Podcast
“Sovereignty Means Being Able to Change Course” – A Conversation with Manfred Beckers
Digital sovereignty in finance: Manfred Beckers discusses cloud dependencies, DORA, exit strategies and maintaining the ability to adapt.
Compliance

31.03.2022|

An exploit exists that makes use of the vulnerability. An application is vulnerable to the exploit when all of the following conditions are true:
The exploit requires network access to the server.
Patches to Spring Framework have been made available that contain a fix for the vulnerability:
Patches to Tomcat have been made available that contain a mitigation for the exploit:
We are investigating and taking action for ACTICO as an enterprise, ACTICO products and ACTICO services that may be potentially impacted, and will continually publish information here to help customers detect, investigate and mitigate attacks, if any, to their ACTICO products and services.
ACTICO is continuing to inventory our products and systems potentially impacted by the vulnerability. As necessary, we will be applying updates as they become available to fix the vulnerability, and applying mitigations in the interim.
ACTICO is continuing a product-by-product analysis for vulnerability impacts. If an ACTICO Software product is impacted, there will be an update on this news post as a remediation or fix becomes available. Such on-premise ACTICO products will then have to be updated by the customer.
ACTICO Professional Services will continue to work directly with its clients in support of the remediation of custom applications and services through its support processes.
For ACTICO Cloud services, ACTICO is remediating managed as-a-service Cloud offerings as applicable.
ACTICO is continuing to assess and remediate any remaining services and validate that mitigating controls remain effective.
ACTICO Platform 9.1 components like Model Hub, Execution Server and Workplace contain affected Spring Framework components. But they run standalone and cannot be deployed as a WAR to Tomcat. Thus, they contain the vulnerability, but are not affected by the exploit.
Still, we will make updates of all Platform 9.1 components available, with updated Spring Framework components, until Monday, April 11 2022 latest.
Update: Platform 9.1 (for the exact version please see the list below) with updated Spring Framework components was released on April 11 2022:
Modeler in all versions is not affected by the exploit or the vulnerability, because it is not serving HTTP requests.
Still, we will update contained Spring Framework components in next releases. A Modeler 9.1 will be included in the update on Monday, April 11 2022.
Update: Platform 9.1, including Modeler, with updated Spring Framework components was released on April 11 2022.
Model Hub 8.1 contains affected Spring Framework components. But it is run standalone and cannot be deployed as a WAR to Tomcat. Thus, it contains the vulnerability, but is not affected by the exploit.
We will make an update of Model Hub 8.1 available, with updated Spring Framework components soon. The exact date will be published as soon as possible.
Update: Model Hub 8.1.21 with updated Spring Framework components was released on April 6 2022.
Workplace 3.8 contains affected Spring Framework components and contains the vulnerability. The default mode of operation is standalone, but a WAR deployment is possible.
We will make an update of Workplace 3.8 available, with updated Spring Framework components soon. The exact date will be published as soon as possible.
Update: Workplace 3.8.26 with updated Spring Framework components was released on April 28 2022.
Compliance Suite contains affected Spring Framework components and contains the vulnerability.
It is often deployed into a Tomcat server as a WAR file. If this is the case and it runs with Java 9 or higher, then it is affected by the exploit.
Please contact us if you are affected by the exploit, so that we can advise on how to install a patched Tomcat.
We will make an update of Compliance Suite 3.5 with updated Spring Framework available soon. The exact date will be published as soon as possible.
ACTICO Rules 6.8 is not affected. It can run only up to Java 8.
We will not provide an update.
Visual Rules 7.2 / 8.0 are not affected. It can run only up to Java 8.
We will not provide an update.
If you have questions, please send an email to support@actico.com to open a ticket.
You may also be interested in:
Podcast
“Sovereignty Means Being Able to Change Course” – A Conversation with Manfred Beckers
Digital sovereignty in finance: Manfred Beckers discusses cloud dependencies, DORA, exit strategies and maintaining the ability to adapt.
Compliance
News
Chartis Research Again Names ACTICO a Category Leader for AML Transaction Monitoring 2026
ACTICO has again been named a Category Leader in the Chartis RiskTech Quadrant® for AML Transaction Monitoring Solutions 2026. The assessment recognizes ACTICO’s strengths in risk typology modeling, analytical modeling, model validation, workflow automation, and AI-powered compliance.
Anti-Money Laundering
Financial Institutions/FinTech, Insurance
Awards & Recognitions
News
ACTICO announces it has joined forces with Axe Finance, a global provider of credit and risk management software
ACTICO announces that it has joined forces with Axe Finance, a UK-based provider of credit and risk management software. The deal is supported by Keensight Capital, one of the leading private equity managers dedicated to pan-European Growth Buyout investments.
Webinar
Update on AML Requirements for Insurers: what you need to do now to be ready by July 2027.
AML update for insurers: What needs to be done by July 2027 regarding KYC, risk assessment and transaction monitoring? Including practical insights. Watch the webinar.
Anti-Money Laundering
Insurance
Newsletter
Regular News and Updates
Decision Management Platform
Compliance
Resources
You are currently viewing a placeholder content from Hubspot Embedded Content. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from HubSpot. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Hubspot Meetings. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Wistia. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information