README for CCMP 12.5(1) ES6 *************************** ABOUT THIS DOCUMENT ------------------- This document provides installation instructions for CCMP 12.5(1) ES6. The document also describes the issues that have been addressed in this ES. Please review all sections in this document pertaining to ES deployment before deploying the ES. PRE-REQUISITE STEPS ------------------- ------------------------------------------------------------------------------------------------------------------------------------ -- DATABASE SERVER -- Execute the following steps on all Database Servers ------------------------------------------------------------------------------------------------------------------------------------ 1. Stop UCCMP Provisioning Server service. 2. Take a backup of the following files from the Provisioning installation directory in the "Management Portal\Provisioning" folder Java\lib\log4j-1.2-api-2.11.1.jar Java\lib\log4j-api-2.11.1.jar Java\lib\log4j-core-2.11.1.jar Java\lib\log4j-jcl-2.11.1.jar Java\lib\log4j-jul-2.11.1.jar Java\lib\log4j-slf4j-impl-2.11.1.jar ------------------------------------------------------------------------------------------------------------------------------------ ------------------------------------------------------------------------------------------------------------------------------------ DEPLOYMENT STEPS ---------------- ------------------------------------------------------------------------------------------------------------------------------------ -- DATABASE SERVER -- Execute the following steps on all Database Servers ------------------------------------------------------------------------------------------------------------------------------------ 1. Stop UCCMP Provisioning Server service (Ignore if already done). 2. Delete the following files from the Provisioning installation directory in the "Management Portal\Provisioning" folder Java\lib\log4j-1.2-api-2.11.1.jar Java\lib\log4j-api-2.11.1.jar Java\lib\log4j-core-2.11.1.jar Java\lib\log4j-jcl-2.11.1.jar Java\lib\log4j-jul-2.11.1.jar Java\lib\log4j-slf4j-impl-2.11.1.jar 3. Add the following files from the Provisioning installation directory in the "Management Portal\Provisioning" folder Java\lib\log4j-1.2-api-2.16.0.jar Java\lib\log4j-api-2.16.0.jar Java\lib\log4j-core-2.16.0.jar Java\lib\log4j-jcl-2.16.0.jar Java\lib\log4j-jul-2.16.0.jar Java\lib\log4j-slf4j-impl-2.16.0.jar 4. Start UCCMP Provisioning Server service. ------------------------------------------------------------------------------------------------------------------------------------ ------------------------------------------------------------------------------------------------------------------------------------ ROLLBACK STEPS ------------------------ ------------------------------------------------------------------------------------------------------------------------------------ -- DATABASE SERVER -- Execute the following steps on all Database Servers ------------------------------------------------------------------------------------------------------------------------------------ 1. Stop UCCMP Provisioning Server service. 2. Delete the following files from the Provisioning installation directory in the "Management Portal\Provisioning" folder Java\lib\log4j-1.2-api-2.16.0.jar Java\lib\log4j-api-2.16.0.jar Java\lib\log4j-core-2.16.0.jar Java\lib\log4j-jcl-2.16.0.jar Java\lib\log4j-jul-2.16.0.jar Java\lib\log4j-slf4j-impl-2.16.0.jar 3. Add the backed up from step 2 of pre-requisite steps in the Provisioning installation directory in the "Management Portal\Provisioning" folder Java\lib\log4j-1.2-api-2.11.1.jar Java\lib\log4j-api-2.11.1.jar Java\lib\log4j-core-2.11.1.jar Java\lib\log4j-jcl-2.11.1.jar Java\lib\log4j-jul-2.11.1.jar Java\lib\log4j-slf4j-impl-2.11.1.jar 4. Start UCCMP Provisioning Server service. ------------------------------------------------------------------------------------------------------------------------------------ ISSUES RESOLVED IN THIS ENGINEERING SPECIAL -------------------------------------------------------- CSCwa47383: Evaluation of ccmp for Log4j RCE (Log4Shell) Vulnerability vulnerability