Deploying a security fix

Cyberwatch offers patch management. The patching view of an asset lists all the present vulnerabilities with their patch. Deploying a security fix on a vulnerability can fix several vulnerabilities.

Manually apply a corrective action

Corrective actions with the status “To be processed manually” occur on software whose automatic patching is not supported by Cyberwatch.

For such applications, two actions are possible:

  • Uninstalling the software either manually or directly through Cyberwatch.
  • Manually patching the software by connecting to the relevant asset.

Dependency Management

  • Linux: If these patches have dependencies, they will also be installed when the patch is deployed.
  • Windows: The patch can be a Microsoft cumulative update.

Deploying a security fix from the page of an asset

  1. Click on Inventory
  2. Choose the concerned asset
  3. In the page dedicated to the asset, click on the “Patch management” tab
  4. Check the security fixes you want to deploy
  5. Click on the “Schedule selected fixes” button
  6. Choose the deploying period allowed for the deployment, and confirm with the “Schedule selected fixes” button

Deploying a security fix from the page of a vulnerability

  1. Click on Vulnerabilities Encyclopedia
  2. Choose the concerned vulnerability
  3. In the page dedicated to the vulnerability, check the assets on which you want to deploy the security fixes
  4. Click on the caret right to the “Ignore and comment” button
  5. Click on “Schedule selected fixes”
  6. Choose the deploying period allowed for the deployment, and confirm with the “Schedule selected fixes” button

Uninstalling a package or an application

  1. Click on Inventory
  2. Choose the concerned asset
  3. In the page dedicated to the asset, click on the technologies tab
  4. Find the package/application in the list
  5. Click on the deletion button at the end of the line and confirm the uninstallation request.

Deleting an executable

  1. Click on Inventory
  2. Choose the concerned asset
  3. In the page dedicated to the asset, click on the technologies tab
  4. Find the executable in the list
  5. Click on the deletion button at the end of the line and confirm the request.

This deletion will not modify any configuration or additional files used by this executable, and such files must be deleted by you, outside of Cyberwatch.

Enabling the deployment of corrective actions for Microsoft KBs from Cyberwatch

To apply corrective actions for Windows and Microsoft applications, Cyberwatch deploys Microsoft KBs part of one of these three type:

  • Security updates
  • Critical updates
  • Monthly roll ups

In order to enable Cyberwatch to apply these updates, the WSUS has to be configured to automatically approve updates belonging to one of the above classifications.

Official documentation on how to configure these automatic approvals.

List of software covered by the Patch Management module

  • Linux: any software installed with the package manager of the distribution can be patched or uninstalled
  • Windows: Microsoft software (supported by security KBs)

List of software uninstallable by Cyberwatch

All applications installed by MSI can be uninstalled via Cyberwatch. Here is the list of applications for which the uninstallation parameters have been checked by our teams:

  • Adobe Acrobat
  • Chrome
  • Firefox
  • Firefox ESR
  • Gimp
  • iTunes
  • JAVA
  • KeePass
  • LibreOffice
  • Putty
  • Thunderbird
  • VirtualBox
  • VLC
  • Wireshark
  • 7-Zip