Due to the Spring Framework (Spring4Shell) vulnerability issues, the 2021x Refresh2 HF3 has been released on May 27, 2022. The HF3 addresses the Spring Framework (Spring4Shell) 5.3.0 to 5.3.17, 5.2.0 to 5.2.19 versions.

For more information, see CATIA Magic and No Magic products affected by Spring Framework - Spring4Shell - vulnerability - CVE-2022-22965.

Due to the Apache Log4j vulnerability issues, the 2021x Refresh2 HF2 has been released on March 4, 2022. The HF2 addresses Log4j 1.x and 2.x versions.

For more information, see CATIA Magic and No Magic products affected by Log4j vulnerability - CVE-2021-44228, CVE-2021-45046, CVE-2021-44832.

Also, see the Knowledge Base article at https://kb.dsxclient.3ds.com/mashup-ui/page/resultqai?id=QA00000102301e.

Due to the Apache Log4j vulnerability issues, the 2021x Refresh2 HF1 has been released on December 22, 2021. The HF1 addresses Log4j 2.x versions.

For more information, see CATIA Magic and No Magic products affected by Log4j vulnerability - CVE-2021-44228, CVE-2021-45046, CVE-2021-44832.

Also, see the Knowledge Base article at https://kb.dsxclient.3ds.com/mashup-ui/page/resultqai?id=QA00000102301e.

CATIA Magic products