Trellix Database Security 10.1.0 release addresses new database support, platform support, and resolved issues.
Product rebranding changes
This is solely for informational purpose, there is no action required. You can continue to secure your organization with Trellix Database Security as usual. You will notice the following changes in the software:
Brand logo and name - McAfee logo and name are replaced with Trellix logo and name.
Product name - McAfee Database Security is renamed as Trellix Database Security. All features and options prefixed with product name are renamed with the new product name.
End-User License Agreement and Copyright - The End-User License Agreement and Copyright are updated according to legal requirements. Please read the agreement for details.
For more information about migrating to Trellix Database Security 10.1.0, see article 000013499.
Certificate update changes
As part of rebranding, the certificates used to sign our software have been updated. If your enterprise automatically updates root certificates, the software update or installation does not require any additional effort. However, if your enterprise manages root certificate updates manually, you need to install the new intermediate and root certificates. For more information about updating root certificates, see article 000008115.
Rating
Recommended
This release is recommended for all environments. Apply this update at the earliest convenience.
Release Details
Release Date - Oct 29, 2024
Release Builds:
Trellix Database Security server build - 10.1.0.50203 (Windows and Linux)
Trellix Database Security sensor build -
10.1.0.20064 (Windows, Linux, and Solaris)
10.1.0.20000 (HPUX)
10.1.0.20001 (AIX)
Environment - Trellix Database Security (Standalone)
Note
Customers are required to download the license file to activate the latest version of Trellix Database Security 10.1.0 from the Product download site.
Updated platform, environment, and operating system support
Server package
A new server package is released for Trellix Database Security. See article 000005900.
Note
With 10.1.0 release, all 4.x versions will enter End of Maintenance state. We recommend upgrading to the latest version of Trellix Database Security to ensure continued support.
Sensor package
A new sensor package is released for Trellix Database Security. See article 000005900.
Library upgrades
As part of security enhancements, we have upgraded the following third-party libraries to address vulnerabilities. For detailed information on the previous versions and changes, please refer to the respective vendor Release Notes.
Library
Version
dom4j
2.1.4
jettinson
1.5.4
jgroups
5.3.7
mysql-connector-java
8.4
xalan
2.7.3
jackson-databind
2.17.1
jackson-core
2.17.1
jackson-annotations
2.17.1
xstream
1.4.20
Commons-beanutils
1.9.4
Birt Framework
4.6
Support for additional database versions
Name
Platform
Oracle
Oracle 19.17 - 19.22
Win_64, Linux_64
Oracle 19.23
Win_64, Linux_64, AIX, Solaris, HPUX
Microsoft SQL Server
Security update for SQL Server MSSQL 2019 KB5021125 (15.0.2101.7)
Win_64
Security update for SQL Server MSSQL 2019 CU22 KB5029378 (15.0.4326.1)
Win_64
SQL Server MSSQL 2019 CU23 - CU26
Win_64
Security update for SQL Server MSSQL 2019 CU25 KB5036335 (15.0.4360.1)
Win_64
SQL Server MSSQL 2022 CU12 - CU13
Win_64
Security update for SQL Server MSSQL 2022 KB5036343 (16.0.4120.1)
Win_64
MySQL
MySQL 8.0.31 - 8.0.36 (Community and Enterprise)
Linux_64
MariaDB
MariaDB 10.11.1 - 10.11.7
Linux_64
PostgreSQL
PostgreSQL 15.0 - 15.6
Linux_64
For more information about Trellix Database Security 10.1.0 platform recommendations, see article 000013243.
Resolved issues
Reference | Resolution |
|---|---|
DBSEC-24102 | Fixed an issue where vulnerability scanners detected the "server_sn_v_1.jks" file from the DAM installation folder because it used a weak algorithm of SHA1. |
DBSEC-22244 | Fixed an issue where manual archive of alerts did not work. |
DBSEC-22281 | Fixed an issue where DAM server was reported with jQuery Cross-Site Scripting (XSS) Vulnerability (CVE-2015-9251). |
DBSEC-24356 | Fixed an issue where vulnerability scans run on the DAM server displayed vulnerability error. |
DBSEC-24366 | Fixed an issue where VA scans run against Database Security server displayed the following vulnerabilities.
|
DBSEC-22281 | Fixed an issue where an older version of jquery was detected in the standalone version of Database Security server. |
DBSEC-22244 | Fixed an issue where vulnerability scans reported that the DAM server is vulnerable to CVE-2015-9251. |
DBSEC-23512 | Fixed an issue where the DAM server displayed an error after configuring the proxy. |
DBSEC-21865 | Fixed an issue where Trellix DDL trigger in SQL 2012 displayed an error when dynamic SQL statements were executed. |
DBSEC-20878 | Fixed an issue where after upgrading the sensor, alerts for DDL queries like CREATE, DROP were not generated. |