Skip to main content
Question

IFS10 MWS patches

  • May 19, 2026
  • 2 replies
  • 21 views

NovJohanL
Do Gooder (Partner)
Forum|alt.badge.img+3

Hi!

I have a customer where we recently installed the IFS Solution ID 312399 which is supposed to contain security patches for IFS10 middleware.

Now when they run their security scanning software, it still finds old versions of log4j.jar and commons-text-1.1.jar that is know to have vulnerabilities. 

Aren’t these supposed to have been replaced withIFS Solution ID 312399?

2 replies

ashen_malaka_ranasinghe
Hero (Employee)
Forum|alt.badge.img+14

Hi ​@NovJohanL 

The solution ID 312399 is for Oracle Critical Patch Updates for Middle Tier - 2025 October

More details on this can be found from: Oracle Critical Patch Update Advisory - October 2025

Following are the files that have changed from this solution ID.

  • mws.jar.001
  • mws.jar.002
  • mws.jar.003
  • mws.jar.004
  • mws.jar.005
  • mws.jar.006
  • mws.jar.007
  • mws.jar.008
  • mws.jar.009
  • mws.jar.010
  • mws.jar.011
  • mws.jar.012
  • mws.jar.013
  • mws.jar.014
  • mws.jar.015
  • mws.jar.016
  • mws.jar.017
  • mws.jar.018
  • mws.jar.019
  • mws.jar.020
  • mws.jar.021
  • mws.jar.022
  • mws.jar.023
  • mws.jar.024
  • mws.jar.025
  • mws.jar.026
  • mws-java.tar.gz

Therefore, log4j.jar and commons-text-1.1.jar files are not changed from this.

Also, can you mention the vulnerabilities identified from those files (log4j.jar and commons-text-1.1.jar)?


NovJohanL
Do Gooder (Partner)
Forum|alt.badge.img+3
  • Author
  • Do Gooder (Partner)
  • May 20, 2026

Thanks for replying Ashen!
Yes, common-text-1.1.jar is also there.
There is an older patch (don’t remember the ID now) specifically for handling log4j, can this be installed above  IFS Solution ID 312399?
What would be the best way to be up to date with MWS security patches?

 

Regards

Johan

 


ashen_malaka_ranasinghe
Hero (Employee)
Forum|alt.badge.img+14

Thanks for replying Ashen!
Yes, common-text-1.1.jar is also there.
There is an older patch (don’t remember the ID now) specifically for handling log4j, can this be installed above  IFS Solution ID 312399?
What would be the best way to be up to date with MWS security patches?

 

Regards

Johan

 

The solution ID 311165 (Binary patch 10.26.28.0 delivered) is related with WebLogic (Log4j) security vulnerability for post go live of UPD21 in Apps 10.

This Binary patch 10.26.28.0 is the latest one delivered at the moment.

The latest UPD contains the latest MWS security patches.