This Patch resolves the following issue(s):
Accounts in User Roles without a Policy Resource or Response permissions are logged-out of the web console after any of the following widgets are added into the first page of the Dashboard.
Top Violated Application Control Criteria Top Blocked Applications Attack Discovery Detections Top Endpoints Affected by IPS Events Top IPS Events Top IPS Attack Sources Vulnerability Protection
Solution
The hotfix resolves this issue.
There are no enhancements for this Patch release.
There are no files included in this Patch release.
To download or view electronic versions of the documentation set for this product, go to http://docs.trendmicro.com
To access the Online Help, go to http://docs.trendmicro.com
To install, run "apexcentral-win-en-patch1.exe" on the Apex Central server. A confirmation dialog box displays "Installation successful!" after the system completes the installation.
No special uninstallation instructions are provided.
Visit the following website to download the Installation and Upgrade Guide:
https://docs.trendmicro.com/all/ent/apex-cen/patch/en-us/apexCen_p1_iug.pdf
No post-installation steps required.
NOTE: Trend Micro recommends that you update your scan engine and virus pattern files immediately after installing the product.
Known issues in this release:
Users cannot configure proxy or authentication settings for Deep Discovery Inspector or Deep Discovery Email Inspector on the Edit Server screen.
The user or account name in Attack Discovery logs may be empty.
The signer info in the Attack Discovery logs may be empty.
Users encounter an "Out of memory" error when synching the Active Directory (AD) if there is a large number of AD groups.
Solution
This hotfix ensures that the AD sync function can handle a large number of AD groups.
The sample php files used to test for "log4php" show the internal path of applications.
Solution
This hotfix removes this potential vulnerability.
The AD sync function cannot work normally when there is a large number of AD Organizational Units (OU).
Solution
This hotfix ensures that the AD sync function can handle a large number of AD OUs.
The Dashboard, LogQuery, Active Directory, and Compliance Settings pages of the Apex Central web console are affected by Reflected Cross-Site Scripting (XSS) vulnerabilities.
Solution
This hotfix removes these vulnerabilities.
It takes long time to display the contents of Active Directory (AD) domains in the "User/Endpoint Directory" page.
Solution
This hotfix improves the performance of some related queries so that the "User/Endpoint Directory" page can display the contents of AD domains faster.
In Control Manager 7.0 GM Build Patch 1, the scheduled hourly download job does not run on time.
Solution
This hotfix ensures that the scheduled hourly download job runs on time.
An issue prevents Node Apex Central from syncing the Suspicious Objects list with the Hub Apex Central.
Solution
This hotfix resolves the issue so that Node Apex Central can sync the Suspicious Objects list with the Hub Apex Central successfully.
Sometimes, Apex Central is unable to SSO to Apex One server.
Solution
This hotfix ensures that Apex Central is able to SSO to Apex One server successfully.
A high CPU usage issue occurs when the value of the "bigwatermark" field is NULL.
Solution
This hotfix prevents the high CPU usage issue under this scenario.
Data Discovery ad hoc query results cannot be generated.
Solution
This hotfix ensures that the Data Discovery ad hoc query results contain complete and accurate information.
An issue prevents Apex Central from pushing the Data Loss Prevention™ (DLP) template to Trend Micro InterScan™ Web Security Virtual Appliance (IWSVA).
Solution
This hotfix resolves the issue so that Apex Central can push the DLP template to IWSVA successfully
The "AD connection disabled" warning icon appears in the "User/Endpoint Directory" page of the Apex Central console when the Active Directory (AD) server name is too long.
Solution
This hotfix ensures that long AD server names no longer trigger the warning icon on the "User/Endpoint Directory" page.
When the Active Directory (AD) filter is re-set, all child under a parent with a "half-checked" checkbox are not counted and re-selected.
Solution
This hotfix ensures that when counting the total number of ADs, each parent with a half-checked checkbox counts and reselects all child under it.
Users cannot Single Sign-On (SSO) to the Apex one web console from the Apex Central web console.
Solution
This hotfix ensures that users can SSO to the Apex One web console from the Apex Central web console.
A performance issue prevents users from downloading the "Unmanaged Endpoints" list from the Dashboard Operation Center widget.
Solution
This hotfix resolves the performance issue so users can download the "Unmanaged Endpoints" list from the Dashboard Operation Center widget successfully.
The "DLP Incidents by Channel" widget does not display any information when users click on the "Incidents by Action" pie chart.
Solution
The hotfix ensures that the corresponding information displays after users click on the "Incidents by Action" chart on the "DLP Incidents by Channel" widget.
Widgets in the "DLP Incident Investigation" page do not display any information.
Solution
This hotfix ensures that widgets in the "DLP Incident Investigation" page display information normally.
The C&C Callback Events widget does not display correct results.
Solution
This hotfix ensures that the C&C Callback Events widget displays complete and accurate query results.
In the "Scheduled/Manual update" pages, if a user saves changes to the settings a second time without refreshing the page and without changing the UNC password, the original UNC password will be cleared, resulting in update failures.
Solution
This hotfix allows the user to save the changes in the "Scheduled/Manual update" pages multiple times without refreshing the pages.
The scheduled hourly download job does not run on time.
Solution
This hotfix ensures that the scheduled hourly download job runs on time.
Users may not be able to see some Active Directory (AD) users under specific domains while adding users to the "Active Directory user or group" list.
Solution
This hotfix ensures that users can view all users under each domain.
In Microsoft™ Edge, the Top Email Recipients of Advanced Threats widget and Email Messages with Advanced Threats widget display a blank page when users drill down on any information on the widgets.
Solution
This hotfix ensures that the widgets display complete and accurate information in Microsoft Edge.
When Apex Central deploys commands directly to the Trend Micro ServerProtect for Microsoft™ Windows™ NT Normal Server, the deployment may fail.
Solution
This hotfix ensures that Apex Central can deploy commands to the ServerProtect Normal Server normally.
On the Apex Central web console, "N/A" appears on the "Scan Method" column for Apex One agents that use "Conventional Scan".
Solution
This hotfix ensures that the correct Apex One agent scan method information is displayed on the Apex Central web console.
The scheduled hourly download job does not run on time.
Solution
This hotfix ensures that the scheduled hourly download job runs on time.
An issue prevents Apex Central from applying "Run cleanup when probable virus/malware is detected" to the apex One Security Agent Policy.
Solution
This hotfix resolves the issue.
If a child policy is set to inherit the settings from a parent policy that does not have a scan exclusion list, the child policy will not display the scan exclusion list after it is added to the parent policy.
Solution
This hotfix ensures a child policy that is set to inherit the settings from a parent policy displays the scan exclusion list once it is added to the parent policy.
There are some Cross-Site Scripting (XSS) vulnerabilities in the "Policy Management" page.
Solution
This hotfix removes these XSS vulnerabilities from the "Policy Management" page.
Some user accounts that have just been assigned read only access roles receive "Scheduled incident summary" and "Scheduled incident increase" notifications.
Solution
This hotfix ensures that user accounts that have read only access roles do not receive "Scheduled incident summary" and "Scheduled incident increase" notifications.
NOTE: This solution does not cover existing roles. You need to save each existing role again to apply the solution.
The Application Control Criteria could not be exported in Microsoft™ Internet Explorer™ or Edge web browser.
Solution
This hotfix updates the Apex Central files to fix this issue.
Users cannot see the users and endpoints in the "User/Endpoint Directory" page in Internet Explorer 11.
Solution
This hotfix ensures that the "User/Endpoint Directory" page displays normally in Internet Explorer 11.
This hotfix adds the following four hidden default fields in the Log Query page for iAC detection logs.
This hotfix adds the "Application" hidden default field in the Log Query page for iAC application control logs.
This hotfix adds the "Risk Level" field in the Log Query page for Attack Discovery detections.
This hotfix adds the following eight fields in the Log Query page for Attack Discovery detections.
This hotfix adds the following five fields in the Log Query page for Attack Discovery detections.
This hotfix enables Apex Central to support Trend Micro SafeLock.
This hotfix enables Apex Central to support Deep Discovery Director 3.5
This hotfix enables Apex Central to support the new engine component "Network Content Inspection Engine (3.10, Kernel mode, 64-bit, Conf: 5500)" for Trend Micro Deep Discovery Inspector 5.5.
This hotfix enables the AD to sync with the Global Catalog and to support SSL connections.
This hotfix allows users to import the Device Control approved list from the "Policies > Policy Resource > Device Control Approved Device List" page and apply the list to all Apex One Security Agent Policies.
This hotfix updates the Apex One (Mac) 2019 policy setting in Apex Central to support the latest build of the Apex One (Mac) 2019 agent.
The hotfix enables Apex Central to use the report title to name the corresponding report notification email attachment.
This hotfix updates the expression for the Data Loss Prevention™ (DLP) data identifier "Japan: Date" to the new era "令和".
This hotfix introduces the following enhancements for Endpoint Sensor.
Policy widget enhancements for Apex One (Mac):
The Dashboard is affected by Cross-Site Scripting (XSS) issues.
Solution
This hotfix resolves the issue.
The Antivirus Pattern Compliance dashboard of Control Manager incorrectly shows "-1%".
Solution
This hotfix ensures that Antivirus Pattern Compliance dashboard correctly shows the true value.
This hotfix improves the performance of the policy detail pages of the Apex Central web console.
This hotfix ensures that when users trigger the duplicate policy tasks, redundant tasks are not sent.
The Antivirus Pattern Compliance dashboard of Control Manager incorrectly shows "-1%".
Solution
This hotfix ensures that Antivirus Pattern Compliance dashboard correctly shows the true value.
Apex Central could not deploy the policy to agents with an IP address in the IPv6 ISATAP format.
Solution
This hotfix ensures that Apex Central translates the IPv6 ISATAP address to binary so it can deploy policies to affected agents correctly.
The "Product Connection Status" widget does not display any information.
Solution
This hotfix ensures that the "Product Connection Status" widget displays information normally.
The Dashboard is affected by Cross-Site Scripting (XSS) issues.
Solution
This hotfix resolves the issue.
The scan exclusion settings for Apex One Security Agent child policies are lost if the parent policy is edited.
Solution
This hotfix resolves the issue.
The Apex Central policy cannot overwrite an Apex One agent configuration that has been edited locally.
Solution
This hotfix ensures that policies deployed to Apex One work normally.
The license information of Trend Micro ServerProtect™ for Linux™ does not display in the product directory.
Solution
This hotfix ensures that the ServerProtect for Linux license information does displays normally in the product directory.
The MDR server receives incomplete log from Control Manager when network is slow.
Solution
This hotfix would ensure that Control Manager send complete log to MDR server.
In the "Log Maintenance" page, the number of product event logs always shows "0" even when there are logs in tb_AVEventLog.
Solution
This hotfix ensures that the correct product event log count displays on the "Log Maintenance" page.
When users add a User-Defined Suspicious Object with Scan Action set to "Block", the action will be saved as "Log" instead of "Block".
Solution
This hotfix resolves the issue to ensure that users can save User-Defined Suspicious Objects with "Block" scan action normally.
The endpoint count on Compliance Reports generated by Control Manager does not match the actual Trend Micro OfficeScan™ agent count.
Solution
This hotfix ensures that the correct endpoint count appears in Control Manager Compliance Reports.
An information leakage issue was found in the Dashboard.
Solution
This hotfix resolves the issue.
The Dashboard, LogQuery, Active Directory, and Compliance Settings pages of the Control Manager web console are affected by Reflected Cross-Site Scripting (XSS) issues.
Solution
This hotfix removes these issues.
An issue prevents Control Manager from applying Device Control Setting rules to the Trend Micro OfficeScan™ Agent Policy.
Solution
This hotfix resolves the issue so Control Manager can apply Device Control Setting rules to the OfficeScan Agent Policy.
A performance issue prevents the Control Manager web console from displaying Log Query results.
Solution
This hotfix resolves the performance issue so Log Query results can be displayed normally.
The AD sync function cannot work normally when there is a large number of AD Organizational Units (OU).
Solution
This hotfix ensures that the AD sync function can handle a large number of AD OUs.
The information in exported CSV and XML files may not match the corresponding information in the Control Manager web console.
Solution
This hotfix ensures that the information in exported CSV and XML files match the information on the Control Manager web console.
Administrators cannot deploy policy settings from Control Manager to Apex One.
Solution
This hotfix resolves the issue to ensure that Control Manager successfully deploys policy settings to Apex One.
The following Network Content Inspection Engine (NCIE) log headers are confusing users:
Solution
This hotfix renames the following Network Content Inspection Engine (NCIE) log headers to minimize confusion: CONFUSING HEADING -> FIXED HEADING
This hotfix updates the Deep Discovery Advanced Filter search mechanism to prevent a UI script injection error.
This hotfix adds a new filter type "Security risk scan filter" in the log query page.
This hotfix enables Apex Central to support Trend Micro Deep Discovery Director 5.0.
This hotfix adds the option to configure Apex Central to use a proxy server for hub/node registration and synchronization.
This hotfix enables Control Manager to support TMES 1.6 Update 6.
Duplicate GUID Agents now are recorded.
The update extends PHP execution time.
Trend Micro Security for Mac policy deployment on reliability and optimizing for huge amount of agent counts environment.
This hotfix ensures that when users trigger the duplicate policy tasks, redundant tasks are not sent.
This hotfix ensures that LogForwarder enables the ping function only when the connection protocol is UDP.
The following Network Content Inspection Engine (NCIE) log headers are confusing users:
This hotfix integrates Control Manager with version 9.1 of Trend Micro InterScan™ Messaging Security Suite (IMSS) for Linux™.
This hotfix adds the new "Predictive Machine Learning Local File Model" pattern.
This hotfix adds the new "Predictive Machine Learning Local File Model" pattern.
This hotfix redefines the following variables in Trend Micro Data Loss Prevention™ (DLP) syslog content.
This hotfix adds the following two fields in the "Incident Details" page.
This hotfix improves the performance of the policy detail pages of the Apex Central web console.
Cloud service integration with Cloud App Security allows you to sweep protected mailboxes, correlate Active Directory user information, and generate Analysis Chains in Apex Central to better understand threat vectors and distribution across the entire network.
The Operation Center fails to merge custom reporting line circles and displays random custom reporting line names. This issue occurs if the custom reporting lines include an Active Directory user without a manager.
Solution
The hotfix ensures that the custom reporting line displays correctly in this situation.
An issue prevents the Apex Central from purging the Behavior Monitor log.
Solution
The hotfix ensures that the Apex Central is able to purge the Behavior Monitor log in this situation.
A false rebuild index issue periodically causes the Apex Central to consume high CPU resources.
Solution
This hotfix resolves this issue.
The "Policy Management" page loads repeatedly after users click the "Endpoints/Products without policies" count on the page.
Solution
The hotfix ensures that the relevant information displays under the scenario described above.
Active Directory (AD) synchronization may fail because the mail column in the database is too small.
Solution
This hotfix makes the necessary adjustments so AD synchronization runs normally.
Active Directory synchronization is unsuccessful if the root domain of domain is unrecognition
Solution
This hotfix resolves the issue.
The "%Hierarchy%" token does not display any information in email notifications.
Solution
This hotfix ensures that the "%Hierarchy%" token displays the required information in email notifications.
After Trend Micro Apex One™ (Mac™) registers to Apex Central, the "Product Component Status" field displays "No data to display".
Solution
This hotfix resolves this issue so the correct product component status appears on the Apex Central web console.
An issue prevents the Policy Management screen from displaying properly.
Solution
This hotfix resolves the issue to ensure that the Policy Management screen displays properly.
File paths appear in the wrong format in syslogs.
Solution
This hotfix ensures that file paths appear in the proper syslog format.
Apex Central services stops unexpectedly.
Solution
This hotfix resolves this issue.
The "Local Folder" node on the product tree can be expanded when users create an Active Directory (AD) account with the "DLP_Compliance_Officer" or "DLP_Incident_Reviewer" role.
Solution
This hotfix ensures that the "Local Folder" node is greyed-out under this scenario.
Users do not receive C&C callback outbreak alert notifications.
Solution
This hotfix ensures that users receive C&C callback outbreak alert notifications.
The "Host Name" field in Behavior Monitoring Violations notifications displays the product server host name instead of the endpoint host name.
Solution
This hotfix ensures that the "Host Name" field in Behavior Monitoring Violations notifications displays the endpoint host name.
A high CPU usage issue occurs on the SQL server when purging Web Violations logs.
Solution
This hotfix prevents the high CPU usage issue from occurring in this scenario.
A performance issue causes an "Unable to execute SQL command. The database is busy. Try again after a few minutes." error in the "Historical Investigation" page of the Apex Central web console.
Solution
This hotfix prevents the error by improving the performance of the "Historical Investigation" page.
Users cannot search for targets to deploy policies by "Filter by Criteria" or "Specify Target(s)" in the "Policy Management" page.
Solution
This hotfix ensures that users can search for targets for policy deployment correctly.
The Product Directory page is affected by Cross-Site Scripting (XSS) issues.
Solution
This hotfix resolves the issue.
This hotfix renames the "Host Name" field to "Endpoint" in unmanaged endpoints dataview.
This hotfix expands the IP address columns used in the Data Loss Prevention™ (DLP) violation log so that it can support the IPv6 address format.
This hotfix enables Apex Central to support Trend Micro Deep Discovery Analyzer 6.9.
This hotfix renames the "system restart required" action to "reboot system successfully".
This hotfix adds the new "Endpoint Sensor Activity Filtering Pattern" pattern.