SOLA Release  6.5.14.17  |  6.6.9.67  |  6.7.3.17   PTF SFX6188 and SRS6010

Compatibility Notice - Version Matrix
Requirement Category Version 6.5.14 Version 6.6.9 Version 6.7.3
Core Java & Servlet Specifications
Java Standard Edition (SE) Java SE v1.8 Java SE v17 Java SE v17+
Java Enterprise Edition (EE) Jakarta EE v8 Jakarta EE v10 Jakarta EE v10
Servlet Specifications Servlet v4.0 Servlet v6.0 Servlet v6.0
JSP Specifications JSP v2.3.3 JSP v3.1.1 JSP v3.1.1
Supported Application Servers / Containers
Tomcat Servlet Container v9.0 v10.1 v10.1+
Jetty Servlet Container v10.0 v11.0 v11.0+
WebSphere Application Server Liberty v20.0 v21.0 v21.0+
WebLogic Application Server v14.1 v14.1 v14.1+
JBoss WildFly Application Server v17.0 v17.0 v17.0+
Security Updates
Category Description Status
Vulnerability Upgrades
CVE-2021-23926 (Apache XMLBeans): An XXE flaw in XMLBeans before 3.0.0. The XML parsers weren't configured to block external entities or entity expansion, so crafted XML could read local files, trigger SSRF, or cause a denial of service. Upgrading to 3.0.0 or later fixes it. ✅ Resolved
CVE-2022-34169 (Apache Xalan-J): An integer truncation bug in the XSLTC compiler in Xalan-J 2.7.2 and earlier. A malicious XSLT stylesheet can produce corrupted Java class files, which can lead to arbitrary code execution. This mainly matters if you process untrusted stylesheets. It's fixed in Xalan-J 2.7.3, and the JDK's bundled internal copy of XSLTC was patched separately in the July 2022 Java updates. ✅ Resolved
CVE-2013-4002 (Apache Xerces2-J): A denial-of-service bug in Xerces-J's XMLScanner, affecting 2.11.0 and earlier. Malformed XML with crafted attribute name/value sequences can make parsing consume excessive CPU. It's fixed in Xerces 2.12.0. Older JDKs that bundled the same code were also affected. ✅ Resolved
CVE-2025-14813 (Bouncy Castle bcprov): The GOST CTR implementation (G3413CTRBlockCipher) can't process more than 255 blocks correctly. In practice, GOST 28147 CTR mode reuses keystream after 255 blocks, which undermines confidentiality. It affects BC-JAVA from 1.59 before 1.80.2, from 1.81 before 1.81.1, and from 1.82 before 1.84. Scanners rate it critical, but it only matters if your code actually uses GOST in CTR mode. ✅ Resolved
CVE-2026-50645 (Apache CXF): CXF doesn't limit how many attachment headers a message can contain during deserialization, which allows uncontrolled resource consumption or denial of service. The fix added a default maximum of 500 attachments per message in CXF 4.1.7 and 4.2.2. That fix turned out to be incomplete. The follow-up, CVE-2026-64958, notes the DoS is still possible, and recommends upgrading to 4.2.3, 4.1.8, or 3.6.12. So target those versions rather than the original fix releases. IBM WebSphere and Liberty are also affected via their bundled CXF. ✅ Resolved
CVE-2026-54512 (jackson-databind): A bypass of Jackson's PolymorphicTypeValidator allow-list, done by embedding denied classes as generic type parameters of permitted container types. For example, the attacker smuggles a gadget class inside an allowed ArrayList<...>. If a class with exploitable side effects is on the classpath, this can lead to unauthenticated remote code execution. Applications that accept untrusted JSON and rely on a configured PTV are the ones affected. It's rated high, CVSS 8.1. Affected versions run from 2.10.0 through 2.18.7, 2.21.3, and 3.1.3, with fixes in 2.18.8, 2.21.4, and 3.1.4. If polymorphic typing isn't enabled, you're not exposed. ✅ Resolved
CVE-2020-13956 (Apache HttpClient): HttpClient before 4.5.13 (and 5.x before 5.0.3) could misinterpret a malformed authority component in a request URI and send the request to the wrong target host. It's moderate severity and fixed in 4.5.13 and 5.0.3. ✅ Resolved