Version 4.3

Enhancements

Security Update

Queries - The Query functionality used in Dovetail Agent Version 4.2 and earlier had a vulnerability for possible SQL injection attacks. SQL injection is a code injection technique that exploits a security vulnerability occurring in the database layer of an application. The vulnerability is present when user input is either incorrectly filtered for string literal escape characters embedded in SQL statements or user input is not strongly typed and thereby unexpectedly executed. By changing the way that parameters are used in Queries, this vulnerability has been eliminated. This does require that the latest version of Dovetail SDK is installed, since there are corresponding changes that support this security update.

Bug Fixes

Upgrading to Version 4.3

  1. Install the latest version of the Dovetail SDK.
  2. To install the updates and the new files included with this release, copy all of the files under the \pages directory to the system.
  3. Merge in any of your customizations with the new baseline pages.

See Also

Upgrade Guide and New Features

Before You Upgrade

Version 4.7

Version 4.6

Version 4.5

Version 4.4

Version 4.2

Version 4.1

Version 4.0

Version 3.10

Version 3.9

Version 3.8

Version 3.7

Version 3.6

Version 3.5

Version 3.0

Version 2.3

Version 2.2

Version 2.1

Version 2.0

Version 1.0

Next

Version 4.2

Version 4.3