BFP-22800 - KB0094797 - Console may crash if "ComputerName" was incorrectly stored Issue BFP-22758 - KB0094695 - (doc) Missing note in dynamic throttling feature documentation Issue BFP-22740 - KB0094747 - Replication may stop with error SQL0302N Issue BFP-22701 - KB0094748 - RPM inspector issue when 32bit libraries are on a 64bit machine Issue BFP-22655 - KB0094394 - Relevance 'version of application' fails Issue BFP-22639 - KB0094344 - Web Reports 9.5.16 issue with BFExtractToCSV.exe tool Issue BFP-22624 - KB0094281 - (doc) Missing description of BES Client manual installation Issue BFP-22587 - KB0094190 - (doc) Required settings in besclient.config file Issue BFP-22436 - KB0094034 - (doc) Installation on Linux may fail if DB2 password contains special characters Issue BFP-22404 - KB0093979 - Deployment Health Checks dashboard raises a DSA alert Issue BFP-22216 - KB0093808 - (doc) Missing information about user privileges required on DB2 Issue BFP-22142 - KB0093641 - (doc) CDT prerequisites for Windows target computers to be reviewed Issue BFP-22128 - KB0093598 - Client may stop to evaluate Analysis/Fixlets from some sites Issue BFP-22114 - KB0093593 - BigFix socket inspector may fail on RHEL/CentOS machines Issue BFP-22045 - KB0093473 - Bad Request message when action fails through mailboxing Issue BFP-21950 - KB0093335 - (doc) Missing disk space requirement for Web Reports Issue BFP-21921 - KB0093331 - (doc) Missing WebUI certificate to check during SAML configuration Issue BFP-21898 - KB0093289 - Links pointing to HTTPS URLs always opened with IE Issue BFP-21896 - KB0093290 - (doc) General rule for 'Component restart required?' Issue BFP-21895 - KB0093291 - (doc) Expected contents of Applicable Computer Count tab for a baseline Issue BFP-21893 - KB0093270 - Action completes with status Waiting instead of DownloadFailed Issue BFP-21891 - KB0093273 - BigFix Client Deploy Tool does not create UDP rules Issue BFP-21838 - KB0093095 - Fixlet 219 does not uninstall the BES Client Issue BFP-21771 - KB0092784 - Files downloaded before accepting Offer if PeerNest enabled Issue BFP-21755 - KB0092703 - Replication process fails with "Invalid character value for cast specification (22005: 0)" Issue BFP-21726 - KB0092613 - audittrailclean_deletedcontent_fxresults may take long time to complete Issue BFP-21725 - KB0092542 - (doc) Wrong description for _BESClient_ActionManager_OverrideDisposition Issue BFP-21707 - KB0092495 - "__LockState" setting does not work on macOS Issue BFP-21659 - KB0092443 - (doc) SSL Certificate documentation has missing information Issue BFP-21641 - KB0092379 - (doc) SSL connections through loadbalancer/dns alias not supported Issue BFP-21477 - KB0091821 - Deployment time filter format issue on CDT dashboard Issue BFP-21473 - KB0091799 - BESWebReportsServer command may fail with permission issues Issue BFP-21444 - KB0091639 - Deployment Health Dashboard is slow to load Issue BFP-21362 - KB0091483 - (doc) WebReports export PDF in Windows Issue BFP-21335 - KB0092076 - Subaction may start with a download still in progress Issue BFP-21275 - KB0091373 - (doc) Client requirements for Mac are not correct Issue BFP-21243 - KB0091289 - (doc) No documentation for BigFix client AV LINUX exclusions Issue BFP-21205 - KB0091164 - Fixlet ID 2305 failing on HP-UX machines Issue BFP-21204 - KB0091178 - (doc) Installing the client with MSI page has wrong information Issue BFP-21159 - KB0091064 - (doc) Old version of unixODBC package can cause unexpected locks Issue BFP-21070 - KB0090694 - (doc) Web Reports edit column picker limited properties available Issue BFP-21034 - KB0090633 - (doc) Wrong reference in how migrate the BigFix server documentation Issue BFP-21005 - KB0090519 - Command "BESWebReportsServer.exe -initializeDB" may crash Issue BFP-20719 - KB0089676 - "BigFix Pre Upgrade Check (Version 10.0.x)" fixlet may fail on Windows Issue BFP-20396 - KB0089399 - Creation Time of system drives and folders not reported accurately Issue BFP-20209 - KB0088670 - Operator REST API does not return any data for some operators Issue BFP-19794 - KB0087173 - BES Support task 713 doesn't hide BESClient Issue BFP-18880 - KB0084838 - BES root server too busy without hitting any system resource limits. Issue BFP-11513 - IJ10843 - /MFS-Linux file is created after Installation of the BES Server Plugin on Issue BFP-11215 - IJ09677 - BigFix Server Plugin Service cannot start on RHEL7 Other Bugs fixed: Issue BFP-24614 - Web Reports error when using .\user to run the Web Report services Issue BFP-24240 - License Overview dashboard : no license info displayed in Patch product in 9.5 Issue BFP-23526 - "command not found" during Bigfix 9.5.18 installation on RHEL 8.3 Issue BFP-23273 - Unable to use the paste context menu for computer name Issue BFP-22304 - Fixlet Debugger Single Clause Execution time bug Issue BFP-22166 - review replication process of WebUI schema in case of temporary issues Issue BFP-21776 - Relay's Parent Connection Pool is not working for HTTPS requests Issue BFP-21465 - RHEL 8 not correctly managed in the os inspector Issue BFP-20382 - Platform update fixlet fails to upgrade the remote WebUI server Issue BFP-20035 - BESAdmin.sh -securitysettings fails to restart the server services Issue BFP-19696 - Error creating PDF on Windows 2019 Issue BFP-19602 - macOS inspector creation time issue for KeyStorage folder Issue BFP-18944 - MacOS client ui message issue with dark theme ===================================================== = Changes between 9.5.17.94 and 9.5.18.74 = ===================================================== Security enhancements: Issue BFP-19718 - CVE-2020-1971 Issue BFP-19600 - CVE-2020-13434, CVE-2020-13435, CVE-2018-20505, CVE-2019-19645 Issue BFP-19541 - CVE-2020-14281 Issue BFP-20207 - CVE-2021-23840 Defect Articles (DAs) addressed: Issue BFP-20812 - DA KB0090101 - 'Web reports - Filter by content type = fixlet turns all analysis property result into Issue BFP-20715 - DA KB0089711 - (doc) Document the "UseRemoteDB" setting into database migration procedure Issue BFP-20356 - DA KB0089242 - Console must be restarted, if BigFix Server restarts Issue BFP-20336 - DA KB0089261 - The console may show an U_ILLEGAL_ARGUMENT_ERROR attempting to filter in the Computers view Issue BFP-20090 - DA KB0088159 - (doc) Value range of _BESClient_Download_RetryMinutes in Configuration Guide is not correct Issue BFP-20000 - DA KB0087618 - Failure on Linux installer for BigFix 10.0.2 and BigFix 9.5.17 Issue BFP-19979 - DA KB0087498 - "Generate BigFix license tags" is not working as expected Issue BFP-19874 - DA KB0087280 - 'Baseline Synchronization Dashboard' search functionality broken Issue BFP-19837 - DA KB0087180 - "BigFix Pre Upgrade Check" fixlet for 10.0.2 and 9.5.17 can fail on a Linux environment Issue BFP-19721 - DA KB0087310 - The BESRemove.exe tools may cause Remote Control to be not usable Issue BFP-19706 - DA KB0086967 - The "Schedule Wake-on-LAN" wizard doesn't show policies in non-English BESConsole Issue BFP-19659 - DA KB0086893 - (doc) Missing details about embedding in a common build and ClientIdentityMatch advanced option Issue BFP-19646 - DA KB0086849 - In a BigFix 10.0.2 environment the Console fails to start with message "class InvalidMonth" and/or the Rest API queries return empty data for some relevances and/or error messages are logged in WebReports log Issue BFP-19637 - DA KB0086797 - (doc) CentOS 8 is certified for the BigFix Agent only Issue BFP-19628 - DA KB0086755 - The sitemapping.csv file is not propagating when deployed by Non Master Operator Issue BFP-19616 - DA KB0086717 - BES Client cannot see the new version when an application is upgraded Issue BFP-19587 - DA KB0086571 - BigFix Console may crash with runtime error Issue BFP-19531 - DA KB0086379 - Maintenance Window Dashboard defect Issue BFP-19473 - DA KB0086246 - The "Schedule Wake-on-LAN" wizard doesn't show policies or the policies cannot be executed Issue BFP-19415 - DA KB0086006 - (doc) NMAP scan from a RHEL7 scanpoint fails if SELINUX is enforced on the system Issue BFP-19401 - DA KB0085945 - Filter not working properly for expanded properties Issue BFP-19165 - DA KB0085423 - False posive for fixlet ID 1759 "Reset Client Credentials on Relays or Servers (CVE-2014-0160)" Issue BFP-19025 - DA KB0085253 - WebUI service in Windows might take long time to start up Issue BFP-18831 - DA KB0084587 - WebReports issue filtering in Explore Data-> Computers->Content Issue BFP-18175 - DA KB0081928 - Error in action script "Hash argument is invalid" Other Bugs fixed: Issue BFP-20471 - role does not save changes for computers assignement Issue BFP-20305 - Add additional log entries for the Web Reports DB Initialization Tool Issue BFP-20224 - WebReport credentials recovery on Windows Issue BFP-20210 - webui wrongly installs unixODBC Issue BFP-20174 - Time out occurred while restarting WebReports Issue BFP-19703 - Client stops on WMI error Issue BFP-19539 - A timeout popup is displayed if the webreports restart popup is not closed Issue BFP-19081 - No confirmation message disabling/enabling a previously defined datasource Issue BFP-19080 - managed properties not correctly handled in imported reports Issue BFP-18887 - WebUI Service in Windows can take very long time to startup Issue BFP-17150 - (doc) "Migrating the BigFix Server (Windows/MS-SQL)" to be reviewd and ported to 9.5 ===================================================== = Changes between 9.5.16.90 and 9.5.17.94 = ===================================================== Defect Articles (DAs) addressed: Issue BFP-19262 - DA KB0085617 - On a Window system, where BigFix Root server and WebReports service 9.5.16 and 10.0.1 are running, there could be a lot of intra process connections in TIME_WAIT Issue BFP-19114 - DA KB0085357 - Result progress in scheduled mails not reported in percentage format Issue BFP-18993 - DA KB0085171 - (doc) Document 64-character length limit for the affiliation group names Issue BFP-18959 - DA KB0085030 - Corrupt mailbox site when posting concurrently multiple files Issue BFP-18933 - DA KB0085035 - BES client inspector might returns invalid data for WIFI property Issue BFP-18881 - DA KB0084839 - (doc) Enabling debug/verbose logging for the BES Root Server and BES Relay services Issue BFP-18869 - DA KB0084859 - Task to cleanup obsolete files uploaded in the Temp folder not working Issue BFP-18833 - DA KB0084583 - (doc) Missing documentation on how to configure the Web Reports setting 'Showing non-relevant results' Issue BFP-18821 - DA KB0084569 - (doc) AIX support information not congruent in Release Notes and documentation Issue BFP-18787 - DA KB0084487 - (doc) The setting 'showevenifexactmatch' does not work Issue BFP-18710 - DA KB0084365 - On Web Reports the list of properties to filter computers is in reversed alphabetical order Issue BFP-18708 - DA KB0084389 - WebReports do not apply filter correctly when splitting rows on multiple results Issue BFP-18704 - DA KB0084361 - Icon indicating the column sort order is not visible Issue BFP-18662 - DA KB0084249 - (doc) Changes required to customize Client UI message strings in BigFix Version 10 Issue BFP-18625 - DA KB0084158 - Upgrade on Linux to Bigfix version 10 may fail because SQL0668N DB2 error Issue BFP-18616 - DA KB0084088 - The BES Support task 'Enable PDF Reports - Part 1/2' stuck in Pending Downloads Issue BFP-18612 - DA KB0084349 - Client Deploy Tool does not install on Unix endpoints Issue BFP-18601 - DA KB0084164 - BigFix Server installation with remote database may fail during database validation Issue BFP-18593 - DA KB0083985 - On DB2, replication process may fail on WebUI tables Issue BFP-18495 - DA KB0082544 - (doc) Unclear documentation for Maximum Child Count Issue BFP-18318 - DA KB0082398 - Blocked content when exporting to PDF Issue BFP-18316 - DA KB0082230 - (doc)BigFix Agent version supported on RedHat 8 Issue BFP-18290 - DA KB0082160 - (doc) Migration steps for moving Platform DB2 database from local 10.5 to remote 11.5 Issue BFP-18234 - DA KB0082076 - (doc) Upper limit for throttle setting _BESRelay_HTTPServer_ThrottleKBPS and _WebReports_HTTPServer_ThrottleKBPS Issue BFP-18211 - DA KB0082077 - Web Reports 'Edit Columns' button became slow increasing the number of properties. Issue BFP-18209 - DA KB0081963 - (doc) Missing information in article "Real Time AV Exclusions for BigFix components" Issue BFP-18177 - DA KB0081858 - (doc) BigFix Platform 9.5.14, 9.5.15, 9.5.16, 10.0.0 and 10.0.1 do not support Db2 V 11.5.4 Issue BFP-18176 - DA KB0081760 - (doc) Add "Enable TLS1.2 for Notification Service" fixlet information to the Notification Service Guide Issue BFP-17901 - DA KB0081455 - The relevance expression 'last write time of ' may fail Issue BFP-17814 - DA KB0081240 - (doc) Missing details for the support of Microsoft Edge browser for BigFix Web Reports Issue BFP-17728 - DA KB0081080 - (doc) Documentation for Maximum Child Relay Count Issue BFP-17683 - DA KB0081029 - (doc) Computer Name for Windows limited to 15 characters is a known limitation Issue BFP-17637 - DA KB0080957 - The "Install BigFix Clients with Client Deploy Tool" Fixlet is not relevant for Ubuntu 18 Issue BFP-17577 - DA KB0081119 - Replication is failing because of string data right truncation error Issue BFP-17358 - DA KB0080453 - Errors visualizing imported reports having columns re-ordered Issue BFP-17289 - DA KB0080299 - Fixlets to update BESClient on SuSE Linux Enterprise are not relevant on SLES 10 Issue BFP-17280 - DA KB0080245 - JavaScript error may be displayed filtering by content or site and playing with analysis properties Issue BFP-17041 - DA KB0079540 - Action Script "Download Now" command is not working with redirected link Issue BFP-16988 - DA KB0079337 - Support and doc webpages still have hyperlinks redirecting to the IBM developerworks webpages that no longer exist Issue BFP-10430 - DA IJ07041 - MAGs are repeatedly evaluated, even if they are not relevant and the relevance condition result cannot change over time Other Bugs fixed: Issue BFP-19351 - (doc) Update Manual Installation for Exporting activity reports to PDF documents on Windows System Issue BFP-18876 - 9.5: BigFix Console behaviour at license expiration time Issue BFP-18867 - Incorrect representation of the "Overview" report Issue BFP-18698 - Export to PDF doesn't work on linux after upgrade Issue BFP-18659 - WR exception opening an imported report with a column sorted Issue BFP-18634 - Using IE, a very long empty picker is opened looking for an unknown item Issue BFP-18558 - JAVA Script error on WR using IE Issue BFP-18552 - BESSupport Fixlet 602 doesn't work Issue BFP-18448 - Column order not respected exporting and re-importing a report with customised order Issue BFP-18185 - WebUI Service: Service needs to respect delayed updates Issue BFP-17630 - (doc) Client 9.5.16 doesn't start after SLES 15 system reboot Issue BFP-17530 - BESAdmin -findinvalidactions option should delete WebUI data Issue BFP-17525 - mac uninstaller requires root privileges though it is been installed as not root Issue BFP-17516 - fixlet to upgrade installation folder remains relevant Issue BFP-17412 - Permission issue on a property for Web Reports user with 'Restrict view by console user' Issue BFP-17410 - BESAdmin -findinvalidactions message is not correct with five actions Issue BFP-17293 - Some hyperlinks do not works on Bigfix Configuration settings ===================================================== = Changes between 9.5.15.71 and 9.5.16.90 = ===================================================== Security enhancements: Issue BFP-15059 - CVE-2010-4207, CVE-2010-4208, CVE-2010-4710, CVE-2012-5881, CVE-2012-5882, CVE-2012-5883 Issue BFP-15060 - CVE-2019-11358 Issue BFP-15056 - CVE-2020-4095 Issue BFP-17234 - CVE-2017-12652, CVE-2010-1205 Issue BFP-15728 - CVE-2019-5435 Issue BFP-17216 - CVE-2020-11022, CVE-2020-11023 Defect Articles (DAs) addressed: Issue BFP-17357 - DA KB0080391 - "Java Error: Incorrect Function" on Web Reports 9.5.15 Issue BFP-17087 - DA KB0079660 - (doc) Upgrade BigFix to v10: manual vs automatic Issue BFP-17040 - DA KB0079535 - RPMHelper agent utility marked as defunct if automount mount point hangs Issue BFP-17016 - DA KB0079407 - (doc) High CPU% of BESClient process on Linux after completion of the action. Issue BFP-17014 - DA KB0079411 - Deployment Overview - Dashboard showing wrong number of Agents Deployed Issue BFP-16958 - DA KB0079246 - Wrong hyperlink in the BigFix Airgap Non-Extraction Usage page Issue BFP-16956 - DA KB0079243 - (doc) Wrong information reported in the REST API page Issue BFP-16927 - DA KB0079062 - (doc) - Missing information about changing settings for the BES Client Helper Service Issue BFP-16869 - DA KB0079072 - The xinetd service inspector failed with 16XinetdParseError Issue BFP-16665 - DA KB0078602 - BES Support fixlet 198 wrongly relevant on BigFix Server version 10 Issue BFP-16614 - DA KB0078536 - (doc) Information missing in the Operator REST API section Issue BFP-16578 - DA KB0078457 - Relays in DMZ using persistent connection causing TCP Port exhaustion Issue BFP-16577 - DA KB0078463 - Temporary files in the UploadManager/BufferDir/Temp folder not deleted if not validly signed Issue BFP-16561 - DA KB0078309 - Relay Health Dashboard shows incorrect values in Client per Relay category Issue BFP-16357 - DA KB0077732 - (doc) Unit of measure is not specified for some settings Issue BFP-16333 - DA KB0077695 - Baseline component group duplicated when editing it from custom dashboard Issue BFP-16281 - DA KB0077469 - Running BES Audit Trail Cleaner in preview could return SQL0420N DB2 errors on Linux Issue BFP-16186 - DA KB0077221 - Login Issue to Inventory and Compliance Portal using Web Reports Issue BFP-15957 - DA KB0076534 - Setting IntervalSeconds not honored in OperatingMode equals to 1 Issue BFP-15916 - DA KB0076421 - Deleting Duplicate Computers based on DNS Issue BFP-15884 - DA KB0076331 - Sites for "BigFix Extensions" are no more referenced Issue BFP-15822 - DA KB0075888 - (doc) Bigfix Asset Discovery - Missing snmp information Issue BFP-15598 - DA KB0075393 - MSQL Job "BFEnterprise Full Database Index Reorganization" completes with success even if some steps are not completed Issue BFP-15579 - DA KB0075393 - Poor performance of ProxyAgent when the number of BigFix console operators and managed devices is very high Issue BFP-15509 - DA KB0075062 - Enable the carbon copy pointing to a not existing drive causes a server internal error Issue BFP-15378 - DA KB0074816 - Filesystem inspector does not show mount point Issue BFP-13943 - DA KB0069057 - Certificate warning for SAML authentication is displayed at every login on BigFix Console Issue BFP-11597 - DA IJ11124 - The certificate delivered by BigFix solution does not contain an entry in the SUBJECTALTNAME field Issue BFP-17403 - DA KB0080616 - High CPU consumption on BESRelay if its parent relay or the server is not reachable Issue BFP-14314 - DA KB0069600 - Web reports not sending email notification for reports containing special chars Other Bugs fixed: Issue BFP-16972 - Mac CPU Package inspectors giving wrong counts Issue BFP-16922 - (doc) "Maintenance and Troubleshooting" page autoreferenciates Issue BFP-16839 - Different "version block" for file comctl32.dll reported by Fixlet Debugger when changing context Issue BFP-16814 - Take into account AdminTool settings when computing Content Visibility view Issue BFP-16606 - (doc) The "Throttling methods" page do not reference the correct section for list of settings Issue BFP-16557 - Windows 10 2004: Pro edition reported as Business Issue BFP-16551 - Error in language versions of WebUI installation Issue BFP-16458 - Editing a baseline using a dashboard causes the components to became not synchronized Issue BFP-16440 - Unable to switch to SSL an existing LDAP directory configuration Issue BFP-16439 - Webreport returns a java script error from Interner Explorer 11 Issue BFP-16327 - BigFix agent is not sending updated status of an offer Issue BFP-16306 - Regression on GET computer tasks Issue BFP-16285 - (doc) About BigFix Console certificate warning using SAML authentication Issue BFP-16270 - REST API GET Sites does too many unnecessary readings of the mastead Issue BFP-16268 - Regression on GET computer fixlets Issue BFP-16094 - AirGap CLI: ca-bundle.crt doesn't fit ssl connection ===================================================== = Changes between 9.5.14.73 and 9.5.15.71 = ===================================================== Security enhancements: Issue BFP-14444 - CVE-2019-1547, CVE-2019-1563 Issue BFP-15673 - CVE-2019-17498 Defect Articles (DAs) addressed: Issue BFP-16368 - DA KB0077751 - (doc) Improve database collation requirement documentation Issue BFP-16275 - DA KB0077495 - (doc) Incorrect references in documentation Issue BFP-16182 - DA KB0077161 - Unable to install Nmap Scan Point 7.70 on Windows Issue BFP-16135 - DA KB0077744 - (doc) Subscription to computer groups containing special chars in the name is not correctly evaluated by devices managed by BigFix ProxyAgent Issue BFP-16083 - DA KB0075113 - (doc) The names of the settings "_Enterprise Server_ClientRegister_MaxChildCount" and "_Enterprise Server_ClientRegister_MaxChildRelayCount" is incorrect in Japanese documentation Issue BFP-16073 - DA KB0076852 - The Network Traffic Guide page refers to TEM description still and should be updated Issue BFP-16043 - DA KB0076762 - Impact of enabling LDAP channel binding and LDAP signing with BigFix Issue BFP-16016 - DA KB0076643 - (doc) Documentation for _BESRelay_HealthCheck* settings has to be removed from Configuration Guide Issue BFP-16008 - DA KB0076690 - (doc) Documentation Error in Database Requirements Issue BFP-15694 - DA KB0075637 - (doc) Reference to obsolete Task IDs in the documentation Issue BFP-15686 - DA KB0075602 - (doc) Default BigFix database name cannot be changed Issue BFP-15586 - DA KB0075370 - (doc) BigFix Console 9.5.13 and 9.5.14 support on Windows 10 (April 2018 Update, 1809 and 1903 versions) Issue BFP-15488 - DA KB0075010 - (doc) Documented supported browsers for Web Reports not aligned to System Requirements Issue BFP-15453 - DA KB0074958 - Computers assigned to a role are visible only from the console on the primary Server Issue BFP-15350 - DA KB0074593 - (doc) Unable to upgrade Bigfix if the 'SQL Server Native Client' driver is not installed Issue BFP-15313 - DA KB0074477 - (doc) Reading file inspectors documentation to be improved Issue BFP-15309 - DA KB0074466 - (doc) Missing details for action status mechanism Issue BFP-15293 - DA KB0074330 - (doc) Missing download retry mechanism for _BESClient_Download_RetryLimit property Issue BFP-15287 - DA KB0074387 - Multiple datasources with the same LDAP directory name may generate unexpected results in the login of LDAP users in Web Reports Issue BFP-15251 - DA KB0074326 - Automation plans and Software Distribution tasks failing to synchronize and update Issue BFP-15250 - DA KB0074347 - Primary key constraint violation on table 'PK_STATISTICAL_BINS' may occur Issue BFP-15244 - DA KB0074295 - How to upgrade a standalone installation of WebUI Issue BFP-15236 - DA KB0074294 - LDAP user with Administrator role inherited from a group loses privileges Issue BFP-15222 - DA KB0074199 - BigFix ProxyAgent not processing mailbox actions when the BigFix port is not the default 52311 Issue BFP-15159 - DA KB0074080 - (doc) Changes of behavior for REST API computer Issue BFP-15158 - DA KB0074081 - Incorrect results for REST API computer Issue BFP-15157 - DA KB0074079 - (doc) A client or session relevance expression containing a large number of elements could cause a crash Issue BFP-15146 - DA KB0074061 - BigFix ProxyAgent doesn't process the devices after the "invalid sequence number" error has been triggered Issue BFP-15144 - DA KB0074053 - (doc) Meaning of the setting _BESClient_Resource_PowerSaveTimeoutX is not clear Issue BFP-15143 - DA KB0074056 - BigFix console returns error when trying to assign a computers group from a custom site Issue BFP-15071 - DA KB0073953 - (doc) Prerequisites about MS SQL database collation are not documented Issue BFP-15070 - DA KB0073939 - After upgrading Web Reports to 9.5.14, normal users cannot open anymore BigFix Labs reports Issue BFP-15033 - DA KB0073997 - For Tiny Core the default open files upper limit ( ulimit -n ) is too low Issue BFP-15015 - DA KB0073868 - Ambiguous behavior of charts in Web Report connected to multiple data sources Issue BFP-15010 - DA KB0073835 - Documented wrong default value for ParallelismEnabled FillDB parameter Issue BFP-14937 - DA KB0073678 - Dynamically target by property" selection in the "Take Action" dialog should not default to "All Computers" Issue BFP-14720 - DA KB0073307 - ProxyAgent fails running action with TranscodeU8ToU16 error Issue BFP-14701 - DA KB0073315 - Custom text of mail visualized in a single line Issue BFP-14687 - DA KB0073316 - On Web Reports, modifying a filter have no effect on charts that are in 'Configure Chart' phase Issue BFP-14684 - DA KB0073265 - Fixlet Debugger indenting problem with underscores Issue BFP-14554 - DA KB0073057 - (doc) Expected behaviour of Offer when multiple users are logged on Issue BFP-14553 - DA KB0072928 - The Action status of an Offer might remain "Waiting" if SSA is enabled Issue BFP-14432 - DA KB0072779 - BigFix WMI inspector not working fine on a Windows 64-bit machine Issue BFP-14295 - DA KB0069592 - LDAP users are unable to log in to Web Reports if DN is longer than 255 chars Issue BFP-14227 - DA KB0069557 - Unable to manage roles with a name exceeding 32 chars by using REST API Issue BFP-14180 - DA KB0072772 - Missing check for DNS rebinding on Web Reports Issue BFP-14054 - DA KB0069303 - Creating and deleting a custom site twice changing the name case causes Windows Agents to stop Issue BFP-13947 - DA KB0069089 - Console message about BESClient_Download_PreCacheStageDiskLimitMB is wrong Issue BFP-13876 - DA KB0068945 - BigFix Server 9.5.13 may experience performance issues if clientIdentityMatch advanced option is set to 100 Issue BFP-13811 - DA KB0068871 - Filesystem inspector causes autofs filesystems to be automatically mounted Issue BFP-13691 - DA KB0068696 - "BES Relay / BES Server Setting: Download Cache Size" fixlet does not perform an automatic restart of BES Relay service Issue BFP-13440 - DA IJ16755 - LicenseUpdater HTTP request can fail due to timeout error Issue BFP-13333 - DA IJ16516 - Task ID 219 "TROUBLESHOOTING: Uninstall BES Client" refers to an old BESRemove executable version Issue BFP-13142 - DA IJ16108 - RestAPI POST mailbox returns wrong SHA1 and size. Issue BFP-12847 - DA IJ15144 - "IBM BigFix Pre Upgrade Check" fixlet failure when the database password contains special chars Issue BFP-12449 - DA IJ14141 - WebReports redirect link in emails is not valid Issue BFP-12061 - DA IJ12901 - Missing Certificate Pinning in BigFix Enterprise Console Issue BFP-12046 - DA IJ12882 - A no master operator is able to view from public webreports properties defined in custom sites for which he has no permissions Issue BFP-11945 - DA IJ12280 - On MAC BigFix client, the inspector 'version of application' does not return the expected version Issue BFP-11498 - DA IJ10807 - When cache is enabled, BES Console opening is still slow Issue BFP-10431 - DA IJ06901 - (doc) Upgrading BigFix Agent in glogal zone removes BigFix agent in local zone Issue BFP-10244 - DA IJ05636 - WebReports logging should be improved to include details about the time required to load reports Issue BFP-10174 - DA IJ00617 - BigFix console operators may result as administrator of computers, even if they don't have rights on those systems Issue BFP-10166 - DA IJ01136 - BFSITEPROPTOOL INCORRECTLY ASSIGN BASELINE RELEVANCE Issue BFP-10123 - DA IJ00146 - (doc) The maintenance window analysis reports a wrong value for next maintenance window in case of weekly periodicity Issue BFP-10108 - DA IV98756 - Webreport shows corrupt characters in the fixlet "View Description" pop-up when the browser language is not English Issue BFP-10067 - DA IV96446 - "display name" returned by IEM CLI get query relevance is not localized Issue BFP-10013 - DA IV93447 - It is not possible to login to BES Console with Windows session credentials, if the Active Directory is added as generic LDAP Other Bugs fixed: Issue BFP-10449 - (Pain Point) Need a fixlet to enable/disable BigFix Server logging Issue BFP-13694 - file uploaded via rest api from Unix machine to a Windows server mailbox site is different from the original Issue BFP-13706 - avoid FillDB abnormal usage of RAM due to analysis collect too much data Issue BFP-13935 - WebUI login doesn't work with format DOMAIN\User Issue BFP-14039 - check if columns PasswordHistory and HashAlgorithm of table USERS already exist during upgrade Issue BFP-14651 - exception on Web Reports with charts and filtering so that have no data Issue BFP-14685 - (serviceability) Name of action or content which contains the pipe character "|" is not encapsulated in the server_audit.log file Issue BFP-14751 - (serviceability) add warning about missing WebUI keys on the filesystem to root server Issue BFP-15451 - (serviceability) trace replication activity and mailbox file not found error Issue BFP-15458 - (Serviceability) Provide a way to configure Notification Service for only TLS1.2 Issue BFP-16039 - BESServer - LicenseUpdater - HTTP Error 60: SSL peer certificate or SSH remote key was not OK Issue BFP-16116 - (Pain Point) Cleanup NMAP scan results on BigFix clients (scan points) Issue BFP-16159 - HTTP error 500 viewing user information on WebReports Issue BFP-16427 - Fixlet 2245 contains errors in "Prerequisite" Issue BFP-16420 - Script error opening BES Support fixlet 2240 Issue BFP-16816 - The data in the Total Issues chart from the WR Overview report is overlapped (auto-fit data is selected) ============================================ = Changes between 9.5.13.130 and 9.5.14.73 = ============================================ Security enhancements: Issue BFP-13475 - CVE-2019-3855, CVE-2019-3856, CVE-2019-3857, CVE-2019-3858, CVE-2019-3859, CVE-2019-3860, CVE-2019-3861, CVE-2019-3862, CVE-2019-3863 Issue BFP-14184 - CVE-2019-13115 APARs addressed: Issue BFP-14702 - APAR KB0073299 - _BESClient_Resource_PowerSaveEnable behaves differently if _BESClient_Resource_AccelerateForPendingMessage is set or not Issue BFP-14452 - APAR KB0072847 - Action postponed multiple time Issue BFP-14218 - APAR KB0069601 - REST API upload fails when using "%" in the file name Issue BFP-14042 - APAR KB0069008 - "Component restart required" information is missing for setting _BESClient_Download_LimitBytesPerSecond Issue BFP-14016 - APAR KB0069210 - Upload Manager settings type change. Issue BFP-13961 - APAR KB0069026 - MAC: Client settings may disappear from BESAgent plist file Issue BFP-13946 - APAR KB0069090 - Values for setting _BESGather_Use_Https are wrong Issue BFP-13877 - APAR KB0068943 - _BESRelay_HTTPServer_LogFileSizeLimit and _BESRelay_HTTPServer_LogFileRotationLimit values Issue BFP-13815 - APAR KB0068877 - BigFix client evaluation of External and Custom sites could require a long time to complete, sometimes even several days. Issue BFP-13777 - APAR KB0068819 - Update the documentation about Bigfix Visualization Tool Issue BFP-13770 - APAR IJ17314 - BigFix action reports pending message while the client shows the action as running Issue BFP-13693 - APAR KB0068750 - On 9.5.13 the console can crash if the 'Four Eyes Approval Capability' feature is enabled Issue BFP-13692 - APAR KB0068698 - BigFix Configuration Guide does not specify that the BES Relay Service restart is required for _BESGather_Download_CacheLimitMB Issue BFP-13592 - APAR IJ17315 - setting delete for current site does not work and logs nothing Issue BFP-13578 - APAR IJ17224 - Relays.dat not reporting affiliation Issue BFP-13565 - APAR IJ17209 - Missing documentation for the options of Unmanaged Asset Importer on Linux Bigfix server Issue BFP-13492 - APAR IJ16964 - The link https://www.ibm.com/developerworks/community/wikis/home?lang=en#!/wiki/Tivoli+Endpoint+Manager/page/BigFix+Monitoringis obsolete and should be updated Issue BFP-13473 - APAR IJ16847 - "_BESClient_ActionManager_SkipVoluntaryOnForceShutdown" has been present in the registry even though is deprecated Issue BFP-13454 - APAR IJ16793 - Root Server 9.5.13 crashes Issue BFP-13439 - APAR IJ16751 - Authentication Failed Message when Taking Action on BES Root server 9.5.13 Issue BFP-13436 - APAR IJ16668 - AIX RPM inspector fails to locate librpm shared libraries when rpm.rte v4.13.0.4 or higher is installed Issue BFP-13420 - APAR IJ16675 - Rest API role/{roleid} call wipes out computer assignment unexpectedly Issue BFP-13417 - APAR IJ16669 - Prefetch starts before time constraint with PeerNest enabled Issue BFP-13413 - APAR IJ16608 - In WebReports, the reports exported using 'Export to CSV' option don't have the same order of the displayed results Issue BFP-13412 - APAR IJ16607 - In latest BigFix patches, in WebReports, it is not possible to drag and drop columns in reports through Internet Explorer Issue BFP-13289 - APAR IJ16482 - MAC: BigFix Client for macOS does not launch unless user is logged in Issue BFP-13283 - APAR IJ16465 - SWD Application Management Groups dashboard fails on deploy if targets are out of sync Issue BFP-13198 - APAR IJ16247 - Precaching tasks stuck in pending download Issue BFP-13166 - APAR IJ16206 - On Web Reports, initial expanded state in "Edit Columns" for saved reports is wrong Issue BFP-13158 - APAR IJ16166 - DSA replication on Linux may fail on table DASHBOARDDATA if the Value column is greater than 1MB. Issue BFP-13132 - APAR IJ16067 - how an Unmanaged Asset is identified Issue BFP-13091 - APAR IJ15987 - Using rest api, filtering response field does not work if refers to properties with not alphanumeric characters in the name Issue BFP-12836 - APAR IJ15084 - The Tasks for client lock and unlock wrongly complete with success Issue BFP-12677 - APAR IJ14687 - Rename or removal of an automatic group is not reflected in role assignments Issue BFP-12610 - APAR IJ14486 - BES.xsd content model is not determinist. Issue BFP-12426 - APAR IJ14080 - Incorrect WebReports scheduled activities visibility Issue BFP-12292 - APAR IJ13361 - The BESAdmin tool, with option findinvalidsignatures, cannot show the list of invalidly signed content if it is too long Issue BFP-12154 - APAR IJ13108 - MacOS Client - the minimize button of Pop Up message works even with topmost setting on Issue BFP-12073 - APAR IJ12907 - If the client is attached at the relay download simultaneously doesn't work Issue BFP-10167 - APAR IJ01206 - BES Support fixlets not properly displayed when BigFix is installed using korean language Issue BFP-9973 - APAR IV77649 - Access to Private Report in BigFix Web Reports with NMO Issue BFP-9952 - APAR IV81995 - Unmanaged Assets not viewed to non-NMO users Issue BFP-9946 - APAR IV68297 - Actions taken against a property with a NULL value fail with Server logs "/data/actions... unexpected end of data" Other Bugs fixed: Issue BFP-14382 - Incorrect parameter in Server Recovery procedure Issue BFP-14056 - BigFix Web Reports and Content Filter Issue Issue BFP-14036 - Linux installer - Incorrect info about installed components Issue BFP-13795 - Clarify doc of createwebuicredentials Issue BFP-13740 - No information in the the WebReports log about GroupSID exceeding the max lenght (255) Issue BFP-13658 - WebReport "Error in template function body: Invalid property result count ============================================ = Changes between 9.5.12.68 and 9.5.13.130 = ============================================ Security enhancements: Issue BFP-11784 - CVE-2018-16839, CVE-2018-16842, CVE-2018-16840 Issue BFP-11850 - CVE-2018-2005 Issue BFP-11914 - CVE-2019-4011 Issue BFP-11915 - CVE-2019-4058 Issue BFP-12325 - CVE-2019-3822, CVE-2019-3823, CVE-2018-16890 Issue BFP-12502 - CVE-2019-1559 APARs addressed: Issue BFP-10196 - APAR IJ03579 - BIGFIX SERVER UPGRADE TO 9.5.8 VERSION MAY FAIL WITH INVALIDMONTH EXCEPTION Issue BFP-10230 - APAR IJ05029 - REST API UPLOAD FAILS WHEN USING "%" INTO FILENAME Issue BFP-10231 - APAR IJ05097 - DSA REPLICATION OF ACTION TABLES COULD NEVER COMPLETE SUCCESSFULLY Issue BFP-10259 - APAR IJ06371 - IT IS IMPOSSIBLE MODIFY SOME SPECIFIC SITES VIA REST API Issue BFP-10260 - APAR IJ06375 - ISSUE CREATING REGISTRY ENTRIES WITH REGSET OR REGSET64 Issue BFP-10420 - APAR IJ07089 - PREVENT BES SERVER INSTALLER CRASH IF SMBV1 IS NOT AVAILABLE Issue BFP-11244 - APAR IJ09782 - WEB REPORTS DOES NOT PROVIDE ANY OPTION TO CONFIGURE THE PASSWORD HISTORY FOR USERS Issue BFP-11627 - APAR IJ11295 - IN BESADMIN THE PROPERTY NAME TO IDENTIFY DUPLICATED COMPUTERS MUST BE SPECIFIED IN ENGLISH, DEFAULT IS IN LOCAL LANGUAGE Issue BFP-11747 - APAR IJ11507 - ON WINDOWS, UPGRADE OR INSTALLATION CAN FAIL IF DATABASE USER DOES NOT HAVE RIGHT PERMISSIONS Issue BFP-11264 - APAR IJ11806 - REST API CANNOT RETRIEVE RELEVANT BASELINES FOR A COMPUTER Issue BFP-11946 - APAR IJ12476 - DB2 CANNOT START IF THE ATTRIBUTE NOSUID IS ENABLED ON THE MOUNT POINT WHERE DB2 INSTANCE OWNER IS CREATED Issue BFP-12075 - APAR IJ12943 - WEB REPORTS CAN CRASH PROCESSING COMPUTER NAME BUILT-IN PROPERTY Issue BFP-12326 - APAR IJ13550 - INTAKE SIZE FOR "ENTER DEVICE NAMES" FIELD ON CONSOLE TAKE ACTION DOES NOT WORK CORRECTLY Issue BFP-12328 - APAR IJ13553 - BES CLIENT ON AIX COULD TERMINATE ABNORMALLY Issue BFP-12378 - APAR IJ13989 - POSSIBLE PAGINATION ISSUE EXPANDING COMPUTERS CURRENT COLUMNS IN WEB REPORTS COMPUTERS VIEW Issue BFP-12417 - APAR IJ14037 - COMPUTERNAME, ISLOCKED, LASTREPORTSENT COLUMNS INTO COMPUTERS TABLE MIGHT BE NOT UPDATED Issue BFP-12516 - APAR IJ14145 - REMOVE % ENCODING IN ACTION PARAMETER QUERY Issue BFP-12520 - APAR IJ14273 - FIXLET "ENSURE XINETD IS NOT ENABLED" INCORRECTLY REPORTING Issue BFP-12596 - APAR IJ14469 - IMAGE PATH OF INSPECTOR COULD FAIL ON WINDOWS Issue BFP-12614 - APAR IJ14503 - INFORMATION MISSING IN SAML CONFIGURATION PAGE Issue BFP-12628 - APAR IJ14563 - CLARIFY THE DIFFERENCE BETWEEN THE PURGEDELETEDCOMPUTERS AND REMOVEDELETEDCOMPUTERS OPTIONS OF COMPUTER REMOVER TOOL Issue BFP-12678 - APAR IJ14673 - ENCODING CLARIFICATIONS ON XML DOM DOCUMENT INSPECTORS Issue BFP-12692 - APAR IJ14748 - HARDWAREUUID NOT SHOWN CORRECTLY IN CLIENT INSPECTOR Issue BFP-12770 - APAR IJ15015 - REGISTRY BUFFERDIR PATH ON 32BIT RELAYS NOT CORRECTLY DOCUMENTED Issue BFP-12772 - APAR IJ15024 - USING SAML AUTHENTICATION, THE RELAY HEALTH DASHBOARD DOESN'T WORK PROPERLY Issue BFP-12837 - APAR IJ15086 - DOCUMENTATION ON "MAINTENANCE WINDOW" SHOULD BE IMPROVED Issue BFP-12838 - APAR IJ15097 - MAXIMUM VALUE OF THE KEY LENGHT FOR BIGFIX WEB REPORTS IS 2048 BITS Issue BFP-12933 - APAR IJ15383 - CUSTOMIZED VALUES OF _WEBREPORTS_HTTPSERVER_HOSTNAME SETTING CAN BE OVERWRITTEN DURING UPGRADE Issue BFP-12986 - APAR IJ15441 - MISLEADING DOCUMENTATION TO EXPORT WEB REPORTS ARE PDF Issue BFP-13051 - APAR IJ15563 - SERVER BACKUP PROCEDURE INCLUDES WRONG RESTORE COMMANDS Issue BFP-13056 - APAR IJ15894 - THE CALENDAR IS NOT CORRECTLY DISPLAYED IN WEB REPORTS 9.5.12 Issue BFP-13066 - APAR IJ15947 - BIGFIX CLIENTQUERYRESULTS VIA REST API RETURNS RESULTS Issue BFP-13064 - APAR IJ15949 - WEB REPORTS - ONLY ADMIN CAN MODIFY DASHBOARD DATASTORE Issue BFP-13067 - APAR IJ15951 - ON LINUX, FILLDB MAY FAIL TO UPLOAD DATA INTO THE TABLES Issue BFP-13060 - APAR IJ15952 - ON LINUX INSTALLATION, UNDER PARTICULAR CONDITIONS, THE SAME OBJECT ID MIGHT BE USED FOR TWO NEW OBJECTS Issue BFP-13070 - APAR IJ15954 - PERFORMANCE DEGRADATION SUBMITTING REST API REQUESTS Issue BFP-13152 - APAR IJ16149 - CLARIFY HOW MANAGE CUSTOM SETTINGS DURING A BACKUP/RESTORE PROCEDURE ON LINUX Issue BFP-9963 - APAR IV76920 - IN NON-ENGLISH ENVIRONMENT, WEBREPORTS FILTER SELECTION IS NOT PROPERLY DEFINED Issue BFP-9959 - APAR IV89989 - ON WINDOWS, INSTALLATION/UPGRADE OF BES SERVER CAN FAIL IF THE DB USER DOESN'T HAVE RIGHT PERMISSIONS TO ACCESS/MODIFY THE DB Issue BFP-10038 - APAR IV94485 - ON WINDOWS SYSTEMS, THE DEVICE TYPE PROPERTY DOESN'T RETURN THE EXPECTED VALUE IF WMI IS NOT AVAILABLE Issue BFP-10120 - APAR IV99815 - IT IS NOT ALLOWED TO MODIFY THE OPERATOR PERMISSIONS FOR EXTERNAL SITES USING REST API Other Bugs fixed: Issue BFP-9539 - CDT isn't able to manage hostname with special characters Issue BFP-9581 - Missing the .pdf extension on some reports when using the "Export to PDF" Issue BFP-10768 - ConnectivityTest doesn't work correctly Issue BFP-12125 - WebReports: upgrade deletes PasswordComplexityRegex registry key Issue BFP-12126 - WebReports: upgrade overwrites possible customization of _WebReports_HTTPServer_HostName Issue BFP-11859 - Wrong user permissions for a MO created by BESAdmin.exe Issue BFP-11887 - RPM inspectors don't work on SLES 15 Issue BFP-12308 - Operator APIs cannot handle some characters Issue BFP-12712 - 9.5 "Replication credentials mismatch" warning during the Linux DSA Server install Issue BFP-12894 - Provide transactional robustness to the property id creation Issue BFP-12964 - Upgrade from 9.2 to 9.5 fails on Linux because the DB2 password with weird chars Issue BFP-13052 - Improve performance during API GET fixlet request ============================================ = Changes between 9.5.11.191 and 9.5.12.68 = ============================================ Security enhancements: Issue BFP-11529 - CVE-2012-5883 CVE-2012-6708 CVE-2015-9251 (APARS IJ09720 and IJ09102) Issue BFP-11785 - CVE-2018-5407 Issue BFP-11875 - CVE-2019-4013 APARs addressed: Issue BFP-12290 - APAR IJ13321 - DOCUMENTATION IS NOT CLEAR ON HOW TO ENABLE ENHANCED SECURITY ON DSA SERVER FOR LINUX AND WINDOWS Issue BFP-12274 - APAR IJ13252 - INCORRECT DOCUMENTATION ABOUT CLIENT ENCRYPTION FOR LINUX Issue BFP-12272 - APAR IJ13253 - WINDOWSCHARACTERSETRESULT ERROR IS GENERATED WHILE DELETING SOME SPECIFIC ACTIONS FROM THE CONSOLE Issue BFP-12248 - APAR IJ13194 - HE ACTION TO UPGRADE WINDOWS 10 VERSION MAY FAIL AFTER THE REBOOT Issue BFP-12157 - APAR IJ13111 - THE CLIENT SETTING _BESCLIENT_CRYPTOGRAPHY_FIPSMODE NEEDS TO BE DOCUMENTED WITH MORE DETAILS Issue BFP-12155 - APAR IJ13105 - MISSING CLIENT PRE-REQUISITE INFORMATION ON SUSE 11 PPC64 Issue BFP-12072 - APAR IJ12905 - LIMITATIONS OF ACTION SCRIPT "ADD NOHASH PREFETCH ITEM" Issue BFP-12004 - APAR IJ12579 - WRONG DEFAULT VALUE FOR _BESCLIENT_COMM_PROXYAUTODETECT PARAMETER Issue BFP-12003 - APAR IJ12713 - BIGFIX CONFIGURATION GUIDE REPORTS A WRONG DEFAULT VALUE FOR _BESCLIENT_RESOURCE_WORKNORMAL Issue BFP-11950 - APAR IJ12547 - CONSOLE PERFORMANCE MAY BE AFFECTED, IF OPERATORS HAVING PERMISSION TO STOP OTHER OPERATORS'S ACTIONS ARE DEFINED Issue BFP-11896 - APAR IJ12124 - "RELEVANCE SUBSTITUTION ERROR" WHEN DEPLOYING IBM BIGFIX PROXY AGENT. Issue BFP-11882 - APAR IJ12151 - INCORRECT INFO IN THE "ACTION INFO" VIEW Issue BFP-11844 - APAR IJ11915 - VALUE SPECIFIED FOR THE BESGATHERDOWNLOAD_TIMEOUTSECONDS SETTING DOES NOT OVERWRITE THE DEFAULT Issue BFP-10611 - APAR IJ07702 - IN BIGFIX CONSOLE, THE BASELINE OFFER TAB DOESN'T SHOW THE DEFINED DESCRIPTION MESSAGE WHILE TAKING THE ACTION Issue BFP-9981 - APAR IV91595 - BESSERVER CANNOT PROPAGATE ACTIONS DUE TO "CLASS ILLEGALFILENAME" ERROR ============================================ = Changes between 9.5.10.79 and 9.5.11.191 = ============================================ Security enhancements: Issue BFP-10554 - CVE-2018-0732 Issue BFP-11851 - CVE-2018-0737 Issue BFP-11298 - CVE-2018-14618 Issue BFP-11786 - CVE-2018-1000301 APARs addressed: Issue BFP-9953 - APAR IV82741 - WEB REPORTS LDAP USER BLOCKED BECAUSE LOCAL USER ALREADY EXISTS Issue BFP-9975 - APAR IV89157 - JP WEBREPORT 9.5 SHOWS ENGLISH CHARACTERS AFTER SORTING Issue BFP-10190 - APAR IJ03325 - CLIENT UI CONFIRMATION DIALOG HAS "RESTART NOW" INSTEAD OF "OK" WHEN THE ACTION CONTAINS A RESTART POST-ACTION Issue BFP-10223 - APAR IJ04884 - FIXLET DEBUGGER CRASHES ON A SPANISH WINDOWS SYSTEM WHEN THE WMI QUERY IS NOT VALID Issue BFP-10258 - APAR IJ06248 - BIGFIX REST API CALL RETURNS DELETED FIXLETS AS RELEVANT FOR A COMPUTER Issue BFP-10424 - APAR IJ06409 - BIGFIX REST API CALL UPDATES EXTERNAL SITES SETTING WRONG SITE VISIBILITY Issue BFP-10425 - APAR IJ06673 - BIGFIX ROOTSERVER ON WINDOWS SHOWS PERFORMANCE ISSUES WHEN RUNNING SOME SQL QUERIES Issue BFP-10581 - APAR IJ07575 - ON A WINDOWS JAPANESE MACHINE, SOME WINDOWS REGISTRY KEY VALUES CAUSED THE CRASH OF THE BIGFIX AGENT Issue BFP-10580 - APAR IJ07576 - AIX BIGFIX INSPECTOR 'LOGICAL VOLUME OF FILESYSTEMS' ERROR WITH MULTIBOS Issue BFP-10641 - APAR IJ07801 - RESULT TRUNCATED FOR 'KEY OF FILE' INSPECTOR ON LINES CONTAINING SEMICOLONS Issue BFP-10823 - APAR IJ08130 - MAC COMPUTERS NOT POSTING BACK TO BIGFIX Issue BFP-11110 - APAR IJ09056 - BIGFIX CLIENT CAN SLOWING DOWN WHEN CPU CONTROL CLIENT SETTINGS ARE ACTIVE Issue BFP-11198 - APAR IJ09653 - LAST REPORT TIME AND OTHER COMPUTERS PROPERTIES NOT REPORTED BY BIGFIX CLIENTS Issue BFP-11253 - APAR IJ09789 - ADMIN TOOL, USELESS ACTION RESULTS OPTION TAKES LONG TIME TO RUN Issue BFP-11252 - APAR IJ09791 - AGENT REGISTRATIONS TO THE BES SERVER MAY FAIL WITH ERROR 1113 IN TRANSCODEU8TOU16 Issue BFP-11305 - APAR IJ10387 - IBM BIGFIX PRE UPGRADE CHECK (VERSION 9.5.10) FIXLET IN BES SUPPORT IS NOT CORRECT AND MAY FAIL IN SOME CONDITIONS Issue BFP-11392 - APAR IJ10607 - UPDATE THE PROXY SETTINGS NAME INTO BESSERVER.CONFIG FILE Issue BFP-11435 - APAR IJ10626 - RACE CONDITION CAN RANDOM LEAD WEB REPORTS SERVICE TO CRASH Issue BFP-11448 - APAR IJ10671 - IN WEBREPORTS, IT IS NOT POSSIBLE TO MOVE CHARTS CREATED WITH THE CHART WIZARD Issue BFP-11489 - APAR IJ10785 - INSTALLATION GUIDE DOES NOT MENTION COMPUTER BROWSER SERVICE Issue BFP-11551 - APAR IJ11091 - BIGFIX CLIENTS MAY STOP WORKING WHEN RETRIEVING INFORMATION FROM DOMAIN CONTROL Issue BFP-11580 - APAR IJ11354 - SOAP API FAILS RETRIEVING A RESULT WITH NON-PRINTABLE CHARACTERS Issue BFP-11749 - APAR IJ11524 - ONLY ADMINISTRATOR USER CAN CREATE NEW LABELS IN WEB REPORTS Issue BFP-11868 - APAR IJ12043 - DOCUMENTATION ABOUT LINUX CLIENT REPORTS ENCRYPTION IS NOT CORRECT Other Bugs fixed: Issue BFP-11009 - Update WebUI database config fixlet Issue BFP-10981 - WebUI: Updated Platform Server Components fixlet 'fixed' for standalone WebUI but doesn't work Issue BFP-10721 - sql instance name and port in webui update/install fixlets redundance Issue BFP-11043 - Relay diagnostics fails if Relay authentication defined Issue BFP-9911 - Missing message in Relay Diagnostic request Issue BFP-7511 - saml reauthenticate embedded console login window remains after logging in again when using ibm isam idp Issue BFP-9051 - BESRemove shows that all products are installed, while only a Client is installed on a box Issue BFP-7880 - Besremove doesn't delete the MSSQL Job Issue BFP-9666 - Action constraint information can be misinterpreted Issue BFP-9866 - BES schema on linux platform has an invalid extension Issue BFP-11579 - IBM Bigfix Relay Health Check not working Issue BFP-8015 - The fixlet for manual upgrade of RedHat Server components is missing an architecture check Issue BFP-9727 - CDT Dashboard is not usable when accessed directly in Console Issue BFP-9908 - Fixlet 3284 "Install IBM BigFix Relay on Linux and UNIX" is not relevant on Ubuntu 18.04 Issue BFP-9473 - Linux server upgraded from 9.5.6 to 9.5.7 has some duplicated PROCEDURES in the database Issue BFP-10443 - When you create a new role via RESTAPI, default is ComputerAssignments=AllComputers Issue BFP-10988 - It is not possible to install Server+WR without WebUI with linux installer Issue BFP-10961 - WebUI gather fails on RHEL installation of remote WR and WebUI Issue BFP-9552 - Airgap CLI: Airgap fails when the name of folder contains non ascii character Issue BFP-9553 - Can create Computers group with duplicate name using REST API =========================================== = Changes between 9.5.9.62 and 9.5.10.79 = =========================================== Security enhancements: Issue BFP-10555 - CVE-2018-0739 Issue BFP-397 - CVE-2018-1474 Issue BFP-393 - CVE-2018-1476 Issue BFP-391 - CVE-2018-1478 Issue BFP-403 - CVE-2018-1480 Issue BFP-402 - CVE-2018-1481 Issue BFP-401 - CVE-2018-1484 Issue BFP-395 - CVE-2018-1485 Issue BFP-376 - CVE-2017-1231 APARs addressed: Issue BFP-10151 - APAR IJ00754 - RELAYS DISCARD REPORTS WHILE THE PARENT RELAY OR THE SERVER IS STOPPED Issue BFP-10157 - APAR IJ00768 - "COMMAND LINE ARGUMENT 1 OF PROCESS " NOT RETURNING EXPECTED RESULTS ON SOLARIS ENDPOINTS Issue BFP-10172 - APAR IJ01299 - START AND END TIME ARE ALWAYS DISPLAYED IN CLIENT LOCAL TIME IN THE ACTION SUMMARY PANEL Issue BFP-10212 - APAR IJ04540 - CONNECTIVITY TEST POLLS PERIODICALLY THE SERVER EVEN IF IT IS NOT THE PARENT COMPONENT Issue BFP-10211 - APAR IJ04541 - FOLDERS CREATED UNDER BIGFIX UPLOADS DIRECTORY ARE NOT DELETED Issue BFP-10213 - APAR IJ04555 - MULTI-BYTE CHARACTERS IN VERSION FIELD ARE NOT PROPERLY DISPLAYED IN SELF-SERVICE APPLICATION. Issue BFP-10227 - APAR IJ04972 - BESCLIENT MAY CRASH ON SOLARIS OS IF CLIENT DEBUG LOGGING IS ENABLED Issue BFP-10236 - APAR IJ05144 - BES CLIENT HANGS IF WMI SERVICE DOES NOT RETURN BACK FROM A QUERY Issue BFP-10240 - APAR IJ05492 - WRONG PROCESS DATA REPORTED BY QNA AFTER ENABLING APPLICATION USAGE SUMMARY Issue BFP-10241 - APAR IJ05494 - ON AIX, THE CPUPACKAGE INSPECTOR MAY RETURN INCORRECT VALUES Issue BFP-10242 - APAR IJ05497 - WEBREPORTS SCHEDULED ACTIVITIES DO NOT RESPECT THE LIMIT OF ENTRIES TO KEEP Issue BFP-10187 - APAR IJ05679 - ON UNIX, BESCLIENT MIGHT HANG WHILE MANAGING QNA PROCESS Issue BFP-10247 - APAR IJ05780 - AFTER UPGRADE CLIENTS REPORT UNCAUGHT EXCEPTION IN PLUGIN Issue BFP-10248 - APAR IJ05883 - UNIX BESCLIENT ENTERS IN FROZEN STATE AND BECOMES UNRESPONSIVE Issue BFP-10250 - APAR IJ05917 - GROUPS OF PROPERTY VALUES IN WEB REPORTS CHART CONFIGURATION PANEL NOT SHOWN ON RELOAD Issue BFP-10252 - APAR IJ05931 - SCRIPT ERROR OCCURRED WHEN TRYING TO DISPLAY THE CLIENT DEPLOY TOOL DASHBOARD IN BIGFIX CONSOLE Issue BFP-10254 - APAR IJ06170 - Missing documentation of configuration parameter _BESDATASERVER_AUTHENTICATIONTIMEOUTMINUTES Issue BFP-10257 - APAR IJ06210 - PARTIAL RESULTS ARE RETURNED FROM A WEBREPORTS QUERY WHEN MULTIPLE DATASOURCES ARE SELECTED Issue BFP-10263 - APAR IJ06235 - BIGFIX CONSOLE CRASHES DUE TO INCORRECT UI INITIALIZATION Issue BFP-10256 - APAR IJ06284 - CREATE ACTIONS' PRIVILEGES REQUIRED FOR NMO TO 'REMOVE COMPUTERS FROM DATABASE' Issue BFP-10428 - APAR IJ06667 - VOLUME GROUP NOT SHOWN BY AIX BIGFIX AGENT Issue BFP-10433 - APAR IJ06711 - BESCLIENT SHOWS HIGH CPU USAGE WHILE RESETTING DATES FOR CONFIGURATION PARAMETERS Issue BFP-10407 - APAR IJ06811 - BES COMPUTER REMOVER TOOL UNEXPECTED BEHAVIOR REMOVING COMPUTERS BY NAME Issue BFP-10408 - APAR IJ06926 - WEB REPORTS COULD CRASH EVALUATING RELEVANCE EXPRESSIONS INCLUDING THE 'BES COMPUTER GROUP' INSPECTOR Issue BFP-10328 - APAR IJ06968 - BESEMAILER SHOULD NOT BE CALLED WITH .TMP FILES AS ARGUMENT Issue BFP-10432 - APAR IJ07057 - LINUX BIGFIX AGENT PROBLEM WITH DMI INSPECTORS Issue BFP-10421 - APAR IJ07161 - DUPLICATION OF FILESYSTEMS OR DRIVES REPORTED BY BIGFIX INSPECTOR ON LINUX Issue BFP-10496 - APAR IJ07388 - UNIX BIGFIX INSPECTOR ERROR EVALUATING GROUP NAME OF Issue BFP-10658 - APAR IJ07881 - CLIENTUI DOES NOT UPDATE CUSTOM CLIENT DASHBOARD Issue BFP-10655 - APAR IJ07882 - TO INSTALL A NON WINDOWS CLIENT WITH CDT AND A SUDOER USER, THE SUDOER USER NEEDS TO BE CONFIGURED AS NOT REQUIRING TTY. Issue BFP-10824 - APAR IJ08249 - BIGFIX RPM INSPECTOR 9.5.9 FAILS COMPARING VERSION RECORDS Issue BFP-10079 - APAR IV96807 - ERROR ASSIGNING A COMPUTER TO ROLE IN CONSOLE WHEN COMPUTER IS SELECTED "BY RETRIEVED PROPERTY > BY COMPUTER NAME" DRILL DOWN Other Bugs fixed: Issue BFP-10572 - Missing file "BESHostname.id" on AIX client Issue BFP-9803 - Double response of some client after submitting a query =========================================== = Changes between 9.5.8.38 and 9.5.9.62 = =========================================== Added support for BigFix agent and relay on AIX 7.2 on Power 9 Security enhancements: Issue 162641 - CVE-2018-1471 Issue 162645 - CVE-2018-1473 Issue 162651 - CVE-2018-1479 Issue 162652 - CVE-2018-1475 APARs addressed: Issue 163141 - APAR IJ04288 - IBM BIGFIX PRE UPGRADE CHECK (VERSION 9.5.8) TASK FAILS WHEN THE ODBC DRIVER CREDENTIALS ARE DIFFERENT FROM THE DEFAULT Issue 164201 - APAR IJ04473 - CLIENT DEPLOY TOOL WIZARD RETURNS JAVASCRIPT ERROR Issue 155235 - APAR IJ00576 - STARTING SELF IMPOSED CLIENT RESTART - DOES NOT RESTART CLIENT - SUN SOLARIS Issue 155857 - APAR IJ00623 - UNDER SPECIFIC CONDITIONS THE ACTION REGSET COMMAND DOES NOT CREATE THE VALUE NAME Issue 155646 - APAR IJ00640 - BESCLIENT SHOWS CPU PEAKS WHEN REFRESHING PROCESS TABLES Issue 155950 - APAR IJ00699 - ERROR DURING FILE UPLOADS IF CHUNKSIZE PARAMETER IS SET TO ZERO Issue 157453 - APAR IJ01479 - PROXY PASSWORD IS SWIPED OUT WHEN CHANGING MANUALLY THE DB2 PASSWORD IN BESSERVER.CONFIG Issue 158348 - APAR IJ02101 - EXCEPTION IN WEB REPORTS 'MY AUTHORED' PAGE IF CURRENT OPERATOR HAVE NOT SAVED REPORTS ASSIGNED Issue 158946 - APAR IJ02231 - CONSOLE ERROR IMPORTING A PACKAGE IN SOFTWARE DISTRIBUTION DASHBOARD Issue 162909 - APAR IJ02721 - UPLOADED CLIENTS FILES CAN BE OVERWRITTEN WITH AN OLDER VERSION OF THE SAME FILES IF DSA IS CONFIGURED Issue 159517 - APAR IJ02753 - COMPUTER//FIXLETS REST API RETURNS FURTHER OBJECTS OTHER THAN FIXLETS AND TASKS Issue 159519 - APAR IJ02831 - FILLDB LINUX WIDETOMULTIBYTECONVERTERROR EXCEPTION BUILDING PROPERTIES STATISTICS Issue 161886 - APAR IJ03578 - BESCLIENT V9.2.0.375 SOLARIS 10-11 MISSING DEPENDENCIES Issue 161956 - APAR IJ03867 - CUSTOM SITES DO NOT WORK PROPERLY IF A SITE WITH THE SAME NAME WAS ALREADY CREATED AND DELETED Issue 163090 - APAR IJ04104 - SORTING ON ASSIGNED ROLES DOES NOT WORK ON WEBREPORTS Issue 163004 - APAR IJ04235 - ON LINUX/DB2 DEPLOYMENTS, YOU MAY EXPERIENCE ISSUES LOGIN TO BESCONSOLE Issue 163333 - APAR IJ04414 - FIXLETS, TASKS AND BASELINES WITH 'RELEVANCE GROUP' EXPORTED VIA REST API CANNOT BE RE-IMPORTED Issue 163994 - APAR IJ04493 - THE PROPAGATEFILES.EXE FAILS TO PROPAGATE FILEONLYCUSTOMSITE STARTING FROM BIGFIX 9.5.5 Issue 164126 - APAR IJ04539 - ON WEBREPORTS, THE USER MANAGEMENT PAGE FOR LDAP ACCOUNTS DOESN'T PROPERLY SHOW THE RESULTS Issue 164550 - APAR IJ04756 - LOAD LIBRARY ERROR OCCURS EXECUTING RPM VERSION AND RELEASE COMPARISON INSPECTORS ON PPC64 AGENTS Issue 164562 - APAR IJ04775 - IN BIGFIX, IF MANY PROPERTIES ARE DEFINED, WEBREPORTS CANNOT FILTER ON PROPERTIES IN EXPLORE COMPUTERS REPORT Issue 164563 - APAR IJ04776 - IN BIGFIX, IF MANY PROPERTIES ARE DEFINED, CONSOLE CANNOT SHOW THE 'COLUMN PICKER' FILTER IN THE COMPUTERS VIEW Issue 164749 - APAR IJ04861 - CONTENTS OF BESAPI AND BES SCHEMAS ARE INVERTED ON BIGFIX SERVER Issue 164947 - APAR IJ04927 - PROCESS USAGEDATA DIRECTORY GROWS ON SOLARIS 5.10 I386 Issue 165366 - APAR IJ05039 - CLIENT RE-REGISTRATION MIGHT FAIL WITH A DATABASE EXCEPTION Issue 165512 - APAR IJ05106 - BESROOT SERVER CRASHES WHILE RECREATING MAILBOX Issue 165538 - APAR IJ05138 - ON LINUX CLIENT, CPU SPIKES TO 100 PERCENT WHEN THE INSPECTOR 'NETWORK' SCANS A LOT OF CONNECTIONS Issue 166236 - APAR IJ05332 - BESCLIENT 9.5.8 MAY FAIL TO START DUE TO AN ERROR LOADING LIBBESCRYPTO.DLL Issue 166033 - APAR IJ05448 - BIGFIX CLIENTS ON MAC CAN BE IN CONSTANT STATE OF RESTART Issue 145554 - APAR IV96737 - BIGFIX SERVER DIAGNOSTIC IS UNABLE TO DETERMINE IF TCP/IP IS ENABLED EVEN IF THE NAMED INSTANCE OF MSQL SERVER IS ONLY ONE Issue 145966 - APAR IV96846 - EDITCOMPUTERSETTINGS IS INCORRECTLY ENABLED FOR OPERATORS NOT HAVING CUSTOM CONTENT PERMISSIONS Issue 149873 - APAR IV98331 - LINUX WEBREPORT CANNOT IMPORT CUSTOM REPORT IF THE REPORTXML COLUMN EXCEEDS 1MB Issue 150837 - APAR IV98759 - MANUAL COMPUTER GROUP NAME WITH SQUARE BRACKET CAUSES UNIX AGENTS MALFUNCTION Issue 153314 - APAR IV99736 - BIGFIX INSPECTOR UNABLE TO RETRIEVE THE ADMIN PRIVILEGE FOR A DOMAIN USER Issue 153329 - APAR IV99792 - ON THE CONSOLE, AN ERROR OCCURS EXPANDING BY ACTIVE DIRECTORY PATH PROPERTY, IF THE AD PATH IS INVALID Other Bugs fixed: Issue 159942 - Fix Windows latform BIOS inspector Issue 153966 - Error logged by WebReports if an AD user with filters is deleted at WR level Issue 159724 - Instances of Application Usage Summary wrongly calculates values for the same process in many paths =========================================== = Changes between 9.5.7.90 and 9.5.8.38 = =========================================== Added support for BigFix relay on TinyCore v8.2 Added support for BigFix agent and relay on Windows 10 Fall Creators Update Security enhancements: Issue 154050 - CVE-2017-3735 Issue 154062 - CVE-2017-1000100 Issue 156914 - CVE-2017-1000254 APARs addressed: Issue 158951 - APAR IJ02575 - WINDOWS PROCESS TABLE NEEDS TO HAVE THE USAGE OF TOOLHELP32 LIBRARY CONFIGURABLE Issue 158184 - APAR IJ02017 - IN BIGFIX LINUX/DB2 ENVIRONMENT, IT IS NOT POSSIBLE TO UPLOAD MDT BUNDLES FROM OSD DASHBOARD Issue 158115 - APAR IJ01960 - INSTALL/UPDATE IBM BIGFIX CLIENT DEPLOY TOOL FIXLETS SHOULD NOT HAVE A "CRITICAL" SOURCE SEVERITY Issue 157559 - APAR IJ01315 - MFE FILE PERMISSION ERRORS IN MAC OS BIGFIX CLIENTS Issue 156633 - APAR IJ01000 - THE CONSOLE MAY NOT SHOW THE PRESETS IN EXECUTION TAB Issue 156435 - APAR IJ00917 - BEST PRACTICES FOR USERS ON Z/VM VIRTUALIZED ENVIRONMENTS Issue 156376 - APAR IJ00872 - CONSOLE CRASH WHEN USING SOFTWARE DISTRIBUTION SELF SERVICE PORTAL AND REQUIRECONFIRMACTION OPTION IS IN PLACE Issue 156125 - APAR IJ00819 - FILLDB SLOWS DOWN UPDATING COMPUTER ADMINISTRATORS DATA Issue 155239 - APAR IJ00461 - THE BIGFIX BRAND ICON OF 32 X 32 PIXELS IS CROPPED TO 30 PIXELS WIDE Issue 155155 - APAR IJ00453 - THE BES PLATFORM API IMPORTACTION RETURNS THE "NOSUCHSIDEID" ERROR Issue 154802 - APAR IJ00474 - DSA REPLICATION MAY FAIL ON TABLE MAILBOX_FILES IF THE MAILBOX FILE TARGETING IS GREATER THAN 1MB. Issue 154789 - APAR IJ00457 - BASELINES, CREATED IN CONSOLES HAVING A LANGUAGE DIFFERENT FROM THE FXF CHARSET, CANNOT RUN AS OFFERS Issue 154275 - APAR IJ00235 - CLIENT COMPLIANCE API NOT RESPONDING CORRECTLY Issue 154187 - APAR IJ00199 - IF THE BESCLIENT FILE SYSTEM GOES TEMPORARILY IN READ-ONLY MODE, DUPLICATED COMPUTERS MAY BE CREATED Issue 153692 - APAR IV99834 - THE MESSAGE TITLE OF THE CONFIRMATION REQUIRED DIALOG IN THE CLIENT UI IS TRUNCATED WHEN TOO LONG Issue 153443 - APAR IV99808 - SPECIFIED INTERVAL FOR STAGGERING ACTIONS NOT BEING HONORED Issue 153206 - APAR IV99765 - THE LOGIN PAGE ON LINUX WEBREPORTS THROWS AN ERROR WHEN LOGGING IN FROM A REMOTE SYTEM AND NO LOCAL OPERATOR IS DEFINED Issue 152591 - APAR IV98967 - LONG RUNNING RELEVANCE FOR UPLOAD MANAGER DIRECTORY SIZE CALCULATIONS Issue 138600 - APAR IV93612 - ON RHEL, WEBREPORTS FAILS TO SEND EMAIL WITHOUT GENERATING AN ERROR Issue 134289 - APAR IV91535 - UNUSED FILES ARE NOT REMOVED FROM THE UPLOADMANAGERDATA FOLDER Other Bugs fixed: Issue 129040 - Table COMPUTER_REGISTRATIONS is never cleared by Computer Remover Issue 154203 - Improve cleanup tasks Issue 155749 - Provide a fixlet to run some pre-checks on the DB =========================================== = Changes between 9.5.6.63 and 9.5.7.90 = =========================================== Security enhancements: Issue 141754 - CVE-2017-1220 Issue 141254 - CVE-2017-1225 Issue 149246 - CVE-2017-1521 Issue 141764 - CVE-2017-1226 Issue 141257 - CVE-2017-1228 Issue 141762 - CVE-2017-1230 Issue 141256 - CVE-2017-1232 APARs addressed: Issue 154276 - APAR IJ00274 - FILLDB PERFORMANCE DEGRADATION, DUE TO LONG TIME REPORT PARSING Issue 154464 - APAR IJ00326 - WEBREPORTS AND CONSOLE MAY CRASH WHILE RUNNING A RELEVANCE QUERY ON THE IP ADDRESS PROPERTY Issue 154801 - APAR IJ00473 - CONSOLE MAY CRASH WHEN CREATING AN ANALYSIS USING FIXLET FROM ILMT SITE Issue 131818 - APAR IV67976 - ACTION CONFIGURED AS AN OFFER APPEARS ON CLIENT UI EVEN IF THE START TIME HAS NOT BEEN REACHED Issue 131821 - APAR IV77632 - ERROR SIGNEDDATAVERIFICATIONFAILURE ON ROLES TABLE Issue 131823 - APAR IV81045 - POST REST API REQUIRES THE ID FOR AN EXISTING OBJECT Issue 131831 - APAR IV89975 - ERROR IN DESERIALIZING BODY OF REPLY MESSAGE FOR OPERATION 'GETRELEVANCERESULT'" WHEN USING BIGFIX SOAP API Issue 134528 - APAR IV91536 - BIGFIX CONSOLE OPERATORS ARE UNABLE TO LOGIN, DUE TO A 'REQUIREMENT FAILURE' ERROR Issue 137911 - APAR IV93393 - BIGFIX SERVER CAN RUN OUT OF DISK SPACE DUE TO THE AMOUNT OF SERVER_AUDIT.LOG FILES Issue 138234 - APAR IV93412 - SLOW EVALUATION CYCLE FOR CLIENTS 9.5.X WHEN USING "LINES OF FILE" INSPECTOR Issue 140251 - APAR IV94316 - BIGFIX CLIENT DOES NOT REBOOT IF THE OPERATING SYSTEM IS A WINDOWS 2012 CORE Issue 140528 - APAR IV94356 - FROM BES CONSOLE THE VALUE OF THE CLIENT SETTING CANNOT EXCEEDS 256 BYTES Issue 141332 - APAR IV94756 - DURING WEBREPORTS INSTALLATION THE WEBREPORTS USER DOMAIN NAME IS NOT EDITABLE Issue 141577 - APAR IV94902 - OPERATOR REMOVAL AT AD/LDAP LEVEL CAN CAUSE PROBLEMS IN ACCESSING THE REPORT LIST PAGE ON WEBREPORTS Issue 143326 - APAR IV95719 - THE BIGFIX NETWORK VIZUALIZATION TOOL IS USELESS AND HAS TO BE REMOVED FROM THE CONSOLE Issue 145744 - APAR IV96100 - PROXY AGENT STILL EVALUATES THE OLD CONTENT Issue 145305 - APAR IV96370 - AIX OBJECT REPOSITORY REPORTING OLD INFORMATION Issue 144865 - APAR IV96460 - ERROR LOGGED BY WEBREPORTS IF AN OPERATOR WITH FILTERS IS DELETED AT AD/LDAP LEVEL Issue 145326 - APAR IV96592 - CHANGES TO TIME SPAN IN WEB REPORT ARE NOT REFLECTED IN CHARTS Issue 146084 - APAR IV96915 - CONSOLE MAY CRASH WHEN DISPLAYING DETAILS OF SOME CLIENTS Issue 146530 - APAR IV97078 - WEBREPORTS SERVER MAY THROWS NOTANUMERAL EXCEPTION WHEN REMOTE DATABASE IS USED ON WINDOWS Issue 147325 - APAR IV97257 - 9.5.5 CLIENT DEPLOYMENT TOOL SHOWS ENGLISH WINDOWS INSTEAD OF JP IN JAPANESE ENVIRONMENT Issue 147186 - APAR IV97285 - WEBREPORTS CANNOT SEND EMAILS FOR SCHEDULED ACTIVITIES WITH SOME SMTP SERVERS Issue 147434 - APAR IV97313 - DATETIME TYPE IS NOT DEFINED IN BES.XSD Issue 147741 - APAR IV97473 - QNA TOOL GRAPHICAL TAB UNABLE TO PROCESS THE "PIPE" OPERATOR Issue 147785 - APAR IV97499 - INACCURATE SUB ACTIONS STATE FOR MULTIPLE ACTION GROUPS USING A SESSION RELEVANCE QUERY Issue 147784 - APAR IV97501 - INCORRECT NUMBER OF CRITICAL FIXLETS/TASKS REPORTED ON CONSOLE Issue 148620 - APAR IV97699 - REINDEX JOB MAY FAIL IF A TABLE NAME IS GREATER THAN 50 CHARACTERS Issue 150844 - APAR IV97718 - Percent encoding value may make Baseline not relevant Issue 148736 - APAR IV97912 - ON LINUX IS MISSING THE CAPABILITY TO CREATE A MASTER OPERATOR OUTSIDE THE CONSOLE Issue 149247 - APAR IV98137 - LOCKED MACHINES CAN SUBSCRIBE BUT NOT UNSUBSCRIBE FROM BES SITES Issue 149883 - APAR IV98232 - BESCLIENT MAY CRASH WHILE USING THE 'REGEX' INSPECTOR Issue 149872 - APAR IV98242 - NCORRECT SYNCHRONIZATION BASELINE WARNING WITH NON-ENGLISH CHARS Issue 149878 - APAR IV98329 - BIGFIX CLIENT 9.2 UNICODE HANDLING IN A 9.5 DEPLOYMENT Issue 150523 - APAR IV98667 - FILE DOWNLOAD CAN FAIL WITH HTTP ERROR 28 IN CASE OF SLOW NETWORK Issue 151708 - APAR IV98765 - BIGFIX CONSOLE FREEZES MAY OCCURS WHEN FILTERING ON COMPUTERS VIEW Issue 152589 - APAR IV99114 - INSTALLING BIGFIX IN NON DEFAULT LOCATION ON LINUX Issue 152971 - APAR IV99691 - CONSOLE OR SERVER CRASH DUE TO A MISSING SUCCESSCRITERIA IN A BASELINE COMPONENT Issue 153207 - APAR IV99766 - REINDEX JOB ERROR BECAUSE PAGE LEVEL LOCKING IS DISABLED Other Bugs fixed: Issue 138680 - Web Report data stops updating until restart Issue 140140 - Space char in the end of an operator's name is allowed during an operator creation, but becomes a reason of a login failure Issue 140554 - Uninstalling Ubuntu relay leaves behind files that should have been removed Issue 141126 - U_TRUNCATED_CHAR_FOUND error with Analysis when multi byte character of relevance crosses 1024 bytes boundary Issue 141816 - Missing Proxy exception list information Issue 141863 - Some REST API dealing with Fixlets and tasks fail on Linux Server Issue 143627 - Track memory usage on Linux server Issue 143810 - Prevent deployment to be 'usable' after a failed upgrade attempt Issue 144667 - On 9.5.5 Upgrade on windows using admin tool without parameters fails if 'sa' db user is not properly configured Issue 146812 - DSA deployment: APP_USERS and APP_ROLES tables don't seem to be replicated entirely Issue 146983 - When minimumSupportedClient value is changed, Relays must pick up a change Issue 147138 - Client which reported to an old parent (Relay 8.2) died on registration when minimumSupportedClient was set to 9.0 Issue 148402 - Unix clients does not remove setting from the obf file when receive a delete action from the console Issue 148621 - Added possibility to run cleanup tools using Besadmin UI on secondary servers Issue 146596 - Changing "Key Exchange Password" requires a relay restart to take effective =========================================== = Changes between 9.5.5.193 and 9.5.6.63 = =========================================== Resigning of Mac Clients with new certificates Console Qualification for Windows 10 Creators Update Security enhancements: Issue 140742 - CVE-2016-9840 Issue 141427 - CVE-2017-1218 Issue 141756 - CVE-2017-1222 Issue 141763 - CVE-2017-1203 Issue 141767 - CVE-2017-1219 APARs addressed: Issue 129082 - APAR IV85510 - BIGFIX CONSOLE NOT WORKING WHEN ONLY TLS 1.2 IS ENABLED, TLS 1.0 NEEDS TO BE ENABLED AS WELL. Issue 131839 - APAR IV78062 - SERVER COMPONENTS AUTOMATIC UPGRADE FIXLET DESCRIPTION DOESN'T CONTAIN REFERENCE TO THE MANUAL UPGRADE FIXLET Issue 133373 - APAR IV90989 - SITE UPDATE FAILURE ON LINUX RELAY DUE TO NOT ENOUGH SPACE ON /TMP Issue 139317 - APAR IV93705 - INVALIDTEXTENCODING ERROR RETURNED BY THE FILESET INSPECTOR WHEN THE NAME CONTAINS JAPANESE CHARACTER Issue 140291 - APAR IV94334 - 9.5 ENDPOINTS MAY HANG WHEN USING "LINES OF FILE" INSPECTOR TO SCAN A FILE THAT IS CONTINUOUSLY UPDATED Issue 140297 - APAR IV94229 - SYMBOLIC LINKS ARE DELETED DURING AIX UPGRADE Issue 140530 - APAR IV94409 - WEBREPORTS ARCHIVE.CSV LINK DOES NOT GENERATE A FILE WITH .CSV EXTENSION Issue 140698 - APAR IV94609 - ON 9.5 USELESS ACTIVITY ON THE SERVER PROPAGATING SITE INFO Issue 141574 - APAR IV94876 - LINUX SERVER UPGRADE SYNTAX REQUIRES FURTHER DETAILS Issue 141580 - APAR IV94874 - BESCLIENT DOES NOT STOP IN SOME SOLARIS ZONE ENVIRONMENTS Issue 143916 - APAR IV95549 - SITE UPDATE FAILURE ON BIGFIX SERVER COMPONENT DUE TO NOT ENOUGH SPACE ON /TMP Issue 144719 - APAR IV96170 - DISK LIMIT EXCEPTION NOT RAISED TO BESCLIENT WHEN SUBMITTING MULTIPLE MAG AND PRECACHESTAGEDISKLIMITMB IS REACHED Issue 146876 - APAR IV97175 - BIGFIX CLIENT ON MAC CANNOT BE INSTALLED BECAUSE THE SIGNING CERTIFICATE EXPIRED Other Bugs fixed: Issue 140609 - Ubuntu relay manually installed does not set correctly custom relay port setting and uses the default 52311 Issue 143033 - BigFix Query not enabled for Detect-only customers Issue 143182 - Inconsistent Result for "match" Inspector in 9.5.5 Issue 143434 - Initialize OpenSSL in Console based on client setting or deployment masthead Issue 143435 - Initialize OpenSSL in Web Reports based on client setting or deployment masthead Issue 143436 - Initialize OpenSSL in CLI based on client setting or deployment masthead Issue 143437 - Initialize OpenSSL in ClientDeployTool based on client setting or deployment masthead Issue 143439 - Initialize OpenSSL during the Evaluation Masthead Creation Issue 143443 - Initialize OpenSSL in BESAPI based on client setting or deployment masthead Issue 143445 - Initialize OpenSSL in FixletDebugger based on client setting or deployment masthead =========================================== = Changes between 9.5.4.38 and 9.5.5.193 = =========================================== Enablement for the BigFix Detect application Client Deploy Tool enhancements Added capability to run Fixlet actions as a specific user and to specify the context for the actions Airgap tool enhancements Enhanced the FillDB component to process agent reports by using a multi-thread approach Added capability for a Non-Master Operator to stop other Non-Master Operator actions Enhanced the BigFix evaluation installation to avoid ripping and replacing the BigFix deployment if transition to production license is needed Enhanced the REST API for Baseline support Enhanced the BigFix agent application usage summary inspector Enhanced the Mac OS version of BigFix agent and inspectors Improved the BigFix database layer to enable direct access from Web UI Enhanced the Client UI end-user experience Enhanced the Self Service application enablement Security enhancements Added support for BigFix relay on Ubuntu 14.04 and 16.04 Intel x86-64 Added support for BigFix server and console on Windows 2016 APARs addressed: Issue 131829 - APAR IV89719 - SOME UPLOADMANAGER CLIENT SETTINGS DO NOT WORK AS DOCUMENTED Issue 131833 - APAR IV90033 - RELEVANCE CONTAINING AN EMPTY DELIMITER FOR THE SENTENCE "SEPARATED BY" MAY HANG Issue 132938 - APAR IV90723 - THE BACKUP, RESTORE AND THE MIGRATION DOCUMENTS DO NOT HANDLE CORRECTLY THE THREE NEW KEYS INTRODUCED IN BIGFIX 9.5.3 Issue 133370 - APAR IV90936 - WINDOWS 10 MACHINES CONTINUE TO REPORT PENDING REBOOT Issue 133377 - APAR IV91024 - CONSOLE MAY CRASH WHILE CLONING AN ACTION TARGETED BY A MANAGED PROPERTY. Issue 133736 - APAR IV91140 - WITH AN HUGE UPLOAD ACTIVITY, THE FILLDB 'SCAN ALL' TASK DOES NOT RESPECT THE CONFIGURED EXECUTION INTERVAL Issue 133753 - APAR IV91151 - SUN SOLARIS 10/11 BES 9.5.3 GOES INTO MAINTENANCE MODE AFTER STOP Issue 133755 - APAR IV91233 - COMPUTER TYPE RESERVED PROPERTY INCORRECTLY EVALUATED ON SOLARIS SYSTEMS Issue 134445 - APAR IV91632 - OUT-OF-SEQUENCE SUB ACTION ID IN MULTIPLE ACTION GROUP (MAG) AFTER PREFETCH PLUGIN FAILURES Issue 134446 - APAR IV91580 - THE 'IBM BIGFIX ACTION REQUESTS' POPUP MESSAGE IN THE BIGFIX CLIENT UI IS DISPLAYED WITH SCROLLING BARS Issue 134545 - APAR IV91717 - AN ERROR MAY APPEAR AT BESCLIENT SERVICE STARTUP, IF THE USERID CONTAINS NON-ASCII CHARACTERS Issue 134587 - APAR IV91720 - INEFFICIENT SQL STATEMENT IN FILLDB MAY CAUSE DEADLOCKS ON SERVER Issue 134588 - APAR IV91723 - "DEFAULT WEB BROWSER" INSPECTOR DOES NOT DETECT DEFAULT BROWSER ON WINDOWS 10 Issue 135840 - APAR IV92312 - FAILURE RETRIEVING PROPERTIES VIA REST API IF "OBSOLETE PROPERTIES" ARE DEFINED IN THE DATABASE. Issue 135936 - APAR IV92521 - VIEW ACTION INFO' ON BIGFIX CONSOLE IS DISPLAYED AS MODAL WINDOW Issue 135937 - APAR IV92549 - MISLEADING ERROR MESSAGE WHEN THE INSPECTOR EVALUATING THE RELEVANCE IS INTERRUPTED Issue 135992 - APAR IV92597 - THE RELEVANCE "PATHNAME OF FILE OF SERVICES" COULD INCORRECTLY RETURNS NO VALUE Issue 136112 - APAR IV92863 - INCONSISTENT RETRY BEHAVIOUR FOR BASELINES Issue 136984 - APAR IV93015 - BIGFIX DOMAIN ICONS IN WEBREPORTS HOME PAGE ARE NOT DISPLAYED USING INTERNET EXPLORER Issue 137067 - APAR IV93098 - NUMERIC VALUE OUT OF RANGE' DATABASE ERROR ON FILLDB LOG Issue 137175 - APAR IV93151 - HIGH NUMBER OF 'INFORMATION EVENTS' GENERATED IN THE EVENT VIEWER LOGGING-IN WITH AD/LDAP OPERATORS WITH BIGFIX 9.5. Issue 137914 - APAR IV93421 - WEB REPORTS ROLE FILTER NOT APPLIED CORRECTLY Issue 137915 - APAR IV93392 - RELAY DIAGNOSTICS PAGE NOT WORKING PROPERLY WITH SOME BROWSERS Issue 138229 - APAR IV93400 - IE11 CONSOLE DASHBOARD COMPATIBILITY ISSUES Other Bugs fixed: Issue 131429 - add check on username to avoid can contain special chars on linux Issue 131131 - CTD proxy settings not set on a Win 32 bit machine Issue 131130 - it should be allowed to delete the proxy settings previously set Issue 131129 - Advanced option "Pull the installation files ...." Issue 131127 - client deploy tool doesn't process IP address ranges correctly Issue 130560 - running or constrained offers vanish from clientui and SSA after a client restart Issue 129682 - Web reports: user name field greyed out in the panel to specify user account Issue 129178 - Description text of the offer tab on the console is truncated in German, Spanish and French translation Issue 128837 - BESAdmin.exe /audittrailcleaner doesn't clean all "Custom Content History" in scheduled mode Issue 128824 - Web Reports User panel of installer not translated Issue 128381 - Manual upgrade SuSe PPC 9.5.2 > 9.5.3 caused warnings for some libraries, which are having "same soname but different type" Issue 126223 - In the Unix ClientUI the "Action Script Preview" and "Description" panels cannot be scrolled down Issue 124580 - FillDB always waits 10s before processing a new batch Issue 124572 - Wrong result FILE inspector for MAC agent Issue 124569 - xqna can't run on console Issue 124550 - UTF-8: cleanup tab performs long query even when no changes were discovered in preview Issue 124548 - TupleStringBuilder::AppendMemberText returns deallocated data Issue 124524 - IEMCLI adds '?' to urls that don't have query parameters, resulting in Resource links in responses containing '?' Issue 123912 - New Tools in the platform log just failure information in BESRelay.log Issue 138224 - Documentation regarding of how to install Linux BigFix Clients is referring to the Client Deploy Tool and is contradictory Issue 136386 - Change Client Deploy Tool usage documentation to reflect GUI changes Issue 135568 - FillDB 9.5.4 exception (ConstDataCapacityExceeded) when processing a BigFix Query report that contains 4K text Issue 135493 - Fix console IE11 compatability issue Issue 135042 - Failed message is not seen when an invalid flag is passed to quarantine file command Issue 134112 - Inconsistent retry behavior for baselines Issue 133734 - Fixlet "Install IBM Bigfix WebUI Service (Version 9.5.4)" missing description for installation parameter Issue 133732 - Relevance of WebUI fixlet "Install IBM Bigfix WebUI Service" Issue 133388 - BESRelay.log contains messages about unexpected lack of configuration keys Issue 133372 - Airgap response can't complete successfully at WebUI gathering Issue 133253 - BigFix relay will not install on AIX 7.2 Issue 133246 - AD syntax limitation when added on Console as Generic LDAP =========================================== = Changes between 9.5.3.211 and 9.5.4.38 = =========================================== Update to OpenSSL 1.0.2j to address vulnerabilities in previous OpenSSL versions APARs addressed: Issue 67448 - APAR IV77401 - WHEN MULTIPLE DATASOURCES ARE DEFINED, WEB REPORTS MAY FAIL TO PROPERLY DISPLAY COMPUTER NAMES FOR CERTAIN REPORTS Issue 68508 - APAR IV75751 - CLIENT RELEVANCE DOES NOT PROPERLY HANDLE VALUE Issue 69162 - APAR IV89747 - MAKE THE ALLOWSCRIPTACCESS FLASH PARAMETER CONFIGURABLE Issue 69494 - APAR IV89343 - NO ACCOUNT LOCKOUT ON WEB REPORTS CHANGE PASSWORD PAGE AFTER MULTIPLE FAILED ATTEMPTS Issue 70939 - APAR IV80816 - UNCLEAR ERROR MESSAGE IN AIR GAP TOOL Issue 72077 - APAR IV85117 - UNDER SPECIFIC CONDITION BIGFIX SERVER UPGRADE TO 9.5.X WITH LINUX SERVER FAILS Issue 72098 - APAR IV84968 - UPGRADE TO 9.5 FAILS IF THE PASSWORD OF THE DB2 USER CONTAINS A "!" CHARACTER Issue 72136 - APAR IV89725 - UPTIME ON SOLARIS SPARC INCONSISTENT Issue 72183 - APAR IV87667 - CLIENT DEPLOY TOOL DOESN'T PARSE CORRECTLY A RANGE OF IP ADDRESSES Issue 72385 - APAR IV89344 - MEAN TIME TO REMEDIATE DATA NOT RETURNED IN WEB REPORTS Issue 72452 - APAR IV87642 - ACTIONS/FIXLETS WITH LONG RELEVANCE CAUSE THE CONSOLE TO TEMPORARILY HANG. Issue 72486 - APAR IV89127 - UNABLE TO DOWNLOAD FILES IN HTTPS USING THE SWD MANAGEMENT DASHBOARD Issue 72729 - APAR IV89549 - RANDOM RELAY SELECTION FAILURE WHILE TRYING TO SELECT THE NEAREST RELAY Issue 72736 - APAR IV89020 - BIGFIX SERVER INSTALLER SCRIPT ON LINUX IS CONFUSING ABOUT PARAMETERS REQUIRED FOR THE INSTALLATION WITH REMOTE DB Issue 72804 - APAR IV89260 - WEB REPORTS OPERATORS WITH CUSTOM ROLE CANNOT DELETE THEIR OWN REPORTS WHILE USING THE 'FILTER BY AUTHOR' FILTER Issue 72830 - APAR IV89397 - FOLDER CREATE ACTION FAILS ON WINDOWS WHEN INPUT PATH INCLUDES SLASHES INSTEAD OF BACKSLASHES USING SOFTWARE DISTRIBUTION Issue 72863 - APAR IV89546 - REST API ACTION CREATION FAILURE DUE TO DUPLICATE KEY IN OBJECT 'DBO.ACTION_FLAGS' Issue 73001 - APAR IV90303 - UNDER SPECIFIC CONDITIONS ON WINDOWS, BESCLIENT 9.5 MAY CRASHES DUE TO A NOT INITIALIZED VARIABLE Issue 73053 - APAR IV90501 - BIGFIX RELAYS MAY NOT BE ABLE TO FORWARD REPORTS TO THE ROOT SERVER Other Bugs fixed: Issue 128941 - Automatic backup does not work if the database names are different from the default ones Issue 129995 - Stand-alone upgrade of WebReports is successful but some errors are showed. Issue 131147 - Airgap tool always includes WEBUI sites in the generated response file Issue 131152 - Database Corruption after BigFix upgrade to v9.5 Issue 131153 - Database Deadlock on actionResults table when using Rest API Issue 131355 - REST API does not allow for "action-ui-metadata" mime field to be included in baseline and MAG definition Issue 131990 - Cannot import an exported action that was exported with ssa icon mimefield info =========================================== = Changes between 9.5.2.56 and 9.5.3.211 = =========================================== Update to OpenSSL 1.0.1t to address vulnerabilities in previous OpenSSL versions APARs addressed: Issue 67806 - APAR IV74080 - MANUAL DATABASE PASSWORD UPDATE IN THE BESSERVER.CONFIG APPEARS TO BE NOT EFFECTIVE. Issue 69155 - APAR IV77149 - CLIENT ON THE TOP LEVEL RELAY OVERWHELMED BY "RESENDREPORT" NOTIFICATIONS Issue 69181 - APAR IV77629 - NOT RELEVANT BASELINE COMPONENTS ARE NOT ACCESSIBLE TO A NON MASTER OPERATOR Issue 70577 - APAR IV80744 - PENDING RESTART POPUP WINDOW PRESENTED WHEN FIXLETDEBUGGER IS USED IN COMMANDLINE MODE Issue 70931 - APAR IV83252 - REPORTS BASED ON CUSTOM REPORT TEMPLATE WITH FLASH CONTENT REMAINS BLANK IF A FILTER IS APPLIED Issue 71520 - APAR IV83439 - THE WEBREPORT PROCESS WILL USE NEARLY 100% OF THE CPU IF WE CONTINUE TO CLICK THE NEXT TO REFRESH THE PAGE. Issue 71457 - APAR IV84286 - BES CLIENT DOESN'T START ACTION EXECUTION EVEN IF DOWNLOADS ARE AVAILABLE Issue 69642 - APAR IV84910 - ERROR LAUNCHING BESCLIENT UI ON OS X 10.11 Issue 71710 - APAR IV85244 - USER AGENT NOT ALWAYS SET TO THE VALUE SPECIFIED WITH _GATHERSERVICE_FORWARDGET_USERAGENTOVERRIDE Issue 72197 - APAR IV85374 - CLIENT RECURSIVE DELETING HAS TO BE ABLE TO HANDLE A SYMLINK Issue 72124 - APAR IV85386 - WEB REPORTS 9.5 MAY CRASH IF SCHEDULED ACTIVITIES ARE ASSOCIATED TO LEGACY OPERATORS Issue 71721 - APAR IV85457 - PROBLEMS IN RENDERING THE SUMMARY TAB PAGE OF THE COMPUTER Issue 71741 - APAR IV85544 - WEB REPORTS - NORMAL USERS UNABLE TO DELETE REPORTS WHEN FILTERED BY AUTHOR Issue 72193 - APAR IV85580 - "FOLLOWING TEXTS" INSPECTOR RETURNS UNEXPECTED RESULTS IN 9.5 Issue 72260 - APAR IV85586 - BESCLIENT 9.5.2 MAY RETURN INCORRECT VALUE FOR DEVICE TYPE ON DESKTOP SYSTEMS Issue 72298 - APAR IV85598 - NON MASTER OPERATORS WITHOUT CUSTOM CONTENT CREATION AUTHORITY ARE NOT ABLE TO CREATE MANUAL GROUPS. Issue 71560 - APAR IV85682 - GATHERDB DOES NOT VALIDATE FILES BEFORE TO UPDATE THE SITENAMEMAP DB TABLE Issue 72166 - APAR IV85743 - SUN SOLARIS 10/11 BES 9.5.2 ON LOCAL ZONE GOES INTO MAINTENANCE MODE Issue 71629 - APAR IV85768 - BESCONSOLE CRASHES WHEN THE TEXT IN ACTIONS TAB FOR SOFTWARE DISTRIBUTION TASK IS EDITED Issue 72405 - APAR IV85778 - INCORRECT CHECK OF FILLDB FAST BUFFERDIR SIZE Issue 72020 - APAR IV85788 - CREATION METHOD "MAIN PROCESSOR" FAILING ON SOME SOLARIS 11 Issue 72323 - APAR IV85964 - BESCLIENTUI CRASHES ON 9.5 UNDER A SPECIFIC COMBINATION OF CONDITION USING NON-ASCII CHARACTERS 9.5 Issue 72415 - APAR IV86186 - FILLDB CRASH AFTER UPGRADE TO 9.5 RELEASE Issue 72442 - APAR IV86493 - IN 9.5 THE 'DISMISS' MESSAGE ON THE CLIENT UI IS WRONGLY TRANSLATED IN JAPANESE Issue 72346 - APAR IV86547 - A CONSOLE CRASH OCCURS WHEN THE USER MODIFIES THE ACTION SETTINGS LOCKS Issue 72280 - APAR IV86737 - IN BIGFIX 9.5.X SOME CUSTOM REPORTS ARE EMPTY WHEN LOADING IN WEBREPORTS Issue 72342 - APAR IV86893 - FILLDB MAY BACKING UP DUE TO A LARGE AMOUNT OF INCOMING FULL REPORTS Issue 72437 - APAR IV86894 - BIGFIX RELAY CAN HANG DURING THE CLEANUP OF OBSOLETE DOWNLOADS Issue 72485 - APAR IV86896 - RELAY MAY STOP FORWARDING REPORTS LOGGING THE MESSAGE: WINDOWS ERROR 0X50: THE FILE EXISTS Issue 72516 - APAR IV86914 - INSPECTOR "CURRENT SITE" MAY RETURNS AN ERROR WHEN USED IN AN ACTION SCRIPT Issue 72100 - APAR IV86924 - COMPUTERS INHERITED FROM ROLE ARE VISIBLE TO AN AD/LDAP OPERATOR BEFORE HE CAN ACTUALLY MANAGE THEM Issue 72134 - APAR IV86958 - RANDOM FAILURE IN VMWARE SNAPSHOT CREATION OR DELETION USING SERVER AUTOMATION Issue 72453 - APAR IV86976 - "FOLDER" INSPECTOR MAY RETURN AN ERROR ON MAC CLIENTS Issue 72517 - APAR IV87070 - CONCURRENT LOGIN ATTEMPTED BY MULTIPLE LOCKED CONSOLE ACCOUNTS CAN CAUSE A SERVER CRASH Issue 72565 - APAR IV87119 - "COMPUTER PROPERTIES LIST" REPORT IS INCOMPLETE WHEN A CLIENT SETTING CONTAINS MULTI BYTE CHARACTERS Issue 72601 - APAR IV87120 - IMPROVEMENT IN BFENTERPRISE FULL DATABASE INDEX REORGANIZATION JOB Issue 72591 - APAR IV87431 - THE 'RESET PASSWORD' OF BIGFIX CONSOLE DOES NOT ALLOW TO SET A PASSWORD LONGER THAN 30 CHARACTERS Issue 72548 - APAR IV87451 - FIXLET DEBUGGER PROBLEMS EVALUATING "PRODUCT TYPE OF OPERATING SYSTEM" IN 'SINGLE CLAUSE' TAB Issue 72592 - APAR IV87525 - WEB REPORT HAS INCORRECT JAPANESE TRANSLATION FOR WORD "AND" Issue 72598 - APAR IV87527 - DSA REPLICATION MAY FAIL ON TABLE SITE_LISTINGS IF THE SITE CONTENT LIST IS GREATER THAN 1MB. Issue 72570 - APAR IV87549 - CERTAIN CONCURRENT ACTIVITIES OF MULTIPLE CONSOLES CAN GENERATE A TEMPORARY CONSOLE FREEZE WHILE SUBMITTING AN ACTION Issue 72581 - APAR IV87571 - UNEXPECTED RELEVANCE EVALUATION FOR ACTIVE DIRECTORY LOGGED ON USERS Issue 72582 - APAR IV87662 - REQUIREMENT FAILURE ERROR MAY BE LOGGED IN THE WINDOWS SERVER LOG AFTER UPGRADE TO 9.5 Issue 72571 - APAR IV87680 - "FOLLOWING TEXT OF POSITION" INSPECTOR NOT RETURNING RESULTS CORRECTLY Issue 72549 - APAR IV87760 - PROPERTIES WITH NOT ASCII CHARACTERS IN THE RELEVANCE STATEMENT CANNOT BE USED IN WEB REPORTS Issue 72668 - APAR IV88273 - 'CREATION TIME' and 'BACKUP TIME' INSPECTORS FAIL TO RETURN THE EXPECTED RESULTS ON MAC 10.11.5 (EL CAPITAN) Issue 72685 - APAR IV88362 - BESREMOVE UTILITY REMOVES WEBREPORTS REGISTRY KEYS WHILE DELETING BESRELAY COMPONENT. Issue 72612 - APAR IV88804 - BES CLIENT 9.5 CRASHES WHILE CHECKING FOR THE LDAP LOGGED ON USERS Issue 72393 - APAR IV88954 - FILESYSTEM INSPECTOR DOESN'T WORK WITH NFS MOUNT POINT ON BIGFIX 9.5 Issue 72770 - APAR IV88976 - DEVICE TYPE IS REPORTING "DESKTOP" ON IBM SERVER BLADECENTER HS21 CHASSIS. Issue 72398 - APAR IV88992 - FILTERING ON SOURCE FIXLET'S SITE OF SOME ACTIONS IN WEBREPORTS DOES NOT WORK. Issue 72788 - APAR IV89217 - A MESSAGE ON THE CLIENT UI HAVE INCORRECT MEANING IN A JAPANESE ENVIRONMENT. Other Bugs fixed: Issue 72224 - Recursive deleting has to be able to handle a symlink Issue 64709 - enable computer assignments for roles Issue 72161 - Device Type reserved property no longer respects the "_BESClient_DeviceTypeOverride" setting if the device type inspector is present Issue 71956 - Add Microsoft SQL Server 2016 detection for Server install Issue 71788 - Add extra tuple handlers for more functionality Issue 72778 - virtualiser of regapps statement crashes qna relevance debugger Issue 59220 - expose the pseudorandom number generator as an inspector Issue 72003 - description of event log record fails for text with percent sign Issue 39146 - Need inspector to detect running in MS virtual machine Issue 63692 - Operators should only be able to send refreshes to administered computers Issue 64600 - POST/PUT api/site/{site}/files does not sanitise filename Issue 72162 - porting the fix for 71457 on 9.5.3 Issue 72601 - BFEnterprise Full Database Index Reorganisation job needs a more intelligent logic Issue 72180 - Security: Align accountLockoutDurationSeconds with Windows recommendation Issue 72337 - Operators without Custom Content permission cannot create manual groups Issue 65038 - Remove the ability to narrow down to the server components in the select features installation dialog on Windows Issue 72238 - /api/etl/computers reports locked computer as unlocked Issue 45693 - Windows Relay installer - ability to install without starting the relay service Issue 71824 - allow registration of SSP client to clientUI to enter IOManager communication Issue 72214 - UTF-8: Audit file doesn't trace changes on WebUI permissions Issue 72321 - User Agent not is set to specified with _GatherService_ForwardGet_UserAgentOverride Issue 128703 - session relevance: javascript array "string" appears to have issues on new platform versions Issue 128481 - Active Directory "logged on users" inspector not working Issue 127838 - add serviceability tracing for some Requirement failure errors ... Issue 127424 - add version and exit to admin tool cli tracing ... Issue 127198 - Shared/Portable/Universe/Files/Windows/Windows/FileLocation.cpp contains NBSP in comments Issue 127192 - When actions are not selected in components of baseline, it could result Please edit the script message on non FXF Console Issue 126444 - On MacOS Usage Data is truncated to 16 characters Issue 125757 - assert using debug module viewing computer list Issue 125482 - Where condition must be removed when the WebUI ETL performs the first run Issue 125280 - Console operating outside of FXF Encoding for OS cannot take a translated action Issue 124640 - HPUX needs hp-roman8 character set Issue 124633 - Missing mounted NFS mount point from 'filesystem' inspector on 9.5.2.56 Issue 124627 - Query Channel: Query submission API should advice the user if Broadcast is not enabled Issue 124624 - UTF-8: ProxyAgentTest fails intermittently Issue 124623 - Additional scenario to fix on: "By manual editing the property, a malicious user can inject some js" Issue 124622 - Add operator to a role through a restapi change role flags Issue 124621 - improve debugging information at first connection attempt installing web reports Issue 124620 - DB2 distinguish between real deadlocks and timeouts Issue 124612 - UTF-8: besadmin cleanup tab activities result in "not responding" window before preview comes up Issue 124611 - custom database: unable modify user features ... Issue 124610 - add possibility to disable UDP notification for downloads only Issue 124608 - Align accountLockoutDurationSeconds with Windows recommendation Issue 124602 - Add serviceability tracing on Server and Relay about the configured file descriptor limit Issue 124601 - Prevent unrestricted file upload on the server Issue 124600 - add serviceability tracing server side about revoked computers Issue 124596 - File details for BigFixAgent.msi contains unresolved product name Issue 124587 - Inspector event log answer with an error on 9.5.2 Issue 124576 - Remove function "CheckForCaclsVersion" and related strings from Server installer Issue 124574 - Installer might inform user that Web Reports will be installed in HTTPS Issue 124573 - FILE inspector not able to manage MAC agent unicode characters Issue 124572 - Wrong result FILE inspector for MAC agent Issue 124568 - FixletDebugger lost a lot of helpful output in 9.5 Issue 124566 - Processor caches use vector::empty() instead of vector::clear() Issue 124559 - No errors are showed in the client log if relay auto selection fails Issue 124555 - UTF-8: as hexadecimal behavior can be different compared to 9.2 Issue 124552 - UTF-8: rhel7 'gather all sites' relay page includes html garbage all over it Issue 124551 - SAML: /saml (9964) - Socket Error: Windows Error - logged every 5 minutes Issue 124545 - Accessibility: dialog scrolling only works with pointing device Issue 124544 - Accessibility: HTML controls don't respond to increased system font size Issue 124537 - Remove unused files and deprecated functions from the Mac Agent Issue 124534 - Server should preserve WebUI CA credentials between restarts Issue 124531 - UTF-8: revise FXF character validation for increased clarity Issue 124522 - Leave the Web Reports service in its current state when doing an upgrade Issue 124520 - Relay: add install option to NOT restart the Agent service Issue 123976 - wrong link in 9.5 documentation Issue 123944 - BESClientSetupMSI.exe should validate and then remove a digital signature Issue 123844 - QNA as a co-process can lock files when they are arguments of relevance Issue 123768 - REST layer reports agent has reported before it has results Issue 121085 - Rest API "WebUI Apps" seems with different logic from the others permissions parameters Issue 121046 - Wrong "Can Submit Queries" defined when added LDAP NMO through Rest API Issue 120861 - Create MO operator via RestAPI set wrongly CanSubmitQueries to false Issue 120833 - Align RestAPI to BES Console to update any permission used PUT method Issue 120629 - Message and behavior when Client cannot send BFQ reports Issue 120384 - FillDB waits 10s between batches procession Issue 120166 - DBL only for query is needed Issue 120025 - fast query ignores client blacklist =========================================== = Changes between 9.5.1.9 and 9.5.2.56 = =========================================== Features added: * BigFix Query support APARs addressed: Issue: 65820 - APAR IV83833 - PROPERTY "DEVICE TYPE" NOT REPORTING CORRECTLY Issue: 68784 - APAR IV81076 - BES CLIENT IS NOT ABLE TO START ON POLISH WINDOWS 2003 SP2 OR LATER Issue: 70039 - APAR IV80898 - ERROR PREPARING ITEMIZED DOWNLOAD REQUEST WHEN USING A PREFETCH BLOCK Issue: 70624 - APAR IV83128 - FIXLETDEBUGGER INCONSISTENT RESULTS WHEN RUNNING SCRIPTS NOT HAVING FULL PATH Issue: 70733 - APAR IV83416 - CLIENTS DO NOT INTIATE AUTOMATIC RELAY SELECTION AFTER THEY DETECT A POSSIBLE NETWORK EVENT Issue: 70857 - APAR IV81823 - CLIENTS CONNECTED TO AN AUTHENTICATING RELAY THAT ATTEMPT TO USE DIRECT DOWNLOAD FAIL TO DOWNLOAD. Issue: 70952 - APAR IV82622 - SOLARIS AGENT GENERATING MASSIVE AUDIT LOGS Issue: 71153 - APAR IV83294 - EXCESSIVE OVERHEAD WITH BES REST API Issue: 71289 - APAR IV82129 - CONSOLE PREFERENCE 'MARK AS OFFLINE AFTER' SETTING ISSUE Issue: 71419 - APAR IV83326 - UNEXPECTED RESULTS FROM SQLITE DATABASE INSPECTOR Issue: 71707 - APAR IV83671 - UPLOADS TABLE NOT PROPERLY UPDATED ON DEPLOYMENT WITH A HUGE NUMBER OF UPLOADED FILES Issue: 71844 - APAR IV84131 - "KEY OF FILE" INSPECTOR MAY RETURNS TRUNCATED RESULTS Issue: 71868 - APAR IV84036 - INCORRECT RELEVANCE RESULT FOR "VARIABLES OF FILE" INSPECTOR. Issue: 71910 - APAR IV84155 - CLIENT ACTIVE DIRECTORY CACHE REFRESH ERROR IN AGENT VERSION 9.5 Issue: 71962 - APAR IV84436 - BIGFIX RELAY FAILURE IN DOWNLOADING LARGE FILES Issue: 71982 - APAR IV84565 - NOT POSSIBLE TO LOGIN TO BES CONSOLE WITH LDAP USERS HAVING DISTINGUISHED NAMES GREATER THAN 255 CHARACTERS Issue: 71994 - APAR IV84675 - ACTIONS CONSTRAINED BY A RELEVANCE EXPRESSION ARE NO LONGER EVALUATED Other Bugs fixed: Issue: 66683 - Console crashes when launching visualization tool. Issue: 71779 - Web Reports encoded subject text contains trailing unnecessary 'newline' character. Issue: 71476 - Fix the year in the Installation Guide window (opened after the eval install). Issue: 71492 - Property saved into questions or longquestion results table according to dbl value. Issue: 71657 - No errors are showed in the client log if relay auto selection fails. Issue: 71697 - UString returning number of "Units" as size. Issue: 71635 - Relay init script needs local codepage fix. Issue: 71704 - Description of active devices returns garbled results on non English Windows. Issue: 71719 - Console gets unexpected error in TranscodeU8ToU16 after upgrading AIX client from 9.2.7 Issue: 71735 - Find adapter does not work for non ASCII name. Issue: 71176 - Three tables have the index longer than 900 bytes.. Issue: 71565 - HideUI option doesn't work with property id mapper feature. Issue: 71737 - Domain user does not work for non ASCII name. Issue: 71762 - Linux user inspector can fail if "(unknown)" user is listed. Issue: 71821 - Editing an Analysis Property loses the relevance syntax highlighting. Issue: 71691 - Create upgrade fixlet for OEL agents. Issue: 71688 - Wake on LAN fails with "NotAnIPSubnet". Issue: 71748 - Make BESAgentControlPanel.sh require root. Issue: 71655 - Add unit tests to UString find() with npos as the second argument. =========================================== = Changes between 9.5.0.311 and 9.5.1.9 = =========================================== APARs addressed: Issue: 71678 - APAR IV83628 - CLIENT KEEPS RESTARTING WHEN TREND CORE PROTECTION MODULE IS ENABLED Issue: 71723 - APAR IV83679 - UPGRADE TO 9.5 CAN FAIL BECAUSE INCONSISTENT DATA IN THE DB Other Bugs fixed: Issue: 71666 - Ensure compatibility with upcoming versions of WebUI Issue: 71712 - Linux user inspector can fail if (unknown) user is listed because of GNOME Issue: 71615 - Web Reports fails to execute batch scripts in scheduled activities Issue: 71714 - "Find Adapter of Network" inspector fails to return results in some cases =========================================== = Changes between 9.2.7.53 and 9.5.0.311 = =========================================== Features added: * Unicode support: Enable BigFix server gathering of data from BigFix clients deployed with different code pages and languages * HTTPS gathering: Enable gathering license updates and external sites via the HTTPS protocol on a BigFix server or in an airgapped environment * SAML V2.0 integration: SAML 2.0 authentication support for users in BigFix console * Database cleanup tools: Standalone tools integrated into BESAdmin to remove data about computers, custom fixlets, properties, analyses, and actions and to update the PropertyIDMap table with changes APARs addressed: Issue 18501 - APAR IV11451 - INVALID SIGNATURES FOR DIFFERENT LANGUAGE AND DIFFERENT LOCALE Issue 26101 - APAR IV68389 - DOWNLOAD STATUS PAGE DISPLAYS OLD AND FAILED DOWNLOADS Issue 62265 - APAR IV58995 - SIMPLIFIED CHINESE DEPLOYMENT CANNOT PULL BACK CHINESE CHARACTERS IN REGISTRY Issue 64830 - APAR IV67353 - THE SOFTWARE DISTRIBUTION DOES NOT WORK WITH JAPANESE NAME FILES WHEN USING COMPRESSED FOLDER. Issue 65373 - APAR IV66933 - DAYLIGHT SAVINGS - WEB REPORTS Issue 66573 - APAR IV76772 - AFTER THE USER HAS MODIFIED STACK SIZE ON THE MACHINE, BESFILLDB SERVICE CRASHES ON LINUX SERVERS. Issue 67486 - APAR IV73105 - IEM SERVER ON LINUX PLATFORM DOES NOT WORK WHEN 1024+ FILE DESCRIPTORS ARE REQUIRED. Issue 68931 - APAR IV76588 - GARBLED CHARACTERS IN THE REPORTS FILTER OF THE REPORTS PAGE WHEN WEBREPORTS ARE IN JAPANESE LANGUAGE. Issue 69055 - APAR IV76914 - THE CONTENT FILTER ON THE BES CONSOLE IS NOT WORKING FOR "DOES NOT CONTAIN" WITHIN RELEVANCE. Issue 70146 - APAR IV81302 - AFTER BIGFIX AGENT IS INSTALLED TRUSTEDINSTALLER.EXE CAUSES CPU SPIKES Issue 70225 - APAR IV79665 - DATABASEPROPAGATOR ERROR INTENDEDSITEDOESNOTMATCH ON WINDOWS Issue 70955 - APAR IV81425 - ON MAC CLIENTS, 'HOME DIRECTORIES OF USERS' AND 'FOLDERS OF FOLDER' INSPECTORS DON'T WORK Other Bugs fixed: Issue: 69762 - Change limit of 512 bytes for a string constant Issue: 68643 - Server Installer can't handle client with different StoragePath Issue: 68892 - QuickU8toU16 can incorrectly transcode Issue: 71086 - assessment of the security issues found by AppScan on Windows WebReports Issue: 71145 - a .beswrpt can be injected/modified to contain malicious javascript Issue: 71146 - When creating a ScheduledActivity it is possible to simulate a fake POST where ArchiveFormat= Issue: 71147 - The POST associated to CustomReport can run a custom js payload Issue: 70846 - WR - same user login with two different LDAP-domain passwords but maintains identity/role of one domain Issue: 71142 - Autocomplete HTML attribute must be disabled for passwords Issue: 71149 - While defining a scheduled activity, an user can insert an arbitrary OS command as part of the args of the customizable exe Issue: 71258 - fixlet description containing injected js may be passed to HTML control Issue: 71148 - By manual editing the property, a malicious user can inject some js Issue: 69652 - Dynamic download fails on RHEL when using a long extended ascii name path Issue: 69756 - HTTP encoding specifications should only be UTF-8 Issue: 69566 - ldap user cannot login to webui after toggling saml from enabled to disabled Issue: 71319 - CHS: quote marks corrupted Issue: 68681 - Lossy transcoding results in relevance being evaluated wrong Issue: 71314 - Some field titles are truncated on Add LDAP Directory dialog Issue: 70430 - Fixlet Debugger saves font selection incorrectly Issue: 68732 - Operator creation should allow UTF-8 name Issue: 70640 - operator with long high-bit name fails to login to Console Issue: 70894 - Upgrade process from 923 to Jarvis can fail for insufficient temporary space Issue: 70535 - migration time to Jarvis quickly grows by increasing the number of rows in the Uploads table on Linux Issue: 69625 - saml authentication to webui fails against ADFS Issue: 69691 - saml access fails with web reports Issue: 69845 - saml WebReports user cannot reauthenticate on adfs timeout Issue: 70817 - Upgrade error using Custom Site with no ASCII standard chars Issue: 69906 - Unable to saml login WR after restarting VM Issue: 70947 - WebUI Apps on Console View disappears at every Console Login Issue: 71030 - WR doens't show the login banner when using SAML authentication Issue: 70415 - Server installer banner graphic missing from all dialogs Issue: 69822 - Console can create 260 char name for analysis property, but can't import it Issue: 71528 - Errors in client log and no longer reporting tabase cleanup tools: Standalone tools integrated into BESAdmin to remove data about computers, custom fixlets, properties, analyses, and actions and to update the PropertyIDMap table with changes APARs addressed: Issue 18501 - APAR IV11451 - INVALID SIGNATURES FOR DIFFERENT LANGUAGE AND DIFFERENT LOCALE Issue 26101 - APAR IV68389 - DOWNLOAD STATUS PAGE DISPLAYS OLD AND FAILED DOWNLOADS Issue 62265 - APAR IV58995 - SIMPLIFIED CHINESE DEPLOYMENT CANNOT PULL BACK CHINESE CHARACTERS IN REGISTRY Issue 64830 - APAR IV67353 - THE SOFTWARE DISTRIBUTION DOES NOT WORK WITH JAPANESE NAME FILES WHEN USING COMPRESSED FOLDER. Issue 65373 - APAR IV66933 - DAYLIGHT SAVINGS - WEB REPORTS Issue 66573 - APAR IV76772 - AFTER THE USER HAS MODIFIED STACK SIZE ON THE MACHINE, BESFILLDB SERVICE CRASHES ON LINUX SERVERS. Issue 67486 - APAR IV73105 - IEM SERVER ON LINUX PLATFORM DOES NOT WORK WHEN 1024+ FILE DESCRIPTORS ARE REQUIRED. Issue 68931 - APAR IV76588 - GARBLED CHARACTERS IN THE REPORTS FILTER OF THE REPORTS PAGE WHEN WEBREPORTS ARE IN JAPANESE LANGUAGE. Issue 69055 - APAR IV76914 - THE CONTENT FILTER ON THE BES CONSOLE IS NOT WORKING FOR "DOES NOT CONTAIN" WITHIN RELEVANCE. Issue 70146 - APAR IV81302 - AFTER BIGFIX AGENT IS INSTALLED TRUSTEDINSTALLER.EXE CAUSES CPU SPIKES Issue 70225 - APAR IV79665 - DATABASEPROPAGATOR ERROR INTENDEDSITEDOESNOTMATCH ON WINDOWS Issue 70955 - APAR IV81425 - ON MAC CLIENTS, 'HOME DIRECTORIES OF USERS' AND 'FOLDERS OF FOLDER' INSPECTORS DON'T WORK Other Bugs fixed: Issue: 69762 - Change limit of 512 bytes for a string constant Issue: 68643 - Server Installer can't handle client with different StoragePath Issue: 68892 - QuickU8toU16 can incorrectly transcode Issue: 71086 - assessment of the security issues found by AppScan on Windows WebReports Issue: 71145 - a .beswrpt can be injected/modified to contain malicious javascript Issue: 71146 - When creating a ScheduledActivity it is possible to simulate a fake POST where ArchiveFormat= Issue: 71147 - The POST associated to CustomReport can run a custom js payload Issue: 70846 - WR - same user login with two different LDAP-domain passwords but maintains identity/role of one domain Issue: 71142 - Autocomplete HTML attribute must be disabled for passwords Issue: 71149 - While defining a scheduled activity, an user can insert an arbitrary OS command as part of the args of the customizable exe Issue: 71258 - fixlet description containing injected js may be passed to HTML control Issue: 71148 - By manual editing the property, a malicious user can inject some js Issue: 69652 - Dynamic download fails on RHEL when using a long extended ascii name path Issue: 69756 - HTTP encoding specifications should only be UTF-8 Issue: 69566 - ldap user cannot login to webui after toggling saml from enabled to disabled Issue: 71319 - CHS: quote marks corrupted Issue: 68681 - Lossy transcoding results in relevance being evaluated wrong Issue: 71314 - Some field titles are truncated on Add LDAP Directory dialog Issue: 70430 - Fixlet Debugger saves font selection incorrectly Issue: 68732 - Operator creation should allow UTF-8 name Issue: 70640 - operator with long high-bit name fails to login to Console Issue: 70894 - Upgrade process from 923 to Jarvis can fail for insufficient temporary space Issue: 70535 - migration time to Jarvis quickly grows by increasing the number of rows in the Uploads table on Linux Issue: 69625 - saml authentication to webui fails against ADFS Issue: 69691 - saml access fails with web reports Issue: 69845 - saml WebReports user cannot reauthenticate on adfs timeout Issue: 70817 - Upgrade error using Custom Site with no ASCII standard chars Issue: 69906 - Unable to saml login WR after restarting VM Issue: 70947 - WebUI Apps on Console View disappears at every Console Login Issue: 71030 - WR doens't show the login banner when using SAML authentication Issue: 70415 - Server installer banner graphic missing from all dialogs Issue: 69822 - Console can create 260 char name for analysis property, but can't import it Issue: 71528 - Errors in client log and no longer reporting