6.9.17 Release Highlights
New features and improvements
- The application now provides additional information about the logs that may have not been cleaned during the archival and cleanup operation.
Security enhancements
-
The jars mentioned in the table below has been upgraded to remove critical and high vulnerabilities in it.
Old version Updated version ehcache-2.10.6.jar ehcache-3.10.8.jar spring-web-6.1.5.jar spring-web-6.1.8.jar bcprov-jdk18on-1.77.jar bcprov-jdk18on-1.78.1.jar commons- configuration-1.10.jar commons-configuration2-2.10.1.jar commons-logging-1.1.2.jar commons-logging-1.2.jar commons-beanutils : 1.9.4.jar commons-beanutils-1.9.4.1.jar opensaml-soap-api-4.3.0.jar opensaml-soap-api-4.3.1 netty-handler-4.1.107.Final.jar netty-handler-4.1.110.Final.jar -
The following vulnerabilities in the application have been fixed:
- Privilege Escalation
- IDOR - Insecure Direct object reference
- Email Flooding
- Improper implementation of reset password feature
- Username Enumeration
- No Rate limiting
-
The users were able to access the following pages even when they were logged out of the application:
https://<domain>/rest/aisresources/uploadjmsjar.jsphttps://<domain>/rest/aisresources/uploadjasperfile.jshttps://<domain>/rest/aisresources/HITemplateNonForm.jsphttps://<domain>/rest/aisresources/uploadjarfiles.jsp
Bug fixes
The following bugs have been fixed with this release:
Process Flow
- The Delete On Success feature failed to delete the source file after the execution of the Process Flow when the source file name contained a special character.
Schema
- Source file for an Excel Schema failed to be processed when the header in the file contained \r or \n.
- When the Text Schema with Dynamic Header Support enabled was processed and the source file did not contain a header, the application showed incorrect number of records with no value in them at the destination.
Mapping
- In a Mapping, the users were not able to set a context variable when the Generate Stream field was set to false and the destination had a Schema.