SR-C71673 · Issue 410561
XXE security improvements
Resolved in Pega Version 8.2
Several updates have been made to improve security against External Entity Injection, including to the following areas: ProcessXSLT, performXSLT, DCOdocumentToBytes, DCOgetStringFromDocument, getTaskStatusXML, pzPMMLTransform, getTaskStatusXML, and validateAgainstXSD.
SR-C72570 · Issue 413020
XXE security improvements
Resolved in Pega Version 8.2
Several updates have been made to improve security against External Entity Injection, including to the following areas: ProcessXSLT, performXSLT, DCOdocumentToBytes, DCOgetStringFromDocument, getTaskStatusXML, pzPMMLTransform, getTaskStatusXML, and validateAgainstXSD.
SR-C68713 · Issue 407255
Moment udated to latest version
Resolved in Pega Version 8.2
Moment.js has been updated to version 2.22.2 .
SR-C71432 · Issue 410184
Moment udated to latest version
Resolved in Pega Version 8.2
Moment.js has been updated to version 2.22.2 .
SR-C66627 · Issue 406212
Placeholder text localized for approval rejection
Resolved in Pega Version 8.2
Localization has been added to the placeholder text of the approval reject step.
SR-C56534 · Issue 399504
Struts updated to v 2.5.16
Resolved in Pega Version 8.2
To address the latest Struts vulnerability, Universal SMA has been updated to Struts version 2.5.16.
SR-C22990 · Issue 364504
Struts updated to v 2.5.16
Resolved in Pega Version 8.2
To address the latest Struts vulnerability, Universal SMA has been updated to Struts version 2.5.16.
SR-C56484 · Issue 394360
Struts updated to v 2.5.16
Resolved in Pega Version 8.2
To address the latest Struts vulnerability, Universal SMA has been updated to Struts version 2.5.16.
SR-C60191 · Issue 400126
Acecss Group encoding updated for compatibility with the latest versiosn of Tomcat
Resolved in Pega Version 8.2
After upgrading to Tomcat 7.0.88, there were intermittent login issues. This was due to the access group hashcode having "[[" appended in the URL, which the latest version of Tomcat does not accept. To resolve this, updates have been made to URLComponentProcessor where the encoding of the access group is done.
SR-C54443 · Issue 396520
Acecss Group encoding updated for compatibility with the latest versiosn of Tomcat
Resolved in Pega Version 8.2
After upgrading to Tomcat 7.0.88, there were intermittent login issues. This was due to the access group hashcode having "[[" appended in the URL, which the latest version of Tomcat does not accept. To resolve this, updates have been made to URLComponentProcessor where the encoding of the access group is done.