Patch 2026.1.3
PostgreSQL JDBC Driver CVEs
A vulnerability CVE-2026-54291 has been disclosed, affeting the PostgreSQL JDBC driver.
While the PostgreSQL driver is bundled with INFOMOTION Data Management Center, the vulnerability only affects very specific combinations of parameters and makes DMC installations using PostgreSQL potentially vulnerable to man-in-the-middle attackes on the connection to the backend database.
Additionally, two separate vulnerabilities CVE-2026-59083 and CVE-2026-59084 have been disclosed affecting the Tomcat Web Application Server.
A version of Tomcat is included in the INFOMOTION Data Management Center package and used for the containerized and standalone deployment options.
- CVE-2026-59084 is based on insufficient technical documentation of the EncryptInterceptor. However, this interceptor is not used inside DMC in the default configuration or any customer configuration known to us. Therefore, to the best of our knowledge, we do not expect DMC to be affted by this vulnerability.
- CVE-2026-59083 is based on incorrect decoding of input data in Tomcat's
RewriteValvecomponent. As far as we can ascertain, this component is inactive in both containerized and standalone deployments of DMC and it is therefore not affected by this issue.
Nonetheless, we are now releasing an updated version 2026.1.3 of Data Management Center that includes a patched version of the PostgreSQL JDBC driver and of Apache Tomcat.
Please note that the patch only secures Tomcat in containerized or standalone DMC deployments. When deployed within a custom Tomcat installation, that installation should be patched as well.
Bugfixes
- Resolve PostgreSQL type-inference error on DATE/NUMBER PK update
(since 2026.1.2)
Container Image: infomotiondmc.azurecr.io/dmc@sha256:0a67951c96aa54e039db2a6bc3eafb648642a1363111ceb0ad97da1ca992c08a
WAR File : https://dmcwiki.blob.core.windows.net/dmc-releases/2026.1.3/dmc.war (sha256: 754a812f1f8c12efde032749d7da2cf151e1f5c65083be2a081f6bc19ef753d4)