Access Manager 4.0 Service Pack 1 Hotfix 1 Readme

June 2014

The Access Manager Service Pack 1 Hotfix 1 (4.0.1 HF1) includes fixes for some security vulnerabilities listed in Section 1.1, Fixed Issues.

For the list of software fixes and enhancements in the previous release, see Access Manager 4.0 SP1 readme.

1.0 What’s New?

Access Manager 4.0.1 HF1 fixes vulnerability issues with OpenSSL and issues with Apache Tomcat 7.0 in this release.

1.1 Fixed Issues

The following sections outline the issues resolved in this release:

Vulnerability Issue with OpenSSL

CVE-2014-0224: OpenSSL is vulnerable to a man-in-the-middle (MITM) attack. The attack occurs on vulnerable SSL/TLS clients and servers. OpenSSL clients are vulnerable in all versions of OpenSSL and servers are known to be vulnerable only in OpenSSL versions before 0.9.8za, from version 1.0.0 until version 1.0.0m, and from version 1.0.1 until version 1.0.1h as mentioned in the CVE-2014-0224. For more information about this issue and the resolution, see TID 705158.

Issues with Apache Tomcat 7.0

CVE-2013-4322: Apache Tomcat from version 7.0 until version 7.0.50 do not handle large amount of chunked data or unlimited whitespace characters in a HTTP header. For more information about this issue, see CVE-2013-4322.

CVE-2013-4286: Apache Tomcat from version 7.0 until version 7.0.47 does not handle certain inconsistent HTTP request headers when HTTP or AJP connectors are used. For more information about this issue, see CVE-2013-4286.

The above vulnerabilities affect the following Access Manager components, which are installed with Tomcat:

  • Administration Console

  • Identity Server

  • Embedded Service Provider running in the Access Gateway machine

4.0.1 HF1 updates these components with the latest Tomcat version 7.0.54. For more information about how to upgrade, see Upgrading to 4.0.1 HF1.

2.0 Upgrading to 4.0.1 HF1

Ensure that you are currently on Access Manager 4.0 Service Pack 1 before upgrading to Access Manager 4.0.1 HF1.

To upgrade to Access Manager 4.0.1 HF1, download the AM_401_HF1.zip file that contains the Access Manager Patch Tool and the patch file by using the following steps:

  1. Go to NetIQ downloads page.

  2. Under Patches, click Search Patches.

  3. Specify AM_401_HF1.zip in the search box and download the Hotfix file.

  4. Upgrade by using the procedure described in Upgrading Access Manager 4.0 HF* Using the Patch Process for Linux and Upgrading Access Manager 4.0 HF* Using the Patch Process for Windows in the NetIQ Access Manager 4.0 SP1 Migration and Upgrade Guide.

3.0 Verifying Version Numbers

To ensure that you have the correct version of files before you upgrade to Access Manager 4.0.1 HF1, verify the existing Access Manager version.

Before and after upgrading, it is important to verify the version number of the existing Access Manager components. This ensures that you have the correct version of files on your system.

Before Upgrading: Before upgrading to Access Manager 4.0.1 HF1, go to Access Manager > Auditing > Troubleshooting > Version and verify that the version number of the component is indicated as 4.0.1.88 in the Version field.

After Upgrading: After upgrading to Access Manager 4.0.1 HF1, go to Access Manager > Auditing > Troubleshooting > Version and verify that the version number of the component is indicated as 4.0.1.88 + HF1-93 in the Version field.

4.0 Known Issue

NetIQ Corporation strives to ensure our products provide quality solutions for your enterprise software needs. The following issues are currently being researched. If you need further assistance with any issue, please contact Technical Support.

4.1 LDAP Group List is not Available

While creating an Identity Server Role policy with LDAP Group as a condition, the LDAP Group list is not available in the Value field. (Bug 876776)

5.0 Contact Information

Our goal is to provide documentation that meets your needs. If you have suggestions for improvements, please email Documentation-Feedback@netiq.com. We value your input and look forward to hearing from you.

For detailed contact information, see the Support Contact Information Web site.

For general corporate and product information, see the NetIQ Corporate Web site.

You can post feedback in the Access Manager forum on Qmunity, our community Web site that also includes product notifications, blogs, and product user groups.

To download this product, go to Access Manager on the All Products Page.