Nieuws

Security patch for AccurioPro Flux available

Two security vulnerabilities have recently been discovered in AccurioPro Flux. We have released a security patch installer that fixes these vulnerabilities. The latest version of AccurioPro Flux also includes the patch.

The first vulnerability, discovered in a third-party component used by AccurioPro Flux, affects all AccurioPro Flux installations from version 8.4.0 to version 10.2.0 and can allow the execution of remote code. A second discovered vulnerability can allow denial-of-service attacks in the AccurioPro Flux Ultimate online shop in versions 10.0.0 to 10.2.0.

The issues were discovered through internal penetration testing and, to the best of our knowledge, is not being actively exploited or known publicly.

We recommend updating all affected installations immediately to patch these vulnerabilties.

The release of the patch is a precautionary measure. To date there have been no reports of the vulnerabilities in AccurioPro Flux being exploited.

The latest version 10.2.0.77844 of AccurioPro Flux has already fixed these vulnerabilities. In addition, security patches are available for older versions that can be applied even without a valid Software Maintenance Plan (SMP). Please contact your Konica Minolta partner to obtain the patch.

/