Absent Member.
Absent Member.
8335 views

How to update Fortify tool to latest version ?

HI All,

We need to update fortify tool to latest version. what are the steps which need to be followed ?

can we also update it through command line mode.

0 Likes
7 Replies
Commander Commander
Commander

The steps for upgrade/installing (really it is installing the new version, two versions can coexist on the same system.  It comes down to which sourceanalyzer.exe you call.  By default, the installer will put the latest install path in the front of the PATH environment variable to make sure it gets called first.)

You can do a commandline/silent (unattended) install.  Look at page 13 of the HPE Security Fortify Static Code Analyzer Installation Guide file (https://www.protect724.hpe.com/docs/DOC-14786).

0 Likes
Absent Member.
Absent Member.

Thanks Stephen Burris ! The document is very helpfull.

0 Likes
Absent Member.
Absent Member.

Hi Stephen,

I have tried few option mentioned in SSC install guide bit it seem complex as first timer. My concern is I just need to upgrade SSC without upgrading database or webInspect server. can you guide me stepwise one by one then it will be very helpfull.

Thanks and Regards,

Tanuj Pathak

0 Likes
Commander Commander
Commander

Tanuj,

Can you start a new question and give a little more detail about what you want?  I am not sure what your starting point is and what you are planning on accomplishing.  It also might help if you tell us what you tried and why it didn't work.

0 Likes
Absent Member.
Absent Member.

Hi Stephen,

My original Question was how to upgrade fortify SCA, SSC and Webinspect from 16.1 to 16.2?

So Far what i have got is as follows:

1. We have 5 different servers:

a) SSC

b) SCA

c) Database(SQL server 2008 R2)

d) Web Inspect Enterprise

e) Web Inspect sensor.

2. We have to check Pre-requirement like jdk 1.8, tomcat 8 etc which we have already installed on SSC server.

Question :

Do we have to install anything else for this upgrade or anything need to be check on third party tools?

3. We have to upgrade SSC first which require all old database migration through SSC.war file

Question:

where I find old ssc.war file, what is the exact path etc ?

4. Do we need to make any changes to Database also. What is database collation properties ?

5. We have to upgrade SCA.

Question: Do we any document for SCA intall ?

6. We have to upgrade WebInspect.

Question: Do we any document for WebInspect intall ?

7. We have to upgrade Webinspect Sensor.

Do we any document for Do we any document for WebInspect sensor ?

0 Likes
Commander Commander
Commander

The first thing you want to check is the documentation.  This lays out all the hardware and software requirements for the products you mentioned.  Note: the main thing that concerns me is your DB version (2008 R2).  None of the products officially support that DB version in 16.1 or 16.2.  This is not to say it will not work (because obviously it is), but we do not test against that scenario and support may not be able to help you.

Documentation, when you logon to this site and navigate to the Fortify section ( ), at the top is a link to our product documentation, that contains all the documents for all versions of our Fortify software.

To your questions:

2. Do we have to install anything else for this upgrade or anything need to be check on third party tools?

- Those look good, since you already have it SSC up and running, you shouldn't need any additional tools then what you have (except for my note about the DB server).

3. Where I find old ssc.war file, what is the exact path etc ?

I would look at your current Tomcat webapps directory and get the current (16.1) ssc.war file from there.  The default install location on Windows is: C:\Program Files\Apache Software Foundation\Tomcat X\webapps (X is the version of tomcat)

4. Do we need to make any changes to Database also. What is database collation properties?

The database collation should be fine, you only had to worry about that back around SSC 4.3/4.3 time-frame.

There most likely will be schema updates that need to be done, that will be on a product by product basis.

5. Do we any document for SCA install ?

6: Do we any document for WebInspect install?

I assume you mean WebInspect Enterprise: (the WebInspect Sensor is just WebInspect configured to work as a sensor, see question 7)

7. Do we any document for Do we any document for WebInspect sensor?

Here is the order I would upgrade the products:

  1. SSC
  2. WebInspect Enterprise
    1. First the manager
    2. Then the sensors
  3. SCA
0 Likes
Absent Member.
Absent Member.

Thanks Stephen for you time.

I have updated SCA but when we check the SCA version (command : sourceanalyzer -version) from command line it still say 16.10.

Question: Does it updated or do we need to restart the server or some services so that the changes take effect ?

Also when we tried to update security content we got error messag

There has been an error. Update rule packRulepeck error.jpg failed! Application will exit now"

0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.