Patches for the server

This window displays all patches associated with the selected managed server.

Show Options – Windows

You can use the Show drop-down list to filter the following types of patch information:

  • Patches Installed: This option displays all patches that have been installed on the server.
  • Patches Recommended By Vendor: This option displays all application and operating system patches that have been recommended by the Windows patch database for the selected server. If multiple patches have the same QNumber, Patch Management detects the application files that are already installed on a managed server and, subsequently, recommends the correct patch to install.
  • Patches with Policies or Exceptions: This option displays patches in policies attached to the selected server, or patches that have ‘always install’ or ‘never install’ exceptions, and have one of the following conditions:
    • The patches are not currently installed and are recommended by the vendor.
    • The patches are currently installed.
  • Patches Needed: This option displays all patches that should be installed on the selected server but are not. These include patches that are in policies attached to that server, or patches that have always install exceptions, and are recommended by the vendor.
  • Patches with Exceptions: This option displays all patches that have exceptions (such as always install or never install) and have one of the following conditions:
    • The patches are not currently installed and are recommended by the vendor.
    • The patches are currently installed.
  • All Patches: This option displays all patches that are associated with the operating system of the server.

Show Options – UNIX

The Show options for UNIX patches display the following information:

  • All Patches: This option displays all patches that are associated with the operating system of the server.
  • Patches Installed: This option displays all patches that have been installed on the server.

Patch Contents – Windows

The Show options for Windows patches display the following information:

  • Icon: A dimmed icon means that the patch has not yet been uploaded to the Software Library.
  • Name: This is the QNumber of a patch that is a hotfix or an update rollup. Service pack patches do not have a QNumber.
  • Compliance: This shows one of the following three levels of patch policy compliance, as defined by a patch administrator:
    • Policy Only: Compliance that includes the policy only.
    • Policy and Exception: Compliance that includes the policy and the policy exceptions.
    • Customized: Customized compliance.
  • Non-Compliant (red): This indicates that the patch is installed on the server, but is not in the policy, or that the patch is not installed on the server but is in the policy.
  • Partial (yellow): This indicates that the policy and exception do not agree, and the exception does not have data in the Reason field.
  • Compliant (green): This indicates one of the following conditions:
    • A patch is installed on the server and is in a policy, or a patch is not installed on the server and is not in a policy.
    • A patch is installed on the server and there are additional patches with the same QNumber in a patch policy or exception. In this case, all patches with the same QNumber are considered installed when Patch Management calculates patch compliance.
    • A patch is not installed on the server and is in a patch policy or has an always install exception, and is not recommended by the vendor. In this case, the patch has a never install exception, because it is not recommended by the vendor.

    In the Preview pane, move the cursor over the icon or text in the Compliance column to view patch compliance information about a server.

  • Type: This shows the type of patch, such as Windows Hotfix or Windows Update Rollup.
  • Bulletin: (Optional) This shows the Microsoft Security Bulletin ID number for this patch.
  • Severity: (Optional) This shows one of the following three Microsoft severity ratings for this patch:
    • Critical: This indicates a patch whose exploitation could allow the propagation of an internet worm, without user action.
    • Important: This indicates a patch whose exploitation could result in a compromise of the confidentiality, integrity, availability of user data, or of the integrity or availability of processing resources.
    • Moderate: This indicates a patch whose exploitability is mitigated to a significant degree by certain factors, such as default configuration, auditing, or the difficulty of exploitation.
    • Low: This indicates a patch whose exploitation is extremely difficult, or whose impact is minimal.
  • Release Date: This displays the date that Microsoft released this patch.
  • Exception: This displays the type of patch policy exception set for the selected server.
  • Installed: This shows if the patch is installed on the selected server.
  • Recommended: A check mark indicates that this patch was recommended by the vendor (Windows patch database) during the last software registration.
  • Description: This displays a description of the server.
  • Opsware ID: (Optional) This displays a unique Opsware ID that identifies the patch object.
  • Locale: (Optional) This displays the encoding of the patch contents.
  • OS: (Optional) This displays the operating system version of the server.

Patch Contents – UNIX

This shows the following Unix patch content information:

  • Icon: A dimmed icon means that the patch has not yet been uploaded to the Software Library.
  • Type: This shows the type of patch, such as Solaris Patch, HP-UX Patch Fileset, and so on.
  • Installed: This shows if the patch is installed on the selected server.
  • Description: This displays a description of the server.
  • Install Date: This displays the date the patch was installed on the server.
  • Opsware ID: (Optional) This displays the unique Opsware ID that identifies the patch object.
  • OS: (Optional) This displays the operating system version of the server.