 
					
				
		
04-04-2022 10:27 AM
Is Hyland able to provide any information on whether ACS, APS or any related product are impacted by the "Spring4Shell" Spring Framework RCE vulnerability?
Announcement from Spring : https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement 
Many thanks in advance for your feedback
Regards !
04-04-2022 10:34 AM
Hi, Mickael.
We're still evaluating detailed impact of this vulnerability.
Attacked libraries and versions are used in some of our products, however this is not the only condition to met.
We sill provide an official communication later this week, but it looks like the impact will be very low or none at all.
Regards
			
    
	
		
		
		10-11-2022
	
		
		03:45 AM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
 - last edited on 
    
	
		
		
		04-11-2025
	
		
		05:56 PM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
 by 
				
		 Tom_Vitale
		
			Tom_Vitale
		
		
		 
		
		
		
		
		
	
			
		
@Atol Support Team:
The official Information can be found here:
Alfresco Process Services (APS) is impacted from  "Spring4Shell"
--> Upgrade to at least APS version 2.3.1
Alfresco Content Services (ACS) is NOT impacted from "Spring4Shell" in its default configuration.
--> I fixed the security issue at the customer by upgrading the Tomcat version and can recommend to do so as well.
See: https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement
More information:
https://tomcat.apache.org/tomcat-10.0-doc/changelog.html#Tomcat_10.0.20_(market) ;
https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.62_(remm) ;
https://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.78_(market)
/content-services/tomcat/bin$ ./version.sh  | grep version04-04-2022 10:34 AM
Hi, Mickael.
We're still evaluating detailed impact of this vulnerability.
Attacked libraries and versions are used in some of our products, however this is not the only condition to met.
We sill provide an official communication later this week, but it looks like the impact will be very low or none at all.
Regards
 
					
				
		
09-28-2022 04:35 AM
Hi Angel,
Do you have any recommendations/updates concerning this issue ?
Best regards,
Marie Magnier.
			
    
	
		
		
		10-11-2022
	
		
		03:45 AM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
 - last edited on 
    
	
		
		
		04-11-2025
	
		
		05:56 PM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
 by 
				
		 Tom_Vitale
		
			Tom_Vitale
		
		
		 
		
		
		
		
		
	
			
		
@Atol Support Team:
The official Information can be found here:
Alfresco Process Services (APS) is impacted from  "Spring4Shell"
--> Upgrade to at least APS version 2.3.1
Alfresco Content Services (ACS) is NOT impacted from "Spring4Shell" in its default configuration.
--> I fixed the security issue at the customer by upgrading the Tomcat version and can recommend to do so as well.
See: https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement
More information:
https://tomcat.apache.org/tomcat-10.0-doc/changelog.html#Tomcat_10.0.20_(market) ;
https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.62_(remm) ;
https://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.78_(market)
/content-services/tomcat/bin$ ./version.sh  | grep version 
					
				
				
			
		
Explore our Alfresco products with the links below. Use labels to filter content by product module.