A security hotfix has been released for FlexNet Manager Suite (FNMS) version 2022 R2 and is available in the Product License Center (PLC).
Name: 2022 R2 On-Premise Hotfix 3
This hotfix contains updated binaries which are to be installed on the FNMS Presentation Server (or application server if using a single-server deployment). To install the hotfix please follow instructions in the ReadMe.txt of the download package.
This hotfix resolves the following security-related issues:
- IOK-1069556 - SQL Injection (Reports > License Compliance > IBM PVU License Consumption)
- IOK-1072870 - CSV Injection (Reports > License Compliance > IBM PVU License Consumption)
- IOK-1073091 - CSV Injection (Discovery & Inventory > Oracle Instances)