Critical security hotfixes for U9, V11 and V12.

A security risk within Sage X3 has been discovered that may impact customers using Sage X3, Sage X3 Warehousing and Sage X3 HR & Payroll. The security risk is related to a platform component and has no impact on the Sage X3 application code or customizations that may have been implemented.

Please make sure the following instructions are carefully reviewed for all customers:

  1. Please review updated security guidelines in the Sage X3 Online Help

Sage provides a set of guidelines outlining best practices for deploying Sage X3 in a secure way. Our recommendation is that customers review these guidelines to ensure that Sage X3 is deployed securely. Please refer to the current security best practice recommendations available via the Sage X3 Online Help Center.

  1. Security technical components hotfixes:

Security technical components hotfixes are available for V12, V11 and PU9.

The updates that are delivered include a common set of components applicable to all versions (Adxadmin, Console, PrintServer, VT server), and version-specific Runtime and Syracuse fixes.

  • Adxadmin 93.2.53
  • Console 2.49.2.7
  • Print server 2.22.1.10
  • VT Server 2.39.1.2

All technical components must be applied together. The runtime component is not compatible with any previous versions of the other technical components. It cannot be installed independently.

Sage X3, Sage X3 HR and Sage X3 Warehousing V12:

Those components are compatible from 2020 R1 and for all later releases. They are included by default in 2021 R2.

  • Common components (adxadmin, Console, Print Server, VT Server)
  • Runtime 93.2.53
  • Syracuse 12.10.2.8

The Syracuse hotfix includes the replacement of Flash components, especially the Visual Process display and editor.

If your current release is 2020 R2 or 2020 R1, in addition to installing the Syracuse hotfix you will also need to:

  • Install the following application hotfixes:
    • Sage X3: WX_195292_R090_023.zip and WX_VP_R090_024.zip
    • Sage X3 HR & Payroll: WP_195292_R090_023.zip and WP_VP_R090_024.zip
    • Sage X3 Warehousing: WG_VP_R090_024.zip
  • Review your Sage X3 Visual Processes (if used) to check for any adaptation if necessary.

If your current release is 2020 R3, in addition to installing the Syracuse hotfix you will also need to:

  • Install the following application hotfixes:
    • Sage X3: WX_VP_R090_024.zip
    • Sage X3 HR & Payroll: WP_VP_R090_024.zip
    • Sage X3 Warehousing: N/A (No 2020 R3 Release for Sage X3 Warehousing)
  • Review your Sage X3 Visual Processes (if used) to check for any adaptation if necessary.

Sage X3 V11 and Sage X3 Warehousing

  • Common components (adxadmin, Console, PrintServer, VT server)
  • Runtime R081.004.810
  • Syracuse 11.25.2.6

The Syracuse hotfix includes the replacement of Flash components, especially the Visual Process display and editor.

Those technical components are compatible with the latest patch: V11 patch 19 for Sage X3 and V11 patch 10 for Sage X3 Warehousing.

Sage X3 HR&Payroll PU9

  • Common components (adxadmin, Console, PrintServer, VT server)
  • Runtime 9.118.904
  • Syracuse 9.24.1.3

Those technical components are compatible with Sage X3 HR & Payroll P20. All these hotfix components are included with the latest HR & Payroll patch P21. If you have already applied Sage X3 HR PU9 P21 and the technical components delivered with it, you do not need to install those Security hotfixes.

Sage X3 PU9

  • Common components (adxadmin, Console, PrintServer, VT server)
  • Runtime 9.118.904
  • Syracuse 9.22.7.2

Those technical components are compatible with the latest patch (X3 PU9 patch 12) and SyracuseServer does not include the replacement of Flash components.