Solace PubSub+ Event Broker (Software & Appliance) new versions are released

The following products have been released and are available for download:

  • Solace PubSub+ Event Broker 9.11.0.9

Release Summary

This release introduces the following new features:

  • RDP - Variable Targets
  • RDP - Additional HTTP Headers with Fixed/Variable Values
  • Support for cgroups v2
  • Support 30,000 Transacted Sessions at 100K and 200K connection tiers
  • Add Search Configuration to resolv.conf on Appliance

Vulnerability Notice

The following vulnerabilities have been addressed in this release (see Release Notes for details):

  • The PubSub+ Event Broker appliance and machine image are exposed to the following vulnerabilities:
  1. CentOS 7 : kernel security updates
    CVSS v3 Score: 7.8 (High)
    CVE: CVE-2020-29374, CVE-2021-23133, CVE-2021-33034, CVE-2021-32399, CVE-2020-26558, CVE-2021-0129, CVE-2020-
    24587, CVE-2020-24586, CVE-2020-24588, CVE-2020-26139, CVE-2020-26147, CVE-2021-29650, CVE-2021-3564, CVE-2021-
    3573, CVE-2021-3587, CVE-2021-34693, CVE-2021-38160, CVE-2021-3609, CVE-2021-3655, CVE-2021-33909, CVE-2021-
    38204, CVE-2021-3679, CVE-2021-37576, CVE-2021-22543
  2. CentOS 7 : kernel (CESA-2021:3327) (https://www.tenable.com/plugins/nessus/152970)
    CVSS v3 Score: 7.8 (High)
    CVE: CVE-2020-27777, CVE-2021-22555, CVE-2021-29154, CVE-2021-29650, CVE-2021-32399
  3. CentOS 7 : bind (https://nvd.nist.gov/vuln/detail/CVE-2021-25214)
    CVSS v3 Score: 6.5 (Medium)
    CVE: CVE-2021-25214

Download

Files can be retrieved from the Solace Products site using your account name and password.

Access

  • Access to the Solace PubSub+ Event Broker: Software Standard Edition is available to everyone at https://solace.com/downloads/
  • Access to the 90-day Solace PubSub+ Event Broker: Software Evaluation Edition is available to everyone at https://solace.com/downloads/
  • Access to the Solace PubSub+ Event Broker: Software Enterprise Edition is available to customers who have licensed the product.

If you need access to AWS for Solace PubSub+ Event Broker: Software downloads, please contact Solace at support@solace.com. Access to http://products.solace.com requires your account name and password.

Documentation

Solace product documentation can be found at: https://docs.solace.com

The following products have been released and are available for download:

  • Solace PubSub+ Event Broker Appliance and Software 9.9.0.37
  • Solace PubSub+ Event Broker Appliance and Software 9.10.0.21
  • Solace PubSub+ Event Broker Appliance and Software 9.11.0.10

Release Summary

These releases introduce the following product updates:

  • Updates to address the following vulnerabilities (Note: some vulnerabilities were addressed in previous 9.10.0 and 9.11.0 releases, and have now been backported to 9.9.0. See Release Notes for more details):
  1. CentOS 7 : kernel security updates
    CVSS v3 Score: 7.8 (High)
    CVE: CVE-2020-29374, CVE-2021-23133, CVE-2021-33034, CVE-2021-32399, CVE-2020-26558, CVE-2021-0129, CVE-2020-24587, CVE-2020-24586, CVE-2020-24588, CVE-2020-26139, CVE-2020-26147, CVE-2021-29650, CVE-2021-3564, CVE-2021-3573, CVE-2021-3587, CVE-2021-34693, CVE-2021-38160, CVE-2021-3609, CVE-2021-3655, CVE-2021-33909, CVE-2021-38204, CVE-2021-3679, CVE-2021-37576, CVE-2021-22543
  2. CentOS 7 : kernel (CESA-2021:3327) (https://www.tenable.com/plugins/nessus/152970 )
    CVSS v3 Score: 7.8 (High)
    CVE: CVE-2020-27777, CVE-2021-22555, CVE-2021-29154, CVE-2021-29650, CVE-2021-32399
  3. CentOS 7 : bind (https://nvd.nist.gov/vuln/detail/CVE-2021-25214 )
    CVSS v3 Score: 6.5 (Medium)
    CVE: CVE-2021-25214
  4. The remote CentOS Linux host is missing one or more security updates. (CESA-2021:3028) (https://www.tenable.com/plugins/nessus/152360 )
    CVSS v3 Score: 8.8 (High)
    CVE: CVE-2020-0543, CVE-2020-0548, CVE-2020-0549, CVE-2020-8695, CVE-2020-8696, CVE-2020-8698, CVE-2020-24489, CVE-2020-24511, CVE-2020-24512
  5. Java SE Vulnerability (https://nvd.nist.gov/vuln/detail/CVE-2021-2369)
    CVSS v3 Score: 4.4 (Medium)
    CVE: CVE-2021-2369
  6. Java SE Vulnerability (https://nvd.nist.gov/vuln/detail/CVE-2021-2341 )
    CVSS v3 Score: 3.1 (Low)
    CVE: CVE-2021-2341
  7. Java SE Vulnerability (https://nvd.nist.gov/vuln/detail/CVE-2021-2388 )
    CVSS v3 Score: 7.5 (High)
    CVE: CVE-2021-2388
  8. CentOS 7 : kernel (CESA-2021:2725) (https://www.tenable.com/plugins/nessus/151979 )
    CVSS v3 Score: 7.8 (High)
    CVE: CVE-2019-20934, CVE-2020-11668, CVE-2021-33033, CVE-2021-33034, CVE-2021-33909
  9. CentOS 7 : linuxptp (CESA-2021:2658) https://nvd.nist.gov/vuln/detail/CVE-2021-3570
    CVSS v3 Score: 9.1 (Critical)
    CVE: CVE-2021-3570
  10. CentOS 7 : kernel security updates
    CVSS v3 Score: 7.5 (High)
    CVE: CVE-2021-38205, CVE-2021-3732, CVE-2021-3653, CVE-2021-3656, CVE-2020-3702, CVE-2021-38198, CVE-2021-3753

Please refer to the product release notes for information on new features, changed functionality, resolved issues, known issues and upgrade considerations.

Download

Files can be retrieved from the Solace Products site using your account name and password.

Access

  • Access to the Solace PubSub+ Event Broker: Software Standard Edition is available to everyone at https://solace.com/downloads/
  • Access to the 90-day Solace PubSub+ Event Broker: Software Evaluation Edition is available to everyone at https://solace.com/downloads/
  • Access to the Solace PubSub+ Event Broker: Software Enterprise Edition is available to customers who have licensed the product.

If you need access to AWS for Solace PubSub+ Event Broker: Software downloads, please contact Solace at support@solace.com. Access to http://products.solace.com requires your account name and password.

Documentation

Solace product documentation can be found at: https://docs.solace.com