Release Version 7.7.4
Release Date: 7th Oct’ 2022
What’s New?
Uptime Value
The uptime field value for Google Redis is now converted to numeric format instead of string value format.
Decimal values increased in SLA
Support of decimal values up to 8 characters is added for the SLA target value.
Change in the description instead of Subject line
When the ticket gets triggered in ‘Clear State’ status, the description of the ticket will get changed with the updated status of the ticket instead of the subject line. For this the plugin ServiceOps Trouble Ticket is updated to version 1.5.
Health status in Third party tool
The health status (ON/OFF) information will now be sent to the third-party tool whenever the device varies in status (Up/Down). For this the plugin Webhook Alert is added with version 1.0.
Integration with Third-Party Map
Integration of ESRI API is added for viewing the Map.
CSV support added in Auto Discovery
As an improvement, scheduling of the CSV import format for Auto Discovery is added, where multiple IP ranges can be added in a CSV file and auto-discovery can be scheduled.
Upgrading Python packages
As a part of the improvement, the below python packages will be installed automatically:
- Netmiko
- Cloud Azure
- Go packages
NMS alerts received in Microsoft Teams
An improvement is added where the NMS alerts will be received on Microsoft Teams when configured. For this, the plugin Webhook Teams is updated to version 1.0.
Log Parser for Fortimanager
Improved the regex for fortimanager log parser, thus both old and new pattern gets parsed. For this, the plugin Universal Log Parser is updated to version 8.8.
Sectona PAM Log Parser
Sectona PAM device log parsers are added and the plugin Universal Log Parser is updated to version 8.8.
End of Support (EOS)/End of Life (EOL)
CISCO EOS/EOL devices support is added in GO Polling.
Firmware Upgrade
Firmware for HP and Aruba devices is added. For this, the plugin SSH NCM Collector is updated to version 4.6.
Rest API will now provide unescaped output
The Struts is updated to version 2.5.26 and JDK to 8.0.301 which will now help in providing the JSON format in an un-escaped format.
GO polling Performance
All packages for GO polling will be installed at the time of the Upgrade. As a part of performance improvement FPing is introduced, along with the SNMP metrics. For this below plugins are updated:
| Plugin Name | Version |
|---|---|
| BGP Routing | 8.4 |
| Cisco Firewall | 8.4 |
| Linux SNMP | 8.7 |
| Cisco Router | 8.4 |
| Firewall | 8.5 |
| Hardware Sensor | 8.3 |
| Juniper Firewall | 8.3 |
| Juniper Switch | 8.4 |
| Juniper Router | 8.4 |
| Router | 8.7 |
| Switch | 8.5 |
| SNMP | 8.8 |
| UPS | 8.3 |
| Sophos Firewall | 1.7 |
| Windows SNMP | 8.8 |
| Cisco SPML2 | 8.1 |
| Cisco SPM | 8.2 |
| Cisco Switch | 8.5 |
| Cisco VLAN | 8.1 |
| ISIS Routing | 8.4 |
| OSPF | 8.1 |
| RF Device | 8.2 |
| Symantic Email | 8.1 |
| Ironport Email Gateway | 8.2 |
Resolved Vulnerabilities List
| No | Name |
|---|---|
| 1 | Lack of Authentication - Account Takeover |
| 2 | Privilege Escalation - Site Wide [Read to Admin] |
| 3 | Local File Inclusion |
| 4 | Insecure Direct Object Reference |
| 5 | Privilege Escalation |
| 6 | Lack of Authentication - Multiple Instances |
| 7 | Improper Error Handling |
| 8 | Vulnerable jQuery Version |
Vulnerabilities with CVE
| No | Vulnerabilities | CVE ID |
|---|---|---|
| 1 | Log4j | CVE-2019-17571, CVE-2020-9488, CVE-2022-23302, CVE-2022-23305, CVE-2021-4104 |
| 2 | Oracle Java SE Multiple | CVE-2022-21426, CVE-2022-21434, CVE-2022-21443, CVE-2022-21449, CVE-2022-21476, CVE-2022-21496 |
| 3 | Java JMX | - |
| 4 | Spring | CVE-2022-22950 |
| 5 | Apache Struts | CVE-2021-31805 |
Bug Fixes
An issue was observed where Amazon Redis monitor was not getting discovered, which is resolved now. For this the plugin AWS-Redis is updated to version 7.6.
The trouble ticket from NMS to ServiceOps were not getting generated as well as getting resolved automatically, which is resolved now and the API response is also improved at ServiceOps end.
An issue was observed where the devices/monitors were not getting shifted from the maintenance mode to normal, which is resolved now.