ESX Virtualization

VMware ESXi, vSphere, VMware Backup, Hyper-V... how-to, videos....

Nakivo Backup and Replication - #1 Backup solution for Virtual, physical, cloud, NAS and SaaS

Menu
  • Certification
      • VCP-DCV vSphere 8
          • vcp2024-125.
        • Close
    • Close
  • VMware
    • Configuration Maximums
    • vSphere
      • vSphere 8.0
      • vSphere 7.0
      • vSphere 6.7
      • vSphere 6.5
      • vSphere 6.0
      • Close
    • VMworld
      • VMware EXPLORE 2024
      • VMware EXPLORE 2023
      • VMware EXPLORE 2022
      • VMworld 2019
      • VMworld 2018
      • VMworld 2017
      • VMworld 2016
      • VMworld 2015
      • VMworld 2014
      • VMworld 2013
      • VMworld 2012
      • VMworld 2011
      • Close
    • Close
  • Microsoft
    • Windows Server 2012
    • Windows Server 2016
    • Windows Server 2019
    • Close
  • Categories
    • Tips – VMware, Microsoft and General IT tips and definitions, What is this?, How this works?
    • Server Virtualization – VMware ESXi, ESXi Free Hypervizor, VMware vSphere Server Virtualization, VMware Cloud and Datacenter Virtualization
    • Backup – Virtualization Backup Solutions, VMware vSphere Backup and ESXi backup solutions.
    • Desktop Virtualization – Desktop Virtualization, VMware Workstation, VMware Fusion, VMware Horizon View, tips and tutorials
    • How To – ESXi Tutorials, IT and virtualization tutorials, VMware ESXi 4.x, ESXi 5.x and VMware vSphere. VMware Workstation and other IT tutorials.
    • Free – Free virtualization utilities, ESXi Free, Monitoring and free backup utilities for ESXi and Hyper-V. Free IT tools.
    • Videos – VMware Virtualization Videos, VMware ESXi Videos, ESXi 4.x, ESXi 5.x tips and videos.
    • Home Lab
    • Reviews – Virtualization Software and reviews, Disaster and backup recovery software reviews. Virtual infrastructure monitoring software review.
    • Close
  • Partners
    • NAKIVO
    • StarWind
    • Zerto
    • Xorux
    • Close
  • This Web
    • News
    • ESXi Lab
    • About
    • Advertise
    • Archives
    • Disclaimer
    • PDFs and Books
    • Close
  • Free
  • Privacy policy

vCenter Server 5.5 U1a released fixing Heartbleed

By Vladan SEGET | Last Updated: April 20, 2014

Shares

VMware has rolled out new update on vCenter server 5.5 U1a. This update fixes a Heartbleed bug in OpenSSL third party library. HearbleThere are no new features in this release and only vCenter server and vCenter server appliance are on the list of updated products. The bug was affecting a Windows based vCenter server and VMware Client integration plugin . vCSA (Linux based vCenter server appliance) is not affected, but the product got an update as well passing from build 1624811 (5.5 U1) to 1750781 (5.5 U1a).

The procefure of updating of vCenter certificates, Single sign-on directory service and is well documented and once SSO is upgraded and new certificates are generated, a new password for [email protected] (default admin for SSO) must be created. Details are in the KB – Resolving OpenSSL Heartbleed for VMware vCenter Server 5.5

Quote from the release notes:

  • Vulnerability in OpenSSL third party library 
    The OpenSSL library is updated to version openssl-1.0.1g to resolve the Heartbleed issue.
    The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the nameCVE-2014-0160 to this issue.
    Details on this vulnerability can be found in VMware Security Advisory VMSA-2014-0004.Note:

    1. After upgrading to vCenter Server 5.5 Update 1a, to remediate the issue, you need to replace certificates and reset passwords. For more information, see Resolving OpenSSL Heartbleed for vCenter Server 5.5 (KB 2076692).
    2. After upgrading the vSphere Web Client, you also need to update the Client Integration plugin by performing the following steps:
      1. Open a web browser and enter the URL for the vSphere Web Client:https://client-hostname:port/vsphere-client.
      2. At the bottom of the vSphere Web Client login page, click Upgrade the Client Integration Plug-in.
      3. Download and install the Client Integration Plug-in.

Since some users are currently running vCenter sever 5.5 (a, b or c version) and others runs on vCenter server 5.5 U1. There are different upgrade paths concerning vCenter server and also the certificates, and changing of passwords for SSO admin and other users (if created) on the SSO.

Screenshot from my lab showing the change in release builds.

vCenter Server 5.5 U1a released fixing Hearbleed bug

Quote from the Resolving OpenSSL Heartbleed for VMware vCenter Server 5.5 KB article:

There are two vCenter Server 5.5. releases issued to overcome the issue:

  • If you are currently running vCenter Server 5.5 GA build 1312298, 1378903 or 1476327 you should upgrade to vCenter Server 5.5.0c build 1750596.

Note: vCenter Server 5.5.0c should not be updated to vCenter Server 5.5 Update 1. You can upgrade vCenter Server 5.5.0c to vCenter Server 5.5 Update 1a build 1750787.

  • If you are currently running vCenter Server 5.5 Update 1 build 1623101 you should upgrade to vCenter Server 5.5 Update 1a 1750787

Well this is certainly interesting as most users aren't yet on the latest 5.5 U1 or not even on the 5.5 GA. However it's a fast reaction from VMware part to fix a critical vulnerability affecting a critical (vCenter server ) system.

Links:  

  • Resolving OpenSSL Heartbleed for VMware vCenter Server 5.5
  • VMware Release Notes of the Update for vCenter server 5.5 U1a
  • VMware Product Updates

 

Shares
Vote !

| Filed Under: Server Virtualization Tagged With: vCenter Server 5.5 U1a

About Vladan SEGET

This website is maintained by Vladan SEGET. Vladan is as an Independent consultant, professional blogger, vExpert x16, Veeam Vanguard x9, VCAP-DCA/DCD, ESX Virtualization site has started as a simple bookmarking site, but quickly found a large following of readers and subscribers.

Connect on: Facebook. Feel free to network via Twitter @vladan.

Private Sponsors

Featured

  • Thinking about HCI? G2, an independent tech solutions peer review platform, has published its Winter 2023 Reports on Hyperconverged Infrastructure (HCI) Solutions.
  • Zerto: One Platform for Disaster Recovery, Backup & Cloud Mobility: Try FREE Hands-On Labs Today!
Click to Become a Sponsor

Most Recent

  • Veeam Backup & Replication v13 Beta: A Game-Changer with Linux
  • What is Veeam Data Cloud Vault and how it can help SMBs
  • Nakivo Backup and Replication – Malware Scan Feature
  • Zerto 10 U7 released with VMware NSX 4.2 Support
  • XorMon NG 1.9.0 Infrastructure Monitoring – now also with Veeam Backup Support
  • Heartbeat vs Node Majority StarWind VSAN Failover Strategy
  • Vulnerability in your VMs – VMware Tools Update
  • FREE version of StarWind VSAN vs Trial of Full version
  • Commvault’s Innovations at RSA Conference 2025 San Francisco
  • VMware ESXi FREE is FREE again!

Get new posts by email:

 

 

 

 

Support us on Ko-Fi

 

 

Buy Me a Coffee at ko-fi.com

Sponsors

Free Trials

  • DC Scope for VMware vSphere – optimization, capacity planning, and cost management. Download FREE Trial Here.
  • Augmented Inline Deduplication, Altaro VM Backup v9 For #VMware and #Hyper-V – Grab your copy now download TRIAL.

VMware Engineer Jobs

VMware Engineer Jobs

YouTube

…

Find us on Facebook

ESX Virtualization

…

Copyright © 2025 ·Dynamik-Gen · Genesis Framework · Log in