My Oracle Support Banner

Web Server Updates for Secure Global Desktop 5.2 (Doc ID 2038218.1)

Last updated on APRIL 04, 2019

Applies to:

Oracle Secure Global Desktop - Version 5.2 to 5.2 [Release 5.0]
Information in this document applies to any platform.
This document is specific to patches of type "Webserver," a discrete package format of the Secure Global Desktop Patch Mechanism.

Details

We are pleased to announce the availability of Web Server Updates for Oracle Secure Global Desktop (SGD), version 5.2.

Please Note: There are other patches available for SGD 5.2, including JVM and Patch Set Updates. For details on these and more, please see the Secure Global Desktop Release Announcement Reference, (Doc ID 2093579.2). The RAR always includes the latest information regarding SGD releases, and a matrix of all available patches for any supported version of the product.

 

Web Server Updates

Patches of this type are intended to update the third party components that are bundled and shipped with Secure Global Desktop as the SGD Web Services stack, and may include new versions Apache's HTTPd Server, OpenSSL, and the Tomcat Servlet Container.  These patches are available to customers with a valid Customer Support Identifier with named support for the Secure Global Desktop product.

Note: These patches are valid for the core component of SGD 5.2 only.  SGD Web Server updates for the SGD Gateway are only delivered within scheduled Patch Set Updates.

 

August 2017

The August 2017 Web Server update for SGD 5.2 is now available to interested Administrators by special request of Oracle's Desktop Virtualization team.   This is the latest tested—and fully supported—web server update for Secure Global Desktop, 5.2.

This update should be applied in parallel with the April 2017 update, below.

Included Components

Component Version Package
Apache HTTP Server   2.2.34   apache-2.2.34_openssl-1.0.2k_jk1.2.42_64
OpenSSL   1.0.2k  
mod_jk   1.2.42  

Bug Fixes

The following table is intended as a high-level reference for the updates included in this patch.

Bugs fixed within August 2017 WS Update
26364896
26533269
PROBLEM WITH APACHE WEBSERVER:
CVE-2017-3167 CVE-2017-3169 CVE-2017-7659 CVE-2017-7668 CVE-2017-7679
CVE-2017-9788

Additional details regarding the solutions included within this update may be found within the README that is bundled directly with the update.


April 2017

The April 2017 Web Server update for SGD 5.2 is now available for download from within My Oracle Support.  This patch is an important prerequisite for the August 2017 Update.

Included Components

Component VersionPackage
Apache HTTP Server   2.2.32 apache-2.2.32_openssl-1.0.2k_jk1.2.42_64
OpenSSL   1.0.2k
mod_jk   1.2.42
Apache Tomcat Servlet Container   7.0.75 tomcat-7.0.75

Bug Fixes

The following table is intended as a high-level reference for the updates included in this patch.

Bugs fixed within April 2017 WS Update
25487780 DO NOT DISPLAY TOMCAT SERVER IDENTITY
25469930 PROBLEM WITH APACHE WEBSERVER:
CVE-2016-8743
25231216
25027873
PROBLEM WITH TOMCAT WEBSERVER:
CVE-2016-0762 CVE-2016-5018 CVE-2016-6794 CVE-2016-6796 CVE-2016-6797
CVE-2016-6816 CVE-2016-6817 CVE-2016-8735

Additional details regarding the solutions included within this update may be found within the README that is bundled directly with the update.

 

Reference

Superseded Webserver Patches

The patches outlined below are included here for reference, but have been superseded by a later release.  These patches may still be available independently to interested Administrators by special request of Oracle's Desktop Virtualization team, via Service Ticket in My Oracle Support (MOS).

July 2016
DatePlatformChecksumNotesValidity
July 2016 Solaris X86 1661489561 13276694
SGD_WS_Jul2016_i3so.tar.gz

Includes: Apache HTTPd 2.2.31, Tomcat 7.0.68, OpenSSL 1.0.2h, mod_jk 1.2.41

This update bundle may be installed on a fresh deployment, or in parallel with previous PSU and/or WebServer Updates for SGD 5.2.

This bundle is only supported on:

SGD 5.2
Solaris SPARC 1501169654 13075734
SGD_WS_Jul2016_spso.tar.gz
Linux 651374963 13218885
SGD_WS_Jul2016_i3li.tar.gz
April 2016
DatePlatformChecksumNotesValidity
April 2016 Solaris X86 2022347246 13275440 SGD_WS_Apr2016_i3so.tar.gz Includes: Apache HTTPd 2.2.31, Tomcat 7.0.68, OpenSSL 1.0.2g, mod_jk 1.2.41

This update bundle may be installed on a fresh deployment, or in parallel with previous PSU and/or WebServer Updates for SGD 5.2.
This bundle is only supported on:

SGD 5.2
Solaris SPARC 3697591908 13076206 SGD_WS_Apr2016_spso.tar.gz
Linux 1754605796 13219057 SGD_WS_Apr2016_i3li.tar.gz
January 2016
DatePlatformChecksumNotesValidity
January 2016 Solaris X86 2269313150 13683337 SGD_WS_Jan2016_i3so.tar.gz Includes: Apache HTTPd 2.2.31, OpenSSL 1.0.2d, Tomcat 7.0.62

This update bundle may be installed on a fresh deployment, or in parallel with previous PSU and/or WebServer Updates for SGD 5.2.
This bundle is only supported on:

SGD 5.2
Solaris SPARC 707354109 13414234 SGD_WS_Jan2016_spso.tar.gz
Linux 400496403 13185653 SGD_WS_Jan2016_i3li.tar.gz
July 2015
DatePlatformChecksumNotesValidity
July 2015 Solaris X86 1011146149 13586947 SGD_WS_Jul2015_i3so.tar.gz Includes: Apache HTTPd 2.2.29, OpenSSL 1.0.1m, Tomcat 7.0.62

This update bundle may be installed on a fresh deployment, or in parallel with previous PSU and/or JVM Updates for SGD 5.2.
This bundle is only supported on:

SGD 5.2
Solaris SPARC 181952663 13302687 SGD_WS_Jul2015_spso.tar.gz
Linux 3397134904 13057767 SGD_WS_Jul2015_i3li.tar.gz

Actions

Download the desired Web Server Update

PatchNames / Aliases
[26570003] August 2017 Web Server Update for SGD 5.2  |  SGD52WS_Aug17
[25800251] April 2017 Web Server Update for SGD 5.2 |  SGD52WS_Apr17

These patch clusters are available to contracted customers as Oracle Patches.  These patches may be downloaded using the links above, or from the My Oracle Support (MOS) Portal directly, by connecting to https://support.oracle.com with an internet browser.

  1. Authenticate with the portal using existing MOS credentials.
  2. Select the Patches and Updates tab.
  3. In the Patch Search tab, search by "Number / Name."
  4. Update the value for Patch Name or Number is to the relevant Patch ID above.
  5. Click the Search button.
  6. Select the appropriate installation platform from the available options, and schedule a download.


Verification

Before attempting to install any update in a production environment, it must be extracted from the download archive, which will implicitly verify the structural integrity.

To do so:

  1. Save the WS Update downloaded from MOS (i.e. p25800251_spso.zip) to the '/tmp' directory on every SGD host where it is to be applied.
  2. Expand the zip archive to prepare the WS update for instalation.
    For example:


Contacts

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Details
 Web Server Updates
 August 2017
 Included Components
 Bug Fixes
 April 2017
 Included Components
 Bug Fixes
 Reference
 Superseded Webserver Patches
 July 2016
 April 2016
 January 2016
 July 2015
Actions
 Download the desired Web Server Update
 Verification
 Installation
 Back-out
Contacts
References

My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.