When users are patching to JSA version 7.3.1 patch 4 and above, they get the following prompt:
"This update contains a mitigation for CVE-2017-5754 Variant 3/Meltdown provided by Red Hat that can impact search performance. Administrators must read the release notes before they install this update. Choices: 1) Enable: Turn ON the mitigation for Variant 3/Meltdown on all appliances. 2) Disable: Turn OFF the mitigation for Variant 3/Meltdown on all appliances. IF YOU CHOOSE NOT TO ENABLE THIS UPDATE TO ADDRESS CVE-2017-5754, YOU WILL NOT HAVE ANY PROTECTION AGAINST VARIANT 3/MELTDOWN. 3) Terminate patch."
Performance assessment summary Administrators can expect performance degradation after they enable the mitigation for the vulnerability.
Due to the potential search performance change when CVE-2017-5754 (Variant 3/Meltdown) is enabled, the installation of JSA 7.3.1 Patch 4 includes a utility to allow administrators to enable or disable the mitigation after the initial installation/patch completes. Administrators must be aware of the security implications if they choose to use this utility to disable the mitigation for CVE-2017-5754 (Variant 3/Meltdown). Juniper cannot be held responsible for risks incurred by administrators who choose to disable the mitigation for CVE-2017-5754.
/opt/qradar/bin/configure-spectre-meltdown-fixes.sh enable-all
/opt/qradar/bin/configure-spectre-meltdown-fixes.sh enable
/opt/qradar/bin/configure-spectre-meltdown-fixes.sh disable-all
/opt/qradar/bin/configure-spectre-meltdown-fixes.sh disable