CVE-2025-48989
A vulnerability CVE-2025-48989 has been disclosed, affecting the Tomcat Web Application Server.
A version of Tomcat is included in the INFOMOTION Data Management Center package and used for the containerized and standalone deployment options.
We are now releasing an updated version 2025.1.2 of Data Management Center that includes a patched version of Apache Tomcat.
Please note that this patch only secures containerized or standalone DMC deployments. When deployed within a custom Tomcat installation, that installation should be patched as well.
CVE-2025-41242
A vulnerability CVE-2025-41242 has been disclosed, affecting certain Spring Framework MVC applications in non-compliant servlet environments.
The INFOMOTION Data Management Center (DMC) includes the Spring Framework as part of its package.
We are now releasing an updated version 2025.1.2 of Data Management Center that includes a patched version of Spring Framework.
Please note:
- Deployments of DMC using the embedded Tomcat servlet container are not affected by this vulnerability, since Tomcat properly rejects malicious path sequences.
- Nevertheless, we include the patched Spring Framework in this release to ensure ongoing security and compatibility.
- If DMC is deployed within a custom servlet container, that environment should be checked and updated accordingly.
Dependency Upgrades
- Upgrade Tomcat from
10.1.43 to 10.1.44 to avoid potential issues with CVE-2025-48989.
- Upgrade Spring Boot from
6.2.8 to 6.2.10 to avoid potential issues with CVE-2025-41242
Bugfixes
- Fixed an issue where List-of-Values without a
filterColumn failed with cryptic errors.
- Fixed an issue where the checkmark on the update view is shows the incorrect state.
- Fixed an issue where QS rules were not revalidated when the table changes, which resulted in invalid SQLs.
- Fixed an issue where commands configured with
QA CHECK BEFORE EXECUTION and Abort on error failed with a INTERNAL_SERVER_ERROR if no QA rules were defined.
- Fixed a header configuration error within
table/{tableId}/data/delete.
- Prevented use of SQL keywords in
columnName or title during Create-Table-Process.
- Fixed cryptic errors in the TablePerm workflow.
- Fixed a deserialization error for table permissions during the create process.
- Fixed an issue where the view did not update after importing a Deployment Set.
- Fixed an issue where attempting to rename a column during deployment-import lead to cryptic error message
Improvements
- Enhanced Field descriptions within Input-Data fields.
(since 2025.1.1)
Container Image: infomotiondmc.azurecr.io/dmc@sha256:2393a32c3c7bfa9c93813a3bd932f5eb0315fd283cba46481496c0a2d30b5c61
WAR File : https://dmcwiki.blob.core.windows.net/dmc-releases/2025.1.2/dmc.war (sha256: 9738ab489ed60937bff5216b0311f3aee3d0296b642ecb260f58b00eb23f87f3)