Document Security | Quick Fix 1034-010

Posted on Nov 09, 2015

Note:

Contact Support for more information or to obtain the QF.

Issues fixed in the QF

  • Deserialization vulnerability in the Apache commons-collections library (Ref# CQ-69048)

Note:

To learn more about the vulnerability and obtain application server-specific patches, see Deserialization vulnerability in the Apache commons-collections library article.

Prerequisites to installing the QF

  • AEM 6.1 forms feature pack 1

Installing and configuring the QF

  1. Take a backup of the <AEM_forms_root>/deploy folder. It is required if you decide to uninstall the quick fix.
  2. Stop your application server.
  3. Extract the QF archive file to your hard drive.
  4. In the directory named according to the operating system that you are using:
    • Windows
      Navigate to the appropriate directory on the installation media or folder on your hard disk where you copied the installer, and double-click the install.exe file.
      • (Windows 32-bit) Disk1\InstData\Windows\VM
      • (Windows 64-bit) Disk1\InstData\Windows_64bit\VM
    • Linux, Solaris, AIX
      Navigate to the appropriate directory, and from a command prompt, type ./install.bin.
      • (Linux) Disk1/InstData/Linux/NoVM
      • (Solaris) Disk1/InstData/Solaris/NoVM
      • (AIX)Disk1/InstData/AIX/VM

    This launches an install wizard that guides you through the installation.

  5. On the Introduction panel, click Next.
  6. On the Choose Install Folder screen, verify that the default location displayed is correct for your existing installation, or click Browse to select the alternate folder where AEM forms is currently installed, and click Next.
  7. Read the Quick Fix Patch Summary information and click Next.
  8. Read the Pre-Installation Summary information and click Install.
  9. When the installation is complete, click Next to apply the quick fix updates to your installed files.
  10. The Start Configuration Manager checkbox is selected by default. Click Done to run the Configuration Manager.

    To run Configuration Manager later, deselect the Start Configuration Manager option before you click Done. You can start Configuration Manager later using the appropriate script in the [AEM_forms_root]/configurationManager/bin directory.

  11. Depending on your application server, choose one of the following documents and follow the instructions in the Configuring and Deploying AEM forms section.
  12. Restart the application server.

Impacted modules

  • AEM forms document security