The following issues were fixed in MOVEit Automation 2024

ID

Category

Fixed Issue

68146

Groups, Permissions

A task or host that is part of a view-only permissions group cannot be cloned by a target group member with edit permissions.

68404

FTP, Tasks

When uploading files to an FTP host the Overwrite option is respected when the Retry Count is active.

74707

Scheduler

Tasks with the Log failure if no files found option enabled are successful where at least one file is downloaded if there are multiple sources.

74763

Admin Console, Permissions

Windows Domain Groups associated with an Automation Resource Group are accessible in Admin Console.

76141

Install

Install logs do not expose database credentials.

76197

Amazon S3 Host, Permissions

Amazon S3 hosts can connect to public buckets without additional permissions.

76695

Permission

Temporary files are deleted from the MOVEitCache when unzipping .tar files.

75558

Admin Console

Admin Console log on time was improved to prevent timeouts.

75559

Server, Task Logs

Unnecessary state file debug log messages eliminated.

75661

Tomcat

To prevent a vulnerability, the HTTP OPTIONS method in Tomcat was disabled.

75802

Google Cloud Storage Host

Rescan option function as expected on Google Cloud Storage hosts.

76019

SFTP, Debug Log

The logging for an SFTP host as a destination was improved.

77104

Web Admin

The Batik-css version was updated to address CVE-2022-44729.

The Neko-htmlunit version was updated to address CVE-2023-49093.

77730

Tasks

The file mask buffer was increased to accommodate FileMasks longer than 2048 characters.

74866

Tamper check

The Tamper Check script completes the first time it is run on a new MOVEit Automation installation

8986

API

API method updateAttribute works as expected with all associated nodes.

75189

Configuration Utility

The configuration utility allows certificate selection without error.

76415

PGP

The minimum signing algorithm for PGP keys is SHA256. The unused SHA1 option was removed.

75089

SFTP

The Resume partial transfers (if possible) option functions as expected. If the connection is disrupted during transfer, MOVEit Automation resumes the partial transfer.

77250

Server, User authentication

Local user log on is successful when NTLM is disabled on the MOVEit Automation server.

78731, 78150

Web Admin

The Spring Web version was updated to address CVE-2024-22259 and CVE-2016-1000027.

65672

Installer

A license type check and error message were added to improve error handling.

76303

Install

Improved debug logs identify specific tables that cause install failure.

76304

Install

Improved error messages identify specific tables that cause install failure.

74724

MICMyToMS

Migrating a MySQL database to MSSQL using the MICMyToMS tool successfully copies all expected logs and tables.

73091

Server, Unicode

Parameter values with Nordic characters are not corrupted.

77542

SFTP

The IPWorks SFTP library was updated to address an unresponsive SFTP host test or browse with a Redox Engine SFTP Server.

78701

Security

The spring-security-core version was updated to address CVE-2024-22257.

80672

Database

The Microsoft OLE DB Driver was updated to address CVE-2024-28915.

81230

Database

The MySQL DB Driver was updated to 8.0.37, the ODBC Connector was updated to 8.4.0, and the ADO.NET Driver for MySQL (Connector/NET) was updated to 8.4.0.

77059, 78194, 78097

SFTP

Updates to the SFTP host ensure that the correct timestamp is utilized in certain end-of-year and leap year cases.

76945, 76773, 76944

Server

The Progress MOVEit Automation configuration export function prior to 2024.0.0 uses a cryptographic method with insufficient bit length, CVE-2024-4563.