APC UPS Data Center & Enterprise Solutions Forum
Schneider, APC support forum to share knowledge about installation and configuration for Data Center and Business Power UPSs, Accessories, Software, Services.
Posted: 2021-06-30 04:02 AM . Last Modified: 2024-03-08 04:37 AM
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-30 04:02 AM . Last Modified: 2024-03-08 04:37 AM
Qualys scans are identifying Eclipse Jetty Vulnerabilities. It shows we are running 9.1.3v20140225 with Powerchute Network Shutdown version 4.2. The most recent version on eclipse.org is 9.4.20.v20190813. Will this work with PCNS 4.2?
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-30 04:02 AM . Last Modified: 2024-03-08 04:36 AM
Hi,
This is not officially support however, you can upgrade the Jetty to 9.4.20. First stop the PCNS server. From command prompt as admin enter net stop pcns1
Second go to C:\Program Files\APC\PowerChute\group1\lib and copy these files to a new folder. This step is to save the files in case you need them at a later date.
Third download Jetty 9.4.20, open the lib folder and copy these file to C:\Program Files\APC\PowerChute\group1\lib
Finally, restart PCNS1 service.
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-30 04:02 AM . Last Modified: 2024-03-08 04:37 AM
Hi,
You should update to PCNS 4.3 that utilizes Jetty 9.4.12.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-30 04:02 AM . Last Modified: 2024-03-08 04:36 AM
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-30 04:02 AM . Last Modified: 2024-03-08 04:36 AM
Will that run on 2008 R2?
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-30 04:02 AM . Last Modified: 2024-03-08 04:36 AM
Hi,
It is not an officially support OS however it should work.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-30 04:02 AM . Last Modified: 2024-03-08 04:36 AM
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-30 04:02 AM . Last Modified: 2024-03-08 04:36 AM
I have updated to PCNS 4.3 on Server 2008R2 with no problems.
The Qualys scans are still showing 2 Eclipse Jetty vulnerabilities:
CVE-2019-10241: the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.
Versions Affected:
9.2.26 and older
9.3.25 and older
9.4.15 and older
QID Detection Logic:(Unauthenticated)
It looks at http banner to check for vulnerable version of Jetty.
that utilizes Jetty 9.4.12.
QID:
The server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on jetty-distribution and jetty-home will include at the end of the Handler tree a Default Handler, which is responsible for reporting this 404 error, it presents the various configured contexts as HTML for users to click through to. This produced HTML includes output that contains the configured fully qualified directory base resource location for each context.
Versions Affected:
7.x (all versions) 8.x (all versions) 9.2.27.v20190403 and older 9.3.26.v20190403 and older 9.4.16.v20190411 and older QID Detection Logic:(Unauthenticated)
It looks at http banner to check for vulnerable version of Jetty.
Customers are advised to refer to Bug 546577 for more information.
Patch:
Following are links for downloading patches to fix the vulnerabilities:
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-30 04:02 AM . Last Modified: 2024-03-08 04:36 AM
Hi,
This is not officially support however, you can upgrade the Jetty to 9.4.20. First stop the PCNS server. From command prompt as admin enter net stop pcns1
Second go to C:\Program Files\APC\PowerChute\group1\lib and copy these files to a new folder. This step is to save the files in case you need them at a later date.
Third download Jetty 9.4.20, open the lib folder and copy these file to C:\Program Files\APC\PowerChute\group1\lib
Finally, restart PCNS1 service.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-30 04:03 AM . Last Modified: 2024-03-08 04:36 AM
Link copied. Please paste this link to share this article on your social media post.
Posted: 2021-06-30 04:03 AM . Last Modified: 2024-03-08 04:36 AM
Bill,
Thanks so much. It worked with no problems. Qualys scans were happy. I have updated all my servers.
Link copied. Please paste this link to share this article on your social media post.
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.