Skip to main content
Version: 25.8.0

RASP Java Agent Release Notes (25.8.0)

Overview

Incremental improvement of release 25.7.0.

New Features / Improvements

  • W4J-2129 enable Relay for Portal SaaS
  • W4J-2146 whitelisting for Path Traversal security rule
  • W4J-2150 improvement in Path Traversal protection for Windows
  • W4J-2165 SQLi security event metadata extended with the URL of the database
  • W4J-2172, W4J-2173, W4J-2184 permit-databases property in ARMR SQLi rule
  • W4J-2211 Reflect Rule - protection against reflection injection

Bug Fixes

  • W4J-1545 failure to load security policy if last line of an armr file is a comment
  • W4J-1546 Path Traversal fails on a few Java and OS configurations when payload results in normalisation
  • W4J-1767 CSRF Same Origin triggers if request is passed through multiple proxies
  • W4J-2138 processing of HTTP requests without a method attribute can lead to false positives
  • ES-2307, W4J-2210 ClassNotFoundException when running with AppDynamics
  • W4J-2214 compatibility fix for JRuby 9.0.1.0 on JDK 11

Known Issues

  • W4J-252 Additional filesystem read events are generated for certain Application and JDK folders the first time an ARMR filesystem rule that contains the api() directive triggers
  • W4J-435 ARMR Socket input specifier not working on some Java6 JDK
  • W4J-1431 ARMR HTTP CSRF rule is not working correctly on a JSP page on Tomcat 10, 11 and JBossEAP8
  • W4J-1432 ARMR HTTP XSS rule is not working correctly on JBoss EAP 8 and Wildfly 32
  • W4J-1477 ARMR Patch for CVE-2016-5552 disables input() specifier on DNS/Socket rules on Windows

Third Party / Open Source Dependencies

  • ANTLR
  • Log4j (version1) Library
  • ASM Library
  • OpenJDK JDK Source
  • JASYPT