Previous Topic

Next Topic

Book Contents

Book Index

Issues Fixed in This Release

The following issues were fixed in MOVEit Automation 2018.

ID

Category

Fixed Issue Description

MICEN-5040

Web Admin

The Retrieve key from button in the Add SFTP Host dialog was fixed. It retrieves the KEX algorithm order and Proxy settings required to connect properly.

MICEN-6088

Database, Security

To conform with security best practices, the MOVEit Automation MySQL configuration is set to local_infile OFF.

MICEN-6090

Database, Security

To conform with security best practices, the MOVEit Automation MySQL configuration is set to secure_file_priv NULL.

MICEN-6098

Web Admin

Web Admin no longer makes unavailable options visible to limited users.

MICEN-6171

API

In previous releases, MOVEit Automation did not run the task and returned a confusing error message if the user specified an invalid task parameter name, such as using the command-line API utility with the -p parameter. For example, micentralclt -startid:123456789 -p:42=42

MICEN-4301

Web Admin, Security

In previous releases, the task run history feature in Web Admin could produce incorrect SQL statements based on the user's filter.

MICEN-4614

Web Admin

The PGP signing length is now available on the Web Admin UI.

MICEN-5386

Hosts, Web Admin

The SSH host test in Web Admin did not validate the SSH host key in previous releases. This issue is fixed.

MICEN-5706

VB Admin

The number of VB Admin connections was increased from 20 to 100.

MICEN-4761

Web Admin

The Edit Transfer Exceptions option was removed from the Actions Menu of Sync tasks as it does not apply to Sync Tasks.

MICEN-5947

Web Admin

The stack overflow exception that was encountered if two tasks that reference each other attempted to build the task dependency collection, when a restricted user accessed Web Admin, was fixed.

MICEN-5675

Hosts

Public keys, on non-Western symbols are not corrupted during the import process.

MICEN-5853

Installer

In rare cases in previous releases, the MOVEit Automation installer failed with the error "Failed to load DLL: PWInst".

MICEN-6067

Web Admin

In previous releases, certain error conditions involving invalid configuration files caused MOVEit Automation Web Admin to return a blank screen rather than an error message.

MICEN-5037

Core

Sync task inconsistencies encountered when the current local time falls between 1:00 AM and 2:00 AM at the end of DST are fixed.

MICEN-5622

Web Admin

The Web Admin configuration export includes the PGP keys section.

MICEN-5661

Scripts

MOVEit Automation 2018 runs in a working directory outside of the "Program Files" to ensure that certain delete scripts do not delete content from the working directory of the process that called the script.

MICEN-6087

Web Admin, Security

Authorization is required to access Tomcat/Spring endpoints other than /access and /logout.

MiCEN-5438

Scripts, Server

Unicode characters can be utilized in the backup files.

MICEN-6070

Security

The SQL query was modified to prevent an SQL injection vulnerability in the Admin Console.

MICEN-5057

Install-server

The installer does not offer an option to upload the installation logs to a support site if an installation fails.

362932

Security

CVE-2020-12677. Fixed an application endpoint that failed to adequately sanitize malicious input which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser. Upgrade to 2018.0.3 is recommended.

Version affected: 2018.0

Version fixed: 2018.0.3

Credit: Bridgewater Security Team