TIBCO WebFOCUS® Hotfix for the Apache Commons Text (Text4Shell) Vulnerability

TIBCO WebFOCUS® Hotfix for the Apache Commons Text (Text4Shell) Vulnerability

book

Article ID: KB0071872

calendar_today

Updated On:

Products Versions
ibi WebFOCUS 8207.28.13 and 9.0.3

Description

This hotfix addresses Apache Commons Text Vulnerability (Text4Shell) - CVE-2022-42889.

Environment

This hotfix addresses the following Apache Commons Text Vulnerability (Text4Shell) - CVE-2022-42889 - for TIBCO WebFOCUS and WebFOCUS Installer Release 8207.28.13 and 9.0.3.

Resolution

See the articles below for instructions on how to install the hotfix for your version of TIBCO WebFOCUS.  Customers on an earlier release of WebFOCUS, such as 9.0.1 or 8207.28.05, are required to upgrade to 9.0.3 Service Pack or 8207.28.13 Service Pack (respectively) from eDelivery prior to installing the hotfix.

9.0.3:
TIBCO WebFOCUS® 9.0.3 HF-007 is available

8207.28.13:
TIBCO WebFOCUS® 8207.28.13 HF-002 is available

The hotfix for legacy WebFOCUS releases 8206.38 is available on demand by opening a case with TIBCO Support.

Issue/Introduction

TIBCO WebFOCUS® Hotfix for the Apache Commons Text (Text4Shell) Vulnerability

Additional Information

Apache Commons Text
https://www.tibco.com/support/notices/2022/10/apache-commons-text-vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2022-42889
https://access.redhat.com/security/cve/cve-2022-42889