ePO - On-prem 5.10.0 Service pack 1 Update 3 supports new features and addresses the known issues, including security fixes and performance.
We recommend that you always upgrade ePO 5.10.0 with the latest release as soon as possible.
Release Details
Trellix ePolicy Orchestrator - On-premises Cumulative Updater Tool ePO_5.10.0_SP1_UP3_1634.
Release Date: May 30, 2024
For the complete list of release dates and build numbers, see Product release information in KB51569.
Rating
The rating defines the urgency for installing this update.
This release is mandatory for all environments. You must apply these updates to maintain a viable and supported product. For more information see KB51560.
New or changed
This release supports for these features:
Support for secure communication between the Agent/client and distributed repositories.
This feature is supported only with Trellix Agent version 5.8.2 and later.
MSOLEDB DB Driver Version Upgrade to 18.6.7.0
Upgraded BSAFE MES version to 5.0.2.1
Upgraded Tomcat version to 9.0.85
Upgraded Java version to 1.8.0_401
Upgraded Apache version to 2.4.58
Upgraded OpenSSL version to 1.0.2zj-fips
Upgraded Spring version to 5.3.31
Upgraded jQuery version to 3.7.1
Resolved issues
This update contains these resolved issues.
Functional stability
Reference | Resolution |
|---|---|
EPO-11444 | SSO users are getting logged out from ePO Console. This has been resolved. |
EPO-12058 | ePO was not able to be added to existing Handler Groups or New AH groups. This has been resolved. |
EPO-12156 | Pull task failure due to Master Repository update task failing Authentication issue. This has been resolved. |
EPO-12035 | Resolves the issue where the Active Directory synchronization task was erroneously deleting the encrypted devices from the System Tree. |
EPO-12157 | Resolves the issue where the queries with product filters do not function correctly when applying conditions such as Value is blank and Value is not blank. |
EPU-577 | Repair operation of ePO 5.10 SP1 no longer fails during the upgrade process. |
EPO-12172 | Hebrew characters are now displayed without any issues in the threat target file path when exporting query results to PDF. |
EPO-6280 | After upgrading to ePO 5.10.0, the new certificate in the Certificate Manager was incorrectly named with the active node instead of the ePO Cluster. This issue has now been resolved. |
EPO-12207 | The Orion rollover was deleted without backing up and has been resolved. |
EPO-9597 | The scheduled AD sync tasks were failing, while the same task completed successfully when executed manually. This issue has been resolved. |
EPO-12176 | Push Agent configuration under AD synchronization can now be saved without encountering any issues. |
EPO-10852 | In Automation, users are now able to edit and save the Issues page successfully. |
EPO-12114 | Resolves the login page issues encountered when configuring the Identity Provider and Cloud Bridge. |
EPO-10834 | The limitation where ePO AD Sync only matched on the first 15 characters of the machine AD name has been resolved. |
EPO-12169 | Resolves an error while saving the default refresh interval for the dashboard monitor from server settings. |
EPO-11231 | The issue with the Product Deployment command line not transferring to client tasks has been resolved. |
EPO-10544 | Threat events get purged without any issues. |
EPO-11244 | The Actions and other buttons will not be disabled when clicking Apply. |
EPO-9349 | When a package didn't exist in the main repository, it would auto-select a random package instead of showing an error message. This issue has been resolved. |
EPO-11706 | The description of IP Address - Matches Subnet Mask in the Tag criteria has been corrected. |
EPO-11254 | Only clients with the precise version (e.g. ENS 10.7.1234) are now labelled as "Installation successful". |
EPO-11120 | The approval page loads promptly without any delay. |
EPO-11561 | The Main Repository allows packages to be checked in without any issues. |
EPO-11569 | Resolves an issue where the System Tree group filter in Queries is replaced with MyOrg if the group is deleted from the System Tree. |
EPO-12376 | ePO no longer exports the multiple queries. |
EPO-12394 | Client machines no longer gets deleted from the System Tree after upgrading ePO - On-prem 5.10 to SP1 Update 3 build 2.0.0.1629. |
Security Hardening
Reference | Resolution |
|---|---|
SAG-84 | Upgraded jQuery version that fixes known vulnerabilities. |
SAG-83 | Upgraded JRE version that fixes known vulnerabilities. |
SAG-82 | Upgraded Open SSL version that fixes known vulnerabilities. |
SAG-81 | Upgraded Tomcat version that fixes known vulnerabilities. |
SAG-80 | Resolves the privilege escalation issues occurred due to ePO insecure direct object references. For more details, see 000013505. |
EPO-11891 | ePO 5.10.0 no longer uses a hardcoded encryption key that can be leveraged to escalate privileges. For more details, see 000013505. |
Known issues
For a list of known issues in this product release, see ePO - On-prem 5.10.0 Known Issues (KB90382).
Additional information
Installation instruction: To install, repair, and verify the cumulative update and Agent Handler updates, refer Cumulative update installation procedures.
Important details about Service pack 1 Update 3: Before you upgrade refer the Mandatory Prerequisites and Upgrade Requirements for SHA-2 migration, and minimum OS/SQL requirements.
Disaster recovery: For information about disaster recovery, restoration, and required repair package versions, see Disaster recovery and restoration scenarios.