This hotfix addresses CVE-2022-42889, an Apache Commons Text vulnerability (Test4Shell) that potentially enables a malicious actor to execute arbitrary code by taking advantage of string interpolation.
The hotfix applies to TIBCO Omni-Gen DQ Edition, TIBCO Omni-Gen MDM Edition, and TIBCO Omni-HealthData Edition Release 3.16.0.
================================================================================ Closed Issues in 3.16.0 HF-008
OG-8684 Hotfix to upgrade commons-text to version 1.10.0.
TIBCO Omni-Gen® DQ, TIBCO Omni-Gen® MDM, and TIBCO Omni-HealthData® 3.16.0 HF-008 are now available.
Environment
Supported platforms
Resolution
The hotfix can be downloaded from the TIBCO Support Customer Portal Web User Interface (https://support.tibco.com). You will need to provide your TIBCO Support Portal credentials. Once you are logged in, you can download the hotfix by selecting Downloads -> Hotfixes -> AvailableDownloads -> ibi.