IWSVA 6.5 SP3 focuses on vulnerability fixes which includes the following below:
- Upgraded 3rd party under Blackduck guidance.
- Passed Infosec scan
- Fixed fortify scan bugs
- Fixed all pending SEG vulnerability issues
- Merged SEG cases in legacy releases
The following enhancements are also included:
- Operating System
This Service Pack switches the operating system from OpenVA to standard CentOS to ensure consistent community support and maintain hardware/hypervisor compatibility with CentOS.
- IWSSD
This Service Pack removes the appd daemon and moves the related functions to IWSSD, including application control, bandwidth control, and bandwidth related dashboard/log/report. This release also helps resolve the race issue between the app daemon and kernel to enhance system stability.
- SunLDAP and Functions
This Service Pack removes SunLDAP/eDirectory support and the WMI, DCagent, and Java Applet/ActiveX functions.
- Web Console
This Service Pack improves product security by removing support for HTTP protocols and HTTPS TLS 1.0 and 1.1 protocols when accessing the web console.
- URL Categories
This Service Pack support new URL categories including "Insecure IoT Connections" and "Noteworthy".
Installation
-
In-box Upgrade: IWSVA 6.5 SP3 upgrade package and readme file are available on Download Center, the upgrade package supports migration from IWSVA 6.5 SP2 Patch4 hotfix1948.
Hotfix 1948 is dependent on Hotfix 1912, please apply them in sequence before performing the in-box upgrade. The hotfixes can be downloaded from download center or following links: Hotfix 1948, Hotfix 1912. -
Fresh Install: User can download the Installation package from Business Support Portal.
For support assistance, please contact Trend Micro Technical Support.