Genian ZTNA v6.0.16(LTS) Release Notes (SEP 2024)

Release Date: 2024/9/16, Last Updated: 2024/9/19 Description The last (R) mark is an additional release patch item.

Last Updated: 2024-09-19

Security Vulnerability

Key Description CVSS Score
#28063 Possible Blind Injection Issue in Node Management Search Bar. 2.2
#27107 Service disabled by Tomcat restart command by unauthorized administrator. 2.7
#26393 Vulnerability where information can be modified by entering a URL directly to an unauthorized page. 3.1
#26390 File export privilege bypass vulnerability via auditlog REST API by unauthorized administrator. 3.1
#27492 Tomcat Version Upgrade (8.5.94 -> 8.5.96 / 9.0.81 -> 9.0.83). 7.5
#26315 Improved two-step authentication to limit the number of times authentication codes can be entered and the time limit. 4.3
#27278 Tomcat Version Upgrade (8.5.94 / 9.0.81). 7.5
#27014 Passkey re-registration function could be used to register a passkey without authorization. 3.9
#26935 Vulnerability where html tags where displayed with department name were executed in tree. 1.2
#26835 Command Injection vulnerability via SQL used to update data. 6.6
#26833 nmap script tampering vulnerability in the process of updating the sensor's NMDB. 4.1
#26696 Insufficient validation of incoming events from a sensor. 6.3
#26694 Parameter Injection vulnerability due to lack of validation of download URL. 6.6
#26383 html/script code injection vulnerability. 5.3

New Features and Improvements

Key Description
#19829 “Added option to allow on-prem backup files to be restored to cloud."
#23316 “Improved upgrades by including sensors/agents in policy server image."
#24332 “Improved so a specific Blocked message page appears when blocked by URL filter."
#24976 “Added Flow Application Name statistics widget to the dashboard."
#25063 “Added 6.0 version widget."
#26117 “Updated the macOS ZTNA Agent minimum supported OS to macOS Big Sur (11.0) or higher."
#26187 “Added ability for user registration page to be able to search by administrator's email for the guest."
#26330 “Improved support for Keycloak by adding a federation provider to use NAC userDB for Keycloak authentication."
#26381 “Added organization name (USER_COMPANY) column to user management list."
#26442 “Added openvpn package to ubuntu target."
#26450 “Improved scrolling to move to the top when moving pages in the history management list."
#26479 “Improved to unblock the blocked nodes when shutting down through the sensor reboot / poweroff command."
#26535 “Improved WLAN monitoring function to work when running DKNS sensor."
#26563 “Improved to allow sensors to manage Alias IP bands without setting Alias IP on sensor interface."
#26619 “Added option to enable or disable when performing NMAP scan in HNAP-NSE."
#26644 “Changed Center CA certificate installation option to default ON and change how often it is performed."
#26724 “Update of Axgate 80D / 200AX model porting module kernel upgrade (2.6.38->4.14.196)."
#26729 “Improved support for AhnLab V3 information collection when using macOS Agent AV Information Collection Plugin."
#26730 “Improved icons for macOS Agent ZTNA and changed the connection display."
#26766 “Added a distribution plugin based on macOS Sigstore e-signature."
#26778 “Added node group conditions for IP/MAC additional field."
#26789 “Added electronic signature validation of operational information data synchronized with GeniAnsync."
#26791 “Increased the number of custom fields available when batch registering nodes (uploading CSV files) to 20."
#26792 “Improved policy server incoming event validation."
#26838 “Removed ICMP Timestamp support feature."
#26879 “Added IP/MAC additional field management option."
#26981 “Improved so authorization window is not displayed when using Windows agent File Distribution Plugin V2."
#26987 “Improved so authorization window is not displayed when using Linux agent File Distribution Plugin V2."
#26988 “Improved so authorization window is not displayed when using macOS agent File Distribution Plugin V2."
#27013 “Improve to allow conversion of items set in markdown."
#27031 “Patched CVE-2023-32629 Local privilege escalation vulnerability in Ubuntu OverlayFS module."
#27038 “Upgraded webssh to 16.17."
#27045 “Added IP / MAC additional field to Node Management list."
#27046 “Added node bulk registration and node property import fields to node registration."
#27121 “Added macOS agent support for new OS 14.0(Sonoma)."
#27142 “Updated the integration module for the new version of pill."
#27146 “Improved so if external authentication connection via extauth failed the password is no longer in the center debug file."
#27164 “Improved to better handle linkupdelys during the interface health check failure tests to prevent unnecessary switching to master/slave state."
#27206 “Added ability to send down trusted node ids from the center to sensors and agents."
#27207 “Improved to validate server events in Agent when using Windows Agent multipolicy server."
#27241 “Improved to validate server events in Agent when using macOS Agent multipolicy server."
#27248 “Improved to validate server events in Agent when using Linux Agent multipolicy server."
#27269 “Remove unnecessary permissions on apache/tomcat related directories and files."
#27390 “Improved Number of Reports to Retain feature to also delete data in /disk/data/report directory when setting report retention count."
#27402 “Improved API to set start/end time when modifying MAC policy."
#27462 “Improved to download only cosign file corresponding to the operating system (64/32 bit) when installing File Distribution V2 plugin."
#27625 “Improved so the sensor operation mode and policy changes do not lag when PUBILC IP is not imported."
#27972 “Changed SSL certificates to generated with a 10-year validity period."
#27973 “Upgrade to OpenSSL 3.0.13 and 1.1.1w - Excessive resource usage when checking X.509 policy constraints."
#28368 “Improved macOS Agent to now support the newly released macOS 15 (codenamed Sequoia)."

Issues Fixed

Key Description Affects Version/s
#24708 “Fixed an issue where environments with many sensor debugs set to send to policy server after reboot could be overloaded with outdated debug deletion behaviors.” 5.0.0
#25831 “Fixed an issue where the input type changed when adding/removing field assignments in Usage Management.” 4.0.11
#26299 “Fixed an issue where Authentication was allowed even if the domain was different from the associated user domain.” 5.0.53
#26300 “Fixed an issue that caused CWP device application and alarm message timezone inconsistencies." 5.0.50
#26314 “Fixed an issue where removing department names etc. from IP application list settings would cause labels to not be visible in the IP application.” 4.0.11
#26341 “Fixed an issue where when synchronizing Tibero/Altibase/DB2 information only the ID was synchronized.” 6.0.8
#26354 “Fixed an issue where Local DB account information was not displaying when authenticating.” 5.0.53
#26372 “Fixed an issue where web access of ZTNA Client was not communicated via SWG after activating URL Filter.” 6.0.12
#26380 “Fixed an issue where the IP application form was not downloading from IPMGMT.” 5.0.43 6.0.0
#26382 “Fixed an issue that caused a Http Status 400 - Bad Request error when setting or adding a SAML IdP in User Authentication > Authentication Integration > SAML2 Authentication Integration.” 5.0.25
#26408 “Fixed an issue that caused an intermittent sensor daemon death when adding a condition that did not belong to a node group to a node group.” 4.0.114 5.0.11
#26431 “Fixed an issue where checking the connection IP of the management console using 'x.x.x.x x.x.x.x’ format the connection is not possible even if the IP is available.” 5.0.33
#26432 “Fixed an issue in Windows Authentication window Wireless Connection Manager where the logo is displayed incorrectly.” 5.0.39 6.0.0
#26459 “Fixed an issue where ZTNA Client Split tunneling did not work when using the fixed IP option.” 6.0.11
#26467 “Fixed an issue where a popup window intermittently displayed as unvalidated reason even after validation with password validation action.” 5.0.6 6.0.0
#26487 “Fixed an issue that caused an Error page to display when there is no value in the CVE detail view.” 5.0.24
#26490 “Fixed an issue where when a custom server domain was set ZTNA connection attempted to connect to the default port.” 6.0.15
#26511 “Fixed an issue where the incorrect log ID appeared in the report auto-generated log.” 6.0.1
#26551 “Fixed an issue where when checking macOS Agent multiple action performance conditions only the result of the last condition is displayed.” 5.0.21 6.0.0
#26566 “Fixed an issue where after updating the node information the information is not updated and displayed when moving the tab.” 5.0.50
#26606 “Fixed an issue with the macOS authentication window where a login was not performed when hitting the enter key once.” 5.0.15
#26643 “Fixed an issue where when removing the Agent Self-Authentication window action policy the previously displayed authentication window was still displayed.” 5.0.0 6.0.0
#26674 “Fixed an issue where the Node management control policy column was displayed as blocked (orange color) even when control policy was set to (PERM-ALL).” 6.0.7
#26687 “Fixed an issue where the time in the node management last action time column was displayed without applying the administrator's timezone.” 4.1.M4
#26751 “Fixed an issue that was causing false positive deadlock detection causing a restart.” 6.0.16(LTS) 5.0.57
#26759 “Fixed an issue where when adding a condition to a RADIUS policy the value was not displayed when modifying a directly entered value item.” 6.0.11
#26785 “Fixed an issue were using a device control policy the device control policy of another node group could be received.” 5.0.23
#26840 “Fixed an issue where the node details information was displayed differently from the output settings.” 6.0.4
#26870 “Fixed an issue where a NAC nodes was not tagged when setting response policy via NAC integration in EDR.” 5.0.42 5.0.45 6.0.2
#26886 “Fixed an issue that was causing ZTNA Client connection error in DKNS.” 6.0.15
#26887 Fixed an issue where the Tooltip of control policy column of node list was not updating when switching sensor mode. 5.0.50 6.0.11
#26895 Fixed an issue where the collect software information plugin failed on macOS Mac mini M2 models. 5.0.11
#26898 “Fixed an issue where the Dashboard license warning message was displaying HTML as text." 6.0.15
#26901 “Fixed an issue where the Policy update was not working due to building with wrong endian." 6.0.5 5.0.48
#26930 “Fixed an issue where the search filter related function did not work when disabling alarm transmission failure message." 5.0.39
#26931 “Fixed an issue where the Motherboard information (updateinfo) was not being deleted." 5.0.52 6.0.13
#26934 “Fixed an issue where the ZTNA Client session monitoring information was not accurate." 6.0.15
#26938 “Fixed an issue where the Linux Agent new node registration failed due to local network change detection error." 5.0.51 6.0.11
#26956 “Fixed an issue where an error message was displayed when modifying the authentication linking settings." 6.0.16(LTS) 5.0.55(LTS) 5.0.56(50LTS)
#26957 “Fixed an issue where actions being performed immediately regardless of the scope of the macOS plugin." 6.0.5 5.0.48
#26958 “Fixed an issue where ZTNA static IP assignment resulted in new IP being assigned." 6.0.13
#26969 “Fixed an issue that was causing XSS false positive issue with Get Parameter(QueryString)." 5.0.42 5.0.50 5.0.53 5.0.54 4.0.155 6.0.15
#26972 “Fixed an issue that caused error ‘BadQuery=Illegal mix of collations’ when SLAVE device was present." 5.0.42 5.0.50 5.0.53 5.0.54 4.0.155 6.0.15
#26973 “Fixed an issue where the macOS user notification message would not pop up when performed periodically." 5.0.42 5.0.50 5.0.53 6.0.14
#27000 “Fixed an issue where moving to user detail screen by link in Node Management List > Authenticated User column would display a Invalid parameter message." 6.0.5 5.0.50
#27012 Fixed an issue where the ZTNA Client tried to access other sensors when connecting to ZTNA Client. 6.0.4
#27016 “Fixed an issue where the Service port of localconf was being changed to unspecified value by sensor daemon." 5.0.42
#27037 “Fixed an issue where Apache failed to run when setting the same HTTPS port as the admin console port." 5.0.42
#27047 “Fixed an issue where an Elastic-specific initialization error when running Tomcat caused Percolate to fail to initialize." 5.0.53 6.0.14
#27053 “Fixed an issue where the AUTHUSER column was not available in the get node properties settings." 5.0.30
#27058 “Fixed an issue where depending on the internal/external status some action would not be performed after a reboot." 5.0.43 6.0.0
#27066 “Fixed an issue that caused a CMD window to display error when executing script in File Deployment V2." 5.0.42 4.0.156 6.0.16(LTS) 5.0.55(LTS) 5.0.56(50LTS)
#27084 “Fixed an issue that caused false positives for URLEncode processed parameters in the XSS check logic logs." 5.0.42 5.0.50 5.0.53 5.0.54 4.0.155 6.0.15
#27085 “Fixed an issue where if logged in to management console with SAML the disconnect and connect (force login) function did not work." 5.0.48 6.0.6
#27088 “Fixed an issue where the URL Filter function was not working." 6.0.4
#27089 “Fixed an issue that caused the GnDaemon to restart when integrity check command was issued by from the macOS Agent management console." 5.0.42 5.0.54 6.0.15 5.0.56(50LTS)
#27091 “Fixed an issue where Event log(procmond process) sent by sensor was not saved with unknown center did error on policy server." 5.0.42
#27106 “Fixed an issue where only some nodes were covered when applying node policies immediately." 5.0.42 5.0.50 5.0.53 5.0.54 4.0.155 6.0.15
#27113 “Fixed an issue where the Update information(sysinfo) sent from the slave device failed to update to unknown devid." 4.0.145 5.0.42 6.0.1
#27127 “Fixed an issue that stopped Offline PMS process when using the Windows Update plugin." 5.0.42 4.0.156 6.0.16(LTS) 5.0.55(LTS) 5.0.56(50LTS)
#27132 “Fixed an issue where the policy server had errors if a % string existed in a mysql password." 5.0.42 5.0.50 5.0.53 5.0.54 4.0.155 6.0.15
#27136 “Fixed an issue where the macOS USB blocking was not working." 5.0.50 6.0.9
#27137 “Fixed an issue where a macOS message window contents were not visible." 5.0.42 5.0.50 5.0.53 5.0.54 6.0.14
#27151 “Fixed an issue where a command terminated during migration causing migration to fail." 5.0.42 5.0.50 5.0.53 5.0.54 4.0.155 6.0.15
#27152 “Fixed an issue where when multiple nodes with the same IP address were present the wrong node was output in the matrix view." 4.0.8
#27154 “Fixed an issue where the link in the connected device column in the node list was working even though switch was deleted in switch management." 5.0.38
#27158 “Fixed an issue where when changing IP additional field of user settings list type node information could not be updated” 6.0.16(LTS) 5.0.55(LTS)
#27162 “Fixed an issue where gdcid daemon did not start after booting the device." 5.0.42
#27176 “Fixed an issue that caused the macOS update plugin to not working correctly." 5.0.11
#27177 “Fixed an issue where backup file contained agent zip files resulting in increased size." 6.0.16(LTS) 5.0.55(LTS)
#27183 “Fixed an issue where the Re-registration event sent from the policy server to the sensor was not processed by the sensor." 5.0.42
#27187 “Fixed an issue where the agent information was not displayed properly on new Cloud Policy Server." 5.0.45 6.0.2
#27198 “Fixed an issue where the ZTNA NAT exception range did not work when setting multiple subnet ranges." 6.0.12
#27200 “Fixed an issue that caused 'BadQuery=Illegal mix of collations' errors to occur in slave center." 5.0.42 5.0.50 5.0.53 5.0.54 4.0.155 6.0.15
#27203 “Fixed an issue where when sending after a certain period of time (5 minutes) even if the result of an action is changed unspecified." 5.0.0 6.0.0
#27209 “Fixed an issue where IP application approval was completed but the request email notification was not going through." 5.0.46 6.0.4
#27210 “Fixed an issue where control policy names were not being recorded in Netflow logs." 6.0.16(LTS)
#27221 “Fixed an issue where Linux Agent terminated abnormally when collecting monitors with non-existent EDID values from the Monitor Information Collection plugin." 6.0.12
#27224 “Fixed an issue where input dialog not shown when screen was locked with agent authentication window." 5.0.49 6.0.7
#27237 “Fixed an issue where a node was not immediately re-registered by the sensor when deleting an agent node registered to a sensor from the management console." 5.0.42
#27259 “Fixed an issue where Linux Agent was not working when installing the agent with certain packages." 5.0.45 6.0.2
#27279 “Fixed an issue where setting trust-nodeserver-id on a center device was only applied after restarting the sensor daemon." 5.0.42 4.0.156 6.0.16(LTS) 5.0.55(LTS) 5.0.56(50LTS)
#27290 “Fixed an issue where the Sensor tree was not displaying correctly when sensor name contained a ‘%’." 5.0.43 6.0.0
#27291 “Fixed an issue that caused a 'The parameter value is invalid' error when the Alias sensor name contained a special characters such as '*' and '-' etc." 5.0.42 4.0.156 6.0.16(LTS)
#27292 “Fixed an issue where when selecting IP/MAC list in policy settings in node details no selection was entered." 6.0.16(LTS) 5.0.55(LTS)
#27345 “Fixed an issue where markdown was not being applied after cpage ready stage." 5.0.42 4.0.156 6.0.16(LTS) 5.0.55(LTS) 5.0.56(50LTS)
#27358 “Fixed an issue where the Start/stop sensor service function of centerd execution option did not work." 5.0.42 4.0.156 6.0.16(LTS) 5.0.55(LTS) 5.0.56(50LTS)
#27359 “Fixed an issue where event queueing worked even in processes that did not need event retransmission processing resulting in same event already exist in queue debug." 5.0.42
#27380 “Fixed an issue that caused an abnormal termination when ‘%’ character exists in the action check condition other than macros supported by the agent." 5.0.0 6.0.0
#27382 “Fixed an issue where 'Additional field - parameter value is invalid' error occurred when including Korean and some special characters in the user selector." 5.0.42 5.0.50 5.0.53 4.0.155 6.0.15
#27383 “Fixed an issue where a 'parameter value is invalid' error occurred and modified it so that characters of all languages could be entered into Korean input fields." 5.0.42 4.0.156 6.0.16(LTS) 5.0.55(LTS) 5.0.56(50LTS)
#27385 “Fixed an issue where the iptables command could fail when running concurrently." 5.0.0 6.0.0
#27388 “Fixed an issue where webssh connection was not working." 5.0.42
#27393 “Fixed an issue where mapping column key set in IP / MAC additional field user selector did not work." 6.0.16(LTS) 5.0.55(LTS)
#27394 “Fixed an issue where backup failed when setting absolute path to SFTP storage device path." 5.0.50 5.0.53 5.0.54 4.0.155 6.0.15
#27396 “Fixed an issue where last movement time column were displayed incorrectly when exporting the node list." 6.0.16(LTS) 5.0.55(LTS)
#27398 “Fixed an issue with Linux Agent where conditions only scan actions did not update when the result changes." 5.0.50 6.0.15
#27399 “Fixed an issue where macOS plugin behaviors were inconsistent depending on internal/external state." 6.0.5 5.0.48
#27400 “Fixed an issue where Passkeys were not being registered in Agent." 6.0.16(LTS)
#27401 “Fixed an issue that caused abnormal termination of sensor process when receiving the same event from sensor device." 4.0.64
#27417 “Fixed an issue where where Status & Filters > Tags > Node Tags was not being displayed correctly." 6.0.16(LTS)
#27437 “Fixed an issue where OS information on macOS Sonoma devices were being categorized as unknown." 6.0.16(LTS) 5.0.55(LTS) 5.0.56(50LTS) 6.0.17 5.0.57 4.0.157
#27442 “Fixed an issue where sorting of the last action time column in the node management list screen was not working properly." 6.0.16(LTS) 5.0.55(LTS)
#27446 “Fixed an issue where SOAP API processing would freeze and uses 100% CPU if an empty password is entered when using external authentication connection (runauth)." 5.0.42 6.0.16(LTS) 5.0.55(LTS) 5.0.56(50LTS) 5.0.57 4.0.157
#27451 “Fixed an issue where Audit > Flow log list was not sorting by time." 6.0.1
#27460 “Fixed an issue where the aes256 command was not being executed on initialization." 5.0.42 6.0.16(LTS) 5.0.55(LTS) 5.0.56(50LTS)
#27467 “Fixed an issue where adding XSS to node action description would cause XSS execution in the policy enforcement popup." 5.0.42 5.0.50 5.0.53 5.0.54 4.0.155 6.0.15
#27480 “Fixed an issue where you were not able to search for conditions of department selection type among node group conditions." 5.0.31 6.0.0
#27490 “Fixed an issue that cause 'Invalid settings: sp_cert_not_found_and_required' message when clicking SAML login button in CWP." 6.0.13
#27496 “Fixed an issue where the Linux Agent was intermittently missed sending action system information." 5.0.50 6.0.15
#27502 “Fixed an issue where agent logon API processing was delayed when the agent/sensor down check by Keepalive took a long time." 5.0.42
#27504 “Fixed an issue that caused NodeID related DB error (Illegal mix of collations) in log when receiving KeepAlive was not generated." 5.0.31 6.0.0
#27510 “Fixed an issue where NAC package upgrades were not added to library." 5.0.42
#27517 “Fixed an issue where Nodes REST API was not modifying certain items." 5.0.8 4.0.111
#27541 “Fixed an issue where if the connection to the information synchronization server failed the entire user was deleted because it was treated as a deleted user." 6.0.9
#27550 “Fixed an issue where data components in tree structures were not being displayed." 6.0.16(LTS) 5.0.55(LTS) 6.0.17 5.0.57
#27561 “Fixed an issue where LDAP configuration file were set to the wrong file on Universal OS causing the ldapsearch commands to fail." 5.0.42
#27573 “Fixed an issue where clicking the number of people in each group in the status by user group was not being displayed." 4.0.156 6.0.16(LTS) 5.0.57
#27574 “Fixed an issue where ES index (nac-filter) for log filter were deleted during ES log cleaning cycle." 5.0.50 6.0.11
#27575 “Fixed an issue where ES log filter action did not work when the query result were larger than 2K." 4.1.M6
#27617 “Fixed an issue where the operating system information collection action locked the AD account when checking if an empty password was used." 4.0.109 5.0.6 6.0.0
#27641 “Fixed an issue where the web console could not be accessed after multiple attempts because code was not being returned to the pool in the tomcat log." 5.0.20
#27652 “Fixed an issue where Google OTP authentication could not proceed because the Google OTP security key issued by the center was not being sent to the agent." 6.0.13
#27749 “Fixed an issue where that caused the Edit User Information page in CWP to not be accessible." 6.0.16(LTS) 5.0.55(LTS) 5.0.56(50LTS) 6.0.18 5.0.58
#27769 “Fixed an issue where some nodes were bing blocked due to a policy enforcement error after IP policy changes." 5.0.30 6.0.0
#27983 “Fixed an issue where event packets sent by 5.0/6.0 policy server were not processed by 4.0.1 sensors." 5.0.42 6.0.16(LTS)
#27986 “Fixed a compatibility issue with SLSA TUF certificate renewal." 5.0.42 5.0.50 6.0.15 4.0.156
#27993 “Fixed an issue where the DNS cache feature could not be turned off if the maximum number of DNS caches setting in System > Preferences was not applied." 6.0.12 5.0.53
#27994 “Fixed an issue where the Linux agent File Deployment Plugin V2 failed when the verification method was Sigstore Keyless Signing." 5.0.50 5.0.53 5.0.54 6.0.15
#28003 “Fixed an issue where the Windows agent File Deployment Plugin V2 failed when the verification method was Sigstore Keyless Signing." 5.0.42 4.0.155 6.0.15 5.0.56(50LTS)
#28005 “Fixed an issue where the macOS agent File Deployment Plugin V2 failed when the verification method was Sigstore Keyless Signing." 6.0.16(LTS) 5.0.55(LTS) 5.0.56(50LTS)
#28036 “Fixed an issue where logging out by clicking the top logout button on the management console did not leave a ‘Administrator logged out.’ entry in log.” 5.0.42 4.0.156 6.0.16(LTS) 5.0.55(LTS) 5.0.56(50LTS)
#28047 “Fixed an issue with snmp daemon not working on [Universal OS] sensors." 6.0.15 5.0.55(LTS)
#28130 “Fixed an issue that caused daemon to abnormally terminate when sending event packets from the center daemon and sensor daemon." 5.0.42 4.0.155 6.0.16(LTS)
#28228 “Fixed an issue that could cause a Sensor to repeatedly go into up/down state." 5.0.42
#28295 “Fixed an issue where the entire log was deleted if the policy server DB connection fails." 4.1.3
#28306 “Fixed an issue where executing a system command result were intermittently not obtained causing the process to behave abnormally." 5.0.42
#28410 “Fixed an issue where even when the administrator's management scope was limited all logs could be checked in the real-time mode of the logs." 5.0.45 6.0.2
#28418 “Fixed an issue where the Windows Update action did not apply the install/check at specified time option." 5.0.0 6.0.0
#28422 Fixed an issue where Locale (Korean, English, etc.) could not be changed on the management console login page. 6.0.16(LTS) 5.0.55(LTS) 5.0.56(50LTS) 6.0.17 5.0.57