Network Management

Verify That the SUPERNOVA Patch Was Applied to All Orion Platform Web Servers

If you have applied one of the SUPERNOVA Security Fixes (2018.2 HF6 Security Fix, 2018.4 HF3 Security Fix, 2019.2 HF3 Security Fix), this article describes two ways (a script and manual steps) to confirm that the fix was applied correctly to Orion Platform versions 2018.2, 2018.4, and 2019.2.

First published date

12/30/2020 7:38 PM

Last published date

3/25/2021 4:05 PM

Overview

If you are running Orion Platform version 2018.2, 2018.4, or 2019.2, you can do either of the following to verify that one of the SUPERNOVA Security Fixes (2018.2 HF6 Security Fix, 2018.4 HF3 Security Fix, 2019.2 HF3 Security Fix) for the recent SUPERNOVA security vulnerability has been applied to your main Orion server and any additional web servers:

  • If you have PowerShell version 5 installed, you can run a script to perform the verification.
  • If you do not have PowerShell version 5 or you prefer not to run a script, you can perform manual steps to verify the fix.

See the Resolution section for instructions.

Notes: 

  • These instructions will not verify application of the SUPERNOVA Mitigation Script, which can be used to provide a temporary patch for all Orion Platform version 11.x and above. Use the guidance set forth in the document within that Mitigation Script package to confirm the temporary patch was correctly applied. (Also see Mitigate your Orion Platform environment from the risk of the SUPERNOVA vulnerability.)
  • For other Orion Platform versions not addressed in this article (for clarity, this article addresses Orion Platform versions 2018.2, 2018.4, and 2019.2), please consult the guidance within the Security Advisory FAQ for details on actions needed to address SUPERNOVA vulnerability. 

Important: The Security Fixes update only the files that were affected by the SUPERNOVA security vulnerability, such as the OrionWeb.dll file in the website folder (by default C:\InetPub\SolarWinds\bin). There is also an OrionWeb.dll file in the Orion installation folder (by default C:\SolarWinds\Orion). The OrionWeb.dll file in the installation directory was not affected by the security vulnerability, and it does not need to be updated.

Product section

Orion Platform

Resolution

-- Scripts are not supported under any SolarWinds support program or service.
-- Scripts are provided AS IS without warranty of any kind. SolarWinds further
-- disclaims all warranties including, without limitation, any implied warranties
-- of merchantability or of fitness for a particular purpose. The risk arising
-- out of the use or performance of the scripts and documentation stays with you.
-- In no event shall SolarWinds or anyone else involved in the creation,
-- production, or delivery of the scripts be liable for any damages whatsoever
-- (including, without limitation, damages for loss of business profits, business
-- interruption, loss of business information, or other pecuniary loss) arising
-- out of the use of or inability to use the scripts or documentation.

Run a script to verify that the patch was applied

Note: The script requires PowerShell version 5.

  1. Download the Verification Script from the following location:
    https://downloads.solarwinds.com/solarwinds/Documentation/KB_attachments/Verify-SupernovaPatch.zip

  2. Extract the Verification Script from the .zip file and verify the signature.

  3. Run the script on each Orion Platform server on which you placed the SUPERNOVA Security Fixes (2018.2 HF6 Security Fix, 2018.4 HF3 Security Fix, 2019.2 HF3 Security Fix), including the main Orion server and any additional web servers.

  4. Verify that the output of the Verification Script is "All relevant files have been patched."

Perform manual steps to verify that the patch was applied

  1. On your main Orion server, go to the Orion website directory (for example, C:\inetpub\SolarWinds), and perform the following steps:

    1. Verify that the file global.asax is present.

    2. Verify that the SHA-256 hash value of the global.asax file is one of the following values:

      3E2954136DBD34966DA1BF053A97C2387783D49294159FF86D0B1EFAA9683EC5
      F2C1A0667B792DD6AC138F8ECC41BB57DCCA287316253A9F7A3C9ED7ECDA5D54
      9876E575FD3E0923A503E393D3C0F43A5F43803214D715BAB2A938E9524CF58C

  2. Open the \bin directory within the Orion website directory, and verify that the OrionWeb.dll file is signed with the current certificate:

    1. Right-click the OrionWeb.dll file and choose Properties.

    2. Click the Digital Signatures tab.

    3. Select the signature with the SHA-256 algorithm and click Details.

    4. Verify that the date in the Signing time box is Wednesday, December 23, 2020.

    5. Click View Certificate.

    6. Click the Details tab.

    7. Scroll down the list of fields and click Thumbprint. Then verify that the Thumbprint value matches the following:

      a8f6ab73b6212b866a170242efdf3bc99d9241b4