OPS/MVS 14.0 MTCA Upgrade Spring Framework from 5.3.33 to 5.3.34 -Vulnerability CVE-2024-22262
search cancel

OPS/MVS 14.0 MTCA Upgrade Spring Framework from 5.3.33 to 5.3.34 -Vulnerability CVE-2024-22262

book

Article ID: 368836

calendar_today

Updated On:

Products

OPS/MVS Event Management & Automation

Issue/Introduction

Getting the following notification from the Broadcom side.

OPS/MVS 14.0 - MTCA Upgrade Spring Framework from 5.3.33 to 5.3.34 -Vulnerability CVE-2024-22262

Cause

MTCA Upgrade Spring Framework

Resolution

We recommend to apply PTF LU13411 as it provides an upgraded version of the Spring Framework third party library that MTC-A uses to provide access to OPS/MVS data from the MTC-A web user interface. The Open Source community identified a security vulnerability in this Spring Framework component (CVE-2024-22262), and the Spring team provided an updated library version (5.3.34) that negates the identified vulnerability. LU13411 includes this newer version of the Spring Framework to ensure that customers are protected from this particular security vulnerability.