Hotfix 9.0.0 - Security Fixes & Telemetry Program

Hotfix 9.0.0 - Security Fixes & Telemetry Program

book

Article ID: KB0137764

calendar_today

Updated On:

Products Versions
TIBCO JasperReports Server 9.0.0

Description

Hotfix 9.0.0 for JasperReports Server is available. 

The hotfix file name is hotfix_JRSPro9.0.0_cumulative_20250612_1459.zip. You can download it from our Customer Portal using this link.

This latest launch features key security updates including fixes to Spring, Spring Security, commons-compress, and Netty libraries as well as stability improvements through bug fixes, plus the initial implementation of a telemetry program for better product insights. 

Delivered as a hotfix to minimize disruption and ensure quick adoption of these enhancements, all eligible users are strongly encouraged to apply it. 

If you have any questions please reach out to us via our Customer Portal.

 

JasperReports Server Telemetry Program: FAQs

This document provides quick answers to common questions about our new JasperReports Server Telemetry Program. Please note, this article serves as an announcement. For the most recent and complete details, always refer to the official documentation on the Cloud Software Group website and within our product documentation:  https://community.jaspersoft.com/documentation/

  1. What is the JasperReports Server Telemetry Program?

The JasperReports Server Telemetry Program is designed to collect technical data about how JasperReports Server operates in your environment and how it's being used. This helps us understand product performance, common deployment environments, and usage patterns, ultimately leading to a better product and ensuring license compliance.

With this change, Cloud Software Group is aligning the reporting of license telemetry data for on-prem products with the standard reporting provided in cloud services where the data is automatically collected and enforced as a part of service delivery.

For customers who cannot report licenses automatically due to being in isolated network environments, a process is available for the customer to manually collect and upload the license telemetry data upon renewal.

  1. What is the purpose of collecting telemetry data?

We collect telemetry data for several key purposes:

  • License Compliance: To verify adherence to your JasperReports Server license agreements.
  • Product Improvement: To understand how our product is used, identify areas for enhancement, and develop new features.
  • Performance Optimization: To analyze performance in various deployment environments and address hardware-related issues.
  • Security: To improve product and data security, contributing to broader security program improvements.
  • Support: To better understand customer environments for troubleshooting and support.
  1. What specific data is collected through the Telemetry Program?

The Telemetry Program collects technical system information and application usage metrics. This data is related to your JasperReports Server installation and its operating environment. It primarily includes:

  • License Information: Such as your License ID and Installation UUID.
  • Connected Database Information: Including the type of database used with JasperReports Server.
  • Technical System Details: Operating system type and version, CPU model and unique identifier (ProcessorID), number of CPU cores, memory details, and disk information.
  • Application Usage Data: This includes anonymous counts of users, reports run, scheduled jobs, and various product configuration settings.
  1. How do we address privacy requirements & compliance? 

License telemetry data reporting is very limited in nature, and only involves the collection of the telemetry data necessary for our legitimate business interests, including license compliance. This process has been designed to conform to the requirements of the European Union General Data Protection Regulation as well as other applicable global data protection laws.  Customers may review more information about license telemetry reporting, including the specific data elements collected for this purpose, in the product documentation.  Customers seeking an exception to these reporting requirements based on unique business needs will be able to apply for an exception.

  1. Who has access to my telemetry data within Jaspersoft?

Access to telemetry data within Jaspersoft is strictly controlled. Only authorized personnel, typically from our Engineering, Product Management, and License Compliance teams, who have a legitimate business need related to the purposes outlined above, can access this data. We use role-based access controls and log all data access to ensure accountability.

  1. How long is telemetry data retained?

We retain personal data collected through our Telemetry Program for the duration of our active customer relationship. This means we will keep your data for as long as you have an active Jaspersoft license or account with us. We may keep data for a limited time beyond that if there's a legitimate business need (e.g., internal analytics, legal rights protection) or to meet legal requirements (e.g., compliance, dispute resolution).

  1. How is telemetry data disposed of or returned?

Once the retention period ends, or if the data is no longer needed, we securely dispose of it. This includes permanently deleting or anonymizing the data to prevent unauthorized access. Our third-party subprocessors follow similar secure disposal practices.

Issue/Introduction

Hotfix 9.0.0 - Security Fixes & Telemetry Program.