The following issues were fixed in MOVEit Automation 2025.1.

ID

Category

Fixed Issue

65674

Logs

A clear error message is now logged to the MOVEitC.log file when it is unable to write to the task log due to insufficient disk space.

83499

Scripts, Server

Failures which occur in the Zip Advanced script are correctly identified and reported.

87087

SharePoint

MOVEit Automation now logs the entire error message returned by SharePoint Hosts.

91119

Tasks

Cloning a source or destination step in an Advanced Task now correctly retains any overridden host credentials.

91175

Web Admin

Non-admin users now cannot view the Date Lists or Keys and Certs pages with a direct URL, as expected.

91247

FTP Host

Resolved an issue where the Set Cert button remained enabled even when the Override Default Client Certificate check box was cleared in Host Override settings.

91594

Hosts

The Resume Partial Transfers warning message was visually improved in the Edit Source view.

91611

Server

Resolved a memory leak in the license library.

91617

Logs, SFTP

Reduced the amount of SFTP log entries at the lower logging levels.

91653

REST API, Web Admin

The token refresh behavior was fixed to prevent invalidation after refreshing.

91669

Security

The OpenSSL version was updated to address potential vulnerabilities, including authentication problems with Raw Public Keys (RPKs).

91776, 91837

Hosts

The retry count is now respected for all hosts.

92066

Security

Prevented a potential Denial of Service (DoS) vulnerability in Web Admin by enforcing timeouts on unauthenticated TCP connections

92126

Java API

The correct jar name is returned when running MICentralAPIJavaClient.jar.

92161

Web Admin

Fixed incorrect file size reporting during folder browse operations for large files on OpenSSH/SFTP hosts.

92429

Web Admin, Server

Domain users with the User must log on using a smart card flag on their account can now log on to MOVEit Automation if the UseNT4LoginProvider registry key is set to TRUE.

92739, 94757

Security

The Spring Framework version was upgraded to address potential vulnerabilities, including a reflected file download (RFD) vulnerability.

93382

Security, Web Admin

Session timeout functions correctly on all pages.

93737

Security, Web Admin

Removed sensitive user IP data from JWT payloads.

93743

Security

Web Admin does not use cookies. However, the SameSite cookie attribute is explicitly set to Strict in the Tomcat configuration to prevent the issue being raised erroneously in security scans.

95153

Lockouts

The timestamp is displayed on the Manage Lockouts page.

97355

Web Admin

Resolved an issue where a Web Admin session expired unexpectedly when open in multiple browser tabs.