Skip to main content

Version 10.2.9.9

Release date

October 17, 2025

The release enhances the platform's security and stability by addressing critical vulnerabilities in core components. It also introduces improvements to the Generic Connector and includes several fixes that further strengthen overall reliability and performance.

Upgrades

To eliminate known vulnerabilities, the following updates are introduced:

  • Upgraded Spring Framework to v4.3.14.

  • Upgraded Apache Tomcat to v9.0.110.

  • Upgraded Java SE Runtime Environment 8 to v1.8_462.

  • Upgraded Java SE Development Kit 8 to 8u461.

  • Upgraded Java SE Development Kit 17 to v17.0.16.

  • Upgraded Elasticsearch v8.19.4.

  • Upgraded Bouncy Castle to v1.82.

  • Upgraded Netty to v4.1.110.

  • Upgraded Apache CXF to v3.2.1.

  • Upgraded Spring Security to v3.2.10.

  • Upgraded Hazelcast to v5.1.1.

  • Upgraded dom4j to v1.6.1.

  • Upgraded JSON Smart (json-smart-v2) to v2.4.11.

  • Upgraded Apache Commons Text to v1.10.0.

  • Replaced Velocity Template Engine with FreeMarker v2.3.31.

  • Upgraded Rhino JavaScript Engine to v1.7.7.2.

  • Upgraded Apache Struts to v1.3.8.

  • Upgraded Erlang to v26.2.5.14.

  • Upgraded Apache Tomcat Embedded to v9.0.109.

  • Upgraded the log4net dependency to v2.0.17.

Improvements

  • The Trigger REST Server now allows configuring the response content type. A new setting enables users to specify the desired content type for responses, defaulting to application/json.

  • Generic Connector now supports retrieving table-based data as JSON strings from a Business Process configuration, enabling seamless lookup and integration of configuration values stored as data tables.

Corrected issues

  • Resolved the issue where data from one completed Manual Task could incorrectly populate results for another Manual Task.

  • Resolved "Superset Unavailable" errors when accessing reports and improved overall Superset stability and responsiveness under heavy load.

  • Resolved the issue that caused certain tasks to fail during large-scale processing due to user identification errors.

  • Resolved the issue where the REST Server component failed to return JSON data when the response contained non-string values.