This hotfix addresses CVE-2022-42889, an Apache Commons Text vulnerability (Text4Shell) that potentially enables a malicious actor to execute arbitrary code by taking advantage of string interpolation. TIBCO iWay Service Manager does not use the vulnerable areas of commons-text but we provide these instructions to replace it if you so choose.
This hotfix applies to TIBCO iWay Service Manager 8.0.7, iWay Integration Tools 8.0.7, and iWay Integration Tools 8.0.7 HF-001.
================================================================================ Closed Issues in 8.0.7 HF-002
ATE-1769 Instructions to upgrade commons-text to version 1.10.0.
TIBCO iWay® Service Manager 8.0.7 HF-002 is now available.
Environment
Supported Platforms
Resolution
The hotfix can be downloaded from the TIBCO Support Customer Portal Web User Interface (https://support.tibco.com). You will need to provide your TIBCO Support Portal credentials. Once you are logged in, you can download the hotfix files by selecting Downloads -> Hotfixes -> AvailableDownloads/ibi/iWay Service Manager/8.0.7/HF-002.
Please contact TIBCO Support if you have any problems finding or downloading the hotfix.
Attachments
TIBCO iWay® Service Manager 8.0.7 HF-002 is now available
get_app