Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The Universal Agent for SOA 6.9.0.3 maintenance release provides an update only to the Universal Agent for SOA packages. No other Universal Agent components or packages were updated. 

Change ID

Platforms

Component

Description

B-14737

Linux (Intel only) Windows

UACSRV
UAC
UAI

Update the Apache log4j distributions (used for the bundled Tomcat server) to version 2.17.0.

This update was done to resolve the log4j 2.x vulnerabilities reported by: 

 

Update the Apache log4j distribution used by the UAI component from 1.2.15 to 1.2.17. No vulnerabilities were reported for the 1.x versions of log4j, but the maintenance release provided a good opportunity to delivery this update. 

Note
titleNote

A bundled Apache Axis2 distribution still includes log4j 1.2.15. An update to this Axis2 distribution was not done for this release, due to the urgency of addressing the CVEs above. An Axis2 update may be provided in a future release.