RASP Java Agent Release Notes (25.8.0)
Overview
Incremental improvement of release 25.7.0.
New Features / Improvements
- W4J-2129 enable Relay for Portal SaaS
- W4J-2146 whitelisting for Path Traversal security rule
- W4J-2150 improvement in Path Traversal protection for Windows
- W4J-2165 SQLi security event metadata extended with the URL of the database
- W4J-2172, W4J-2173, W4J-2184
permit-databasesproperty in ARMR SQLi rule - W4J-2211 Reflect Rule - protection against reflection injection
Bug Fixes
- W4J-1545 failure to load security policy if last line of an armr file is a comment
- W4J-1546 Path Traversal fails on a few Java and OS configurations when payload results in normalisation
- W4J-1767 CSRF Same Origin triggers if request is passed through multiple proxies
- W4J-2138 processing of HTTP requests without a method attribute can lead to false positives
- ES-2307, W4J-2210 ClassNotFoundException when running with AppDynamics
- W4J-2214 compatibility fix for JRuby 9.0.1.0 on JDK 11
Known Issues
- W4J-252 Additional filesystem read events are generated for certain Application and JDK folders the first time an ARMR
filesystemrule that contains theapi()directive triggers - W4J-435 ARMR Socket input specifier not working on some Java6 JDK
- W4J-1431 ARMR HTTP CSRF rule is not working correctly on a JSP page on Tomcat 10, 11 and JBossEAP8
- W4J-1432 ARMR HTTP XSS rule is not working correctly on JBoss EAP 8 and Wildfly 32
- W4J-1477 ARMR Patch for CVE-2016-5552 disables input() specifier on DNS/Socket rules on Windows
Third Party / Open Source Dependencies
- ANTLR
- Log4j (version1) Library
- ASM Library
- OpenJDK JDK Source
- JASYPT