In the MVE SMP UI, the user had to click on the Execute Action button to validate the action. When running MVE in Metasys ADX, if the MVE user attempted to execute an action when the MVE ADX user was enabled, the action would be validated against a blank password.

This issue was resolved in MVE 12.2. The MVE SMP UI now requires the MVE user to click on the Execute Action button in order for the action to be validated.

Workaround: If a MVE user attempts to execute an action when the MVE ADX user is enabled, the action will be validated against a blank password.

CVE-2022-22040

In the MVE ADX UI, when the user logged in to Metasys ADX with a different username, the menu was not displayed.

This issue was resolved in MVE 12.2. If a user logs in to Metasys ADX with a different username, now the menu is displayed as expected.

MVE 12.1

.0.1 Resolved
In the MVE SMP UI, the user had to click on the Execute Action button to validate the action. When running MVE in Metasys ADX, if the MVE user attempted to execute an action when the MVE ADX user was enabled, the action would be validated against a blank password.
This issue was resolved in MVE 12.2. The MVE SMP UI now requires the MVE user to click on the Execute Action button in order for the action to be validated.

CVE-2021-21933

When the MVE execution engine is restarted, the MVE UI does not send a request to service.

This issue was resolved in MVE 12.2. The MVE execution engine now sends a request to service when it restarts.

Platforms

Microsoft Windows Metasys
Microsoft Windows Metasys (MVE) is a software product that provides users with a content-enrichment system. MVE is highly configurable and can be set up to support multiple distribution channels and e-commerce solutions. Features such as content filtering, URL redirection, dynamic web site publishing, and item-level tagging make it easy to deploy and manage. In addition to the MVE software, you need Microsoft Windows Server 2016 Standard Edition operating system in order for MVE to function properly.

Timeline

Published on: 10/07/2022 18:15:00 UTC
Last modified on: 10/13/2022 13:09:00 UTC

References