Re: [Axis2] v1.8.2 needed update for CVEs against Jettison 1.5.0 and Spring Framework 5.3.21

2023-09-29 Thread Steven Saunders
Hi Axis2 Dev Mailing List, I'm needing to remediate the use of xalan v2.7.2 embedded version of Apache BCEL to a newer version 6.6.0 or newer due to CVE-2022-42920 (CVSS v3.1 score in NVD is *9.8*). I verified my current build of axis2 1.8.2 builds fine and then updated the axis2 1.8.2 pom.xml fr

Re: [Axis2] v1.8.2 needed update for CVEs against Jettison 1.5.0 and Spring Framework 5.3.21

2023-09-29 Thread Steven Saunders
The exception is below. Do I need other apache classes to go with xalan 2.7.3? Build environment: Maven: v3.6.3 Maven home: /usr/share/maven Java version: 11.0.20.1, vendor: Ubuntu, runtime: /usr/lib/jvm/java-11-openjdk-amd64 Default locale: en_US, platform encoding: UTF-8 OS name: "linux", vers