This Security Syracuse Server release fixes vulnerabilities discovered in Syracuse Server 12.19.0.
The security risk does not affect the previous version of Syracuse. Please replace Syracuse Server 12.19.0 with Syracuse Server 22.214.171.124.
Syracuse Server 126.96.36.199 fixes two specific risks that have been identified:
- Host management for the “Reset password” link: The hostname management for the “Reset password” feature has been reinforced with a hostname allowlist to protect from hostname hijacking. Allowed host names must be specified in the allowlist in Administration > Global Settings for the reset password URLs to be accepted by Sage X3. (Documentation for this feature will be available soon)
- This hotfix also addresses a translation issue with the French language on login.
Following the Sage X3 Security Best Practices reduces security risks. However, we strongly advise you to apply all security patches issued by Sage.
To access this download, visit our Sage Knowledgebase Site HERE, then scroll down to locate the 2023R2 (12.0.34) downloads. Once you select the download link, you will be prompted to login to your Sage Portal Account.