Database Security 10.1.0 Release Notes - October 2024

Prev Next

Trellix Database Security 10.1.0 release addresses new database support, platform support, and resolved issues.

Product rebranding changes

This is solely for informational purpose, there is no action required. You can continue to secure your organization with Trellix Database Security as usual. You will notice the following changes in the software:

  • Brand logo and name - McAfee logo and name are replaced with Trellix logo and name.

  • Product name - McAfee Database Security is renamed as Trellix Database Security. All features and options prefixed with product name are renamed with the new product name.

  • End-User License Agreement and Copyright - The End-User License Agreement and Copyright are updated according to legal requirements. Please read the agreement for details.

For more information about migrating to Trellix Database Security 10.1.0, see article 000013499.

Certificate update changes

As part of rebranding, the certificates used to sign our software have been updated. If your enterprise automatically updates root certificates, the software update or installation does not require any additional effort. However, if your enterprise manages root certificate updates manually, you need to install the new intermediate and root certificates. For more information about updating root certificates, see article 000008115.

Rating

Recommended

This release is recommended for all environments. Apply this update at the earliest convenience.

Release Details

Release Date - Oct 29, 2024

Release Builds:

  • Trellix Database Security server build - 10.1.0.50203 (Windows and Linux)

  • Trellix Database Security sensor build -

    • 10.1.0.20064 (Windows, Linux, and Solaris)

    • 10.1.0.20000 (HPUX)

    • 10.1.0.20001 (AIX)

  • Environment - Trellix Database Security (Standalone)

    Note

    Customers are required to download the license file to activate the latest version of Trellix Database Security 10.1.0 from the Product download site.

Updated platform, environment, and operating system support

  • Server package

    A new server package is released for Trellix Database Security. See article 000005900.

    Note

    With 10.1.0 release, all 4.x versions will enter End of Maintenance state. We recommend upgrading to the latest version of Trellix Database Security to ensure continued support.

  • Sensor package

    A new sensor package is released for Trellix Database Security. See article 000005900.

  • Library upgrades 

    As part of security enhancements, we have upgraded the following third-party libraries to address vulnerabilities. For detailed information on the previous versions and changes, please refer to the respective vendor Release Notes.

    Library

    Version

    dom4j

    2.1.4

    jettinson

    1.5.4

    jgroups

    5.3.7

    mysql-connector-java

    8.4

    xalan

    2.7.3

    jackson-databind

    2.17.1

    jackson-core

    2.17.1

    jackson-annotations

    2.17.1

    xstream

    1.4.20

    Commons-beanutils

    1.9.4

    Birt Framework

    4.6

  • Support for additional database versions

    Name

    Platform

    Oracle

    Oracle 19.17 - 19.22

    Win_64, Linux_64

    Oracle 19.23

    Win_64, Linux_64, AIX, Solaris, HPUX

    Microsoft SQL Server

    Security update for SQL Server MSSQL 2019 KB5021125 (15.0.2101.7)

    Win_64

    Security update for SQL Server MSSQL 2019 CU22 KB5029378 (15.0.4326.1)

    Win_64

    SQL Server MSSQL 2019 CU23 - CU26

    Win_64

    Security update for SQL Server MSSQL 2019 CU25 KB5036335 (15.0.4360.1)

    Win_64

    SQL Server MSSQL 2022 CU12 - CU13

    Win_64

    Security update for SQL Server MSSQL 2022 KB5036343 (16.0.4120.1)

    Win_64

    MySQL

    MySQL 8.0.31 - 8.0.36 (Community and Enterprise)

    Linux_64

    MariaDB

    MariaDB 10.11.1 - 10.11.7

    Linux_64

    PostgreSQL

    PostgreSQL 15.0 - 15.6

    Linux_64

    For more information about Trellix Database Security 10.1.0 platform recommendations, see article 000013243.

Resolved issues

Reference

Resolution

DBSEC-24102

Fixed an issue where vulnerability scanners detected the "server_sn_v_1.jks" file from the DAM installation folder because it used a weak algorithm of SHA1.

DBSEC-22244

Fixed an issue where manual archive of alerts did not work.

DBSEC-22281

Fixed an issue where DAM server was reported with jQuery Cross-Site Scripting (XSS) Vulnerability (CVE-2015-9251).

DBSEC-24356

Fixed an issue where vulnerability scans run on the DAM server displayed vulnerability error.

DBSEC-24366

Fixed an issue where VA scans run against Database Security server displayed the following vulnerabilities.

  • CVE-2023-24998

  • CVE-2023-46589

  • CVE-2022-45143

DBSEC-22281

Fixed an issue where an older version of jquery was detected in the standalone version of Database Security server.

DBSEC-22244

Fixed an issue where vulnerability scans reported that the DAM server is vulnerable to CVE-2015-9251.

DBSEC-23512

Fixed an issue where the DAM server displayed an error after configuring the proxy.

DBSEC-21865

Fixed an issue where Trellix DDL trigger in SQL 2012 displayed an error when dynamic SQL statements were executed.

DBSEC-20878

Fixed an issue where after upgrading the sensor, alerts for DDL queries like CREATE, DROP were not generated.