H+H Software GmbH

The HAN knowledge base

The HAN knowledge base helps you with smaller problems.

HAN.V5

HAN 5.6.3.0 available

Security patches in the recent version 5.6.3.0

The update HAN 5.6.3.0 is a service release that contains important security fixes. It is strongly recommended that you install the update as soon as possible. 

The update addresses the security vulnerabilities in the Apache web service that make it possible to attack the system (further information from the German Federal Office for Information Security can be found here). The following CVE (Common Vulnerabilities and Exposures) are addressed:

CVE-2023-38709, CVE-2024-36387, CVE-2024-38472, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573

HAN 5.6.3 updates the following core components mof the HAN Server:

  • Apache version 2.4.60 with Open SSL library 3.1.6
  • updatetd HAN Kernel
  • updatetd Open ID Connect module

Further changes are not made in this version.

Please note, that the HAN client does not need to be updated after the server update.