Tools

Web Help Desk 12.7.7 Hotfix 1 Release Notes

This article describes how to install Web Help Desk 12.7.7 Hotfix 1 on your Web Help Desk server.

First published date

12/22/2021 10:31 AM

Last published date

12/22/2021 2:36 PM

Overview

This hotfix resolves the following issues:
  • Put and Delete methods are enabled when they should be disabled
  • Specific internal endpoints security
This hotfix modifies the following files in the <WebHelpDesk>/bin/webapps/helpdesk/WEB-INF/lib/ directory:
  • whd-core.jar
  • whd-persistence.jar
  • whd-web.jar
This hotfix adds the following file in the <WebHelpDesk>/bin/webapps/helpdesk/WEB-INF/lib/ directory:
  • java-jwt.jar
If you are running Microsoft Windows, this hotfix modifies the following files in the <WebHelpDesk> directory:
  • whd.bat
  • whd_start.bat
This hotfix requires Web Help Desk 12.7.7.8388.

NOTE: In the installation instructions, <WebHelpDesk> represents the Web Help Desk home folder. The default home folders for the supported operating systems are listed below.
Operating SystemPath
macOS/Library/WebHelpDesk
Microsoft Windows\Program Files\WebHelpDesk
Linux/usr/local/webhelpdesk


CVEs

SolarWinds would like to thank our Security Researchers below for reporting on the issue in a responsible manner and working with our security, product, and engineering teams to fix the vulnerability.
CVE-IDVulnerability TitleDescriptionSeverityCredit
CVE-2021-35232Hard-coded credentials found in SolarWinds Web Help Desk which allows to execute Arbitrary HSQL queries.Hard-coded credentials in SolarWinds Web Help Desk. Through these credentials an attacker could be allowed to execute arbitrary HSQL queries against the database. MediumShubham Shah 
CVE-2021-35243HTTP PUT and DELETE Methods EnabledThe HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (versions 12.7.6 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data saved on the server with a user-supplied URL. While the DELETE method requests the origin server remove the association between the target resource and its current functionality. Improper use of these methods may lead to a loss of integrity.MediumN/A

Product section

Web Help Desk

Resolution

Download this hotfix

  1. Log in to the Web Help Desk server as an administrator.
  2. Open a Web browser, navigate to the SolarWinds Customer Portal, and log in.
  3. Click Downloads and select Hotfixes.
  4. Click the View Hot fixes for License drop-down menu and select Web Help Desk Per Seat License.
  5. Download Web Help Desk v12.7.7 - Hot Fix 1. 

Install this hotfix

  1. Stop Web Help Desk.
  2. If you are running Linux on MacOS, go to step 3. If you are running Windows, perform the following steps:
    1. Navigate to the <WebHelpDesk> directory.
    2. Back up the following files to a separate directory
      • whd.bat
      • whd_start.bat
    3. Copy the files included with this hotfix to the <WebHelpDesk> directory:
      • whd-bat
      • whd_start.bat
  3. Navigate to the following directory:
    • <WebHelpDesk/bin/webapps/helpdesk/WEB-INF/lib/
  4. Back up the following files to a separate directory:
    • whd-core.jar
    • whd-persistence.jar
    • whd-web.jar
  5. Copy the files included with this hotfix to the /lib directory, overwriting the following files:
    • whd-core.jar
    • whd-persistence.jar
    • whd-web.jar
    • java.jwt.jar
  6. Start Web Help Desk. The hotfix is installed.

Uninstall the hotfix

  1. Stop Help Desk.
  2. Navigate to the following directory:
    • <WebHelpDesk>/bin/webapps/helpdesk/WEB-INF/lib/
  3. Copy your backup files to the /lib directory, overwriting the following files:
    • whd-core.jar
    • whd-persistence.jar
    • whd-web.jar
  4. If you are running Linux on macOS, go to step 5. If you are running Windows, perform the following steps:
    1. Navigate to the <WebHelpDesk> directory.
    2. Copy the following backup files to the <WebHelpDesk> directory, overwriting the following files:
      • whd.bat
      • whd_start.bat
  5. Start Web Help Desk. The hotfix is uninstalled.
For assistance, contact SolarWinds Technical Support