This section outlines issues tracked and fixed by the MOVEit product team for the 2022.0.8 service pack (September 2023).

ID

Category

Fixed Issue

70103 Security/SSH Improved handling of long usernames when writing log entries.
70252 Security/Server Applied best practice for loading libraries.
71353 Server/Utilities Sysadmin password reset utility not supported.
70732 Server Handle transactions to block unwanted queries.
70780 Security/Webapp Adjustments to align with best practices when viewing dynamic scan results.
71019 Performance/Security Improvements to upload size using WebUI.
71109 Database/Security SQL injection possible for authorized sysadmin user.
71263 Database/Security Authenticated SQL injection possible through machine interface.
71319 WebUI/Security Added user-permissions checks and handling for multi-org deployments that use the WebUI.
71325 LDAP/Security/WebUI Improvements to handle multi-org permission scope with deployments using LDAP or RADIUS.
71587 Server/Authentication Additional session hardening.
72231 Security/UI Fixed medium vulnerability found in Ad Hoc UI functionality.