11.8.2609 Patch Release Notes
he patch release includes all the previous patches of versions.
Table: Enhancements
Issue Number | Description |
|---|---|
SC-73890 |
The SLP Job Details probe now collects historical incomplete Storage Lifecycle Policy (SLP) jobs during scheduled collection. IT Analytics refreshes images and copies that remain incomplete after they age past the standard SLP lookback window. Two new advanced parameters control this behavior: NBU_ENABLE_HISTORICAL_INCOMPLETE_SLP_JOB_COLLECTION and NBU_HISTORICAL_INCOMPLETE_SLP_JOB_COLLECTION_INTERVAL_DAYS. For more information, see Backup Manager advanced parameters. |
SC-78618 |
Added support for the Client Attributes probe (requires NetBackup 10.0+) to the Veritas NetBackup data collector policy configuration in the Portal UI. A new Client Attributes row is now available in the policy dialog, allowing operators to enable or disable the probe and configure its collection schedule alongside existing probes. The probe is disabled by default for both new and existing policies and can also be run on demand from the dialog without affecting the saved schedule. |
SC-78628 |
The PostgreSQL JDBC driver used by IT Analytics has been upgraded from version 42.7.2 to 42.7.13 to address CVE-2026-42198 (CVSS 7.5). This vulnerability was exploitable in IT Analytics only if you use the Avamar collector and it connects to an Avamar target system that has a malicious, compromised, or attacker-controlled Avamar PostgreSQL database endpoint. |
SC-78722 |
Upgraded the log4net logging library used by the WMI Proxy Server component of the Windows Data Collector from 2.0.15 to 3.3.1 to address a vulnerability identified in a recent security scan. This is a logging library update only, with no configuration or functional changes to WMI-based collection. |
SC-78724 |
Upgraded the Logback logging library (logback-classic, logback-core, and logback-access-common) to address vulnerabilities identified in a recent security scan. This is a version-only update with no changes to application logging behavior or configuration. |
SC-78839 |
Upgraded the Spring HATEOAS library to version 2.5.3 across IT Analytics to address CVE-2026-41007, a vulnerability that could be exploited by an authenticated caller sending crafted JSON:API request bodies to REST endpoints that deserialize into EntityModel. |
SC-79031 |
Upgraded the Apache HTTP Server used by IT Analytics from 2.4.67 to 2.4.68 to address vulnerabilities identified in a recent security scan, along with updated SafeLogic libraries. No configuration changes are required and existing web services continue to function as before. |
SC-79047 |
Upgraded the embedded Apache Tomcat server (and tomcat-embed-core) used by IT Analytics to version 10.1.57 to address security vulnerabilities identified in a recent scan. This upgrade requires no configuration changes and all existing web services continue to function as before. |
SC-79127 |
Upgraded the Amazon Corretto JDK used by IT Analytics (on-premises) to version 17.0.20.8.1 to keep the platform current with the latest OpenJDK security and stability updates. No functional changes or regressions are expected as a result of this upgrade. |
SC-79351 |
The HP 3PAR / HPE Alletra Storage MP B10000 collector policy now supports authenticating with an SSH private key in addition to username/password. Specify the location of the private key file on the Data Collector Server. The corresponding public key must be registered for the user ID on the array. |
SC-79467 |
SSO/AD/JWT group matching now scoped to the root domain. External group names supplied during AD, SAML SSO, and JWT authentication are now matched only against root-domain portal user groups. Sub-domain groups are internally keyed as domainName:groupName, so they are no longer matched against bare external group names. To assign groups via these authentication flows, create the corresponding user groups under the root domain and name them to match the external group. |
SC-79546 |
The Oracle 19c July 2026 quarterly patch set has been qualified, applied and tested on the Windows portal, and the documentation has been updated. The following Oracle patches are included:
Customers running the IT Analytics Portal on Windows are recommended to apply this quarterly patch set. The patch binaries and the patch instructions document are available at the July 2026 Windows release build location referenced in the story description. |