X4 Help Center

Release Notes 7.4.19

Bug Fixes

The following issues have been resolved in Release 7.4.19.

X4 Server

Key

Summary

X4BPMS-493

X4 Update Tool: Running the Update Tool in pure simulation mode caused a crash, which under certain circumstances could lead to the unintended deletion of the existing X4 Server installation directory. This issue has been resolved: the simulation now runs stably, and the rollback mechanism exclusively cleans up its own temporary data.

X4BPMS-479

Linux Environments / Shell Operation: When running the X4 Server directly via the command line (shell) under SUSE Linux, X4 Apps could not be built successfully. This behavior has been corrected.

X4BPMS-477

Linux Installer: System-side dependencies were missing from the Linux installation packages, which could cause errors during clean installations or upgrades. The missing components have been added to the installer.

X4BPMS-415

Migration Tool Update: The Migration Tool has been extended with the new --force-full-update parameter. This allows forcing a full server update—including data migration and configuration transfer—if required, even if a minor patch update would otherwise suffice.

Sicherheitsaktualisierungen (Behobene CVEs)

To enhance system security and compliance, numerous integrated third-party libraries have been updated in this version. This addresses and mitigates the following known security vulnerabilities (CVEs), among others:

  • Critical Vulnerabilities & System Core:

    • CVE-2026-27446: ActiveMQ Artemis Message Server

    • CVE-2025-12543: Undertow Web Server Core

    • CVE-2021-41411: Drools / KIE Workflow Engine

    • CVE-2023-40743: Deprecated Axis Framework completely removed; affected adapters have been moved to an optional legacy package.

  • XML & Graphics Handling Security:

    • CVE-2021-40690: Apache Santuario / XML Security

    • CVE-2020-11988: XMLGraphics Commons

    • CVE-2020-11979: Apache Ant Build Component

    • CVE-2015-0226: Apache WSS4J / Web Service Security

  • Data Processing & Transport Security:

    • CVE-2023-34455, CVE-2023-43642: Snappy Java Compression Library

    • CVE-2021-22569: Google Protobuf & Cloud Storage Integration

    • CVE-2021-37714: jsoup HTML Parser

In addition, the bundled base runtime environments have been updated to minimize general security risks and ensure long-term support:

  • Updated the integrated Java Development Kit (JDK 17) to the latest security patch level.

  • Updated the bundled Apache Maven environment.

  • Consolidated and cleaned up various helper libraries (including Jackson JSON Parser, Google Guava, Apache POI, Apache Commons, and Keycloak connection components).