Personal Blog of Thomas Hampel - Creative Mythbusting in Development and Collaboration

Who am I?

Feeds

Archives

October 2025 (1)
September 2025 (1)
July 2025 (1)
June 2025 (2)
April 2025 (1)
January 2025 (1)
December 2024 (1)
November 2024 (2)
October 2024 (2)
September 2024 (1)
July 2024 (1)
May 2024 (2)
April 2024 (3)
March 2024 (1)
February 2024 (2)
January 2024 (5)
December 2023 (3)
November 2023 (2)
October 2023 (1)
September 2023 (4)
June 2023 (1)
April 2023 (3)
March 2023 (1)
February 2023 (1)
July 2022 (1)
September 2021 (1)
August 2021 (2)
May 2021 (1)
February 2021 (3)
January 2021 (1)
November 2020 (1)
October 2020 (2)
September 2020 (2)
March 2020 (1)
November 2019 (1)
August 2019 (1)
July 2019 (1)
March 2019 (1)
December 2018 (1)
November 2018 (1)
October 2018 (1)
September 2018 (1)
May 2018 (1)
January 2018 (1)
December 2017 (1)
November 2017 (1)
September 2017 (1)
March 2017 (2)
February 2017 (5)
November 2016 (1)
September 2016 (4)
April 2016 (1)
March 2016 (7)
January 2016 (1)
December 2015 (1)
November 2015 (3)
August 2015 (1)
July 2015 (2)
June 2015 (5)
May 2015 (5)
March 2015 (3)
February 2015 (2)
January 2015 (4)
December 2014 (3)
November 2014 (1)
September 2014 (4)
August 2014 (1)
May 2014 (4)
April 2014 (1)
March 2014 (2)
February 2014 (3)
January 2014 (2)
October 2013 (1)
September 2013 (1)
August 2013 (2)
July 2013 (2)
March 2013 (2)
February 2013 (4)
January 2013 (3)
December 2012 (2)
November 2012 (1)
October 2012 (2)
September 2012 (4)
August 2012 (3)
July 2012 (1)
June 2012 (6)
May 2012 (1)
February 2012 (2)
January 2012 (1)
December 2011 (4)
November 2011 (2)
September 2011 (1)
May 2011 (2)
March 2011 (1)
January 2011 (1)
November 2010 (5)
October 2010 (2)
September 2010 (2)
August 2010 (1)
July 2010 (3)
June 2010 (1)

HCL Notes/Domino - Apache Tika Vulnerability (CVE-2025-54988)

8 October 2025 Thomas Hampel
Certain versions of HCL Notes and Domino (but not all) are affected by the vulnerability in Apache Tika (CVE-2025-54988)
Apache Tika has an issue with indexing PDF attachments.


For context, the criticality for HCL Notes and Domino might be lower than what the CVE rating indicates because these products usually run in a non-priviliged (non-Root) environment.


Background:

Apache Tika is used in Domino for full-text indexing when:

1. indexing of attachments is enabled
>and<
2. conversion filters is enabled


see Database Properties:

Image:HCL Notes/Domino - Apache Tika Vulnerability (CVE-2025-54988)

Image:HCL Notes/Domino - Apache Tika Vulnerability (CVE-2025-54988)

Apache Tika is based on Java and updated versions of Tika have already been published by the maintainers of Tika for Java 11+

Just replacing the Tika files manually would technically work with Domino 14.0 and higher, but not with Domino 12.0.x and below as those versions are using Java 8

Tika no longer supports Java 8 - see
this
Furthermore it is not recommended to manually replace files in the HCL product as it will break future updates and fixes because the installer is looking for file checksums.


Mitigation actions

Have been published already in these technotes:
- HCL Notes:
KB0124165
- HCL Domino:
KB0124164

However, customers are asking when they can expect a fix for the particular version they have in use.


We have just published a technote to set expectations for when (and if) a fix will be made available:
see
KB0124451 - How to Configure Notes and Domino To Protect Against Apache Tika Vulnerability CVE-2025-54988

Updates are going to be provided only for the latest fixpack of each product version.


Current status:

The issue is fixed in:

-
Download - Notes/Domino 14.5 Fix Pack 1
-
Download - Notes/Domino 14.0 Fix Pack 4 Interim Fix 1 - for Win/Linux/AIX

Next up is to provide an Interim Fix on top of 12.0.2 FP7
additional details are provided in
KB0124451

References:

- How to Configure Notes and Domino To Protect Against Apache Tika Vulnerability CVE-2025-54988

https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124451

- Security Bulletin: HCL Notes is affected by an XML External Entity (XXE) vulnerability in Apache Tika (CVE-2025-54988)

https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124165

- Security Bulletin: HCL Domino is affected by an XML External Entity (XXE) vulnerability in Apache Tika (CVE-2025-54988)

https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124164

- Apache Tike Roadmap / End of life for Tika on Java8

https://cwiki.apache.org/confluence/display/TIKA/Tika+Roadmap+--+2.x%2C+3.x+and+Beyond
Comments [0]
Tagged with: Domino Security

Next HCL Domino Events near you - September 2025

1 September 2025 Thomas Hampel
Hi Folks,

I guess many of you enjoyed the summer and probably took some time off for vacation.
Now back to business! It's time to level up your skills and meet like-minded professionals.
How about joining a conference or meetup near you to connect?

Here is a list of events just for the next few weeks:


12. September 2025 - Denmark/Ringsted - Notes.net  

Notes.net Partner Meetup


18. September 2025 - South Korea / Seoul - Korea Domino User Group Meetup 2025

Location: WeWork Seoul Square


18. September 2025 - Japan/Osaka -
DominoHub
Image:Next HCL Domino Events near you - September 2025
=>
register here


24. September 2025 - Germany / Karlsruhe -
n-komm Connect
=>
zur Anmeldung


25. September 2025 - Germany / München -
HCL Roadshow 2025
=>
zur Anmeldung


and there is more to come
in October with
Let's Connect 2025 in Denmark/Copenhagen and Sweden/Stockholm
Image:Next HCL Domino Events near you - September 2025

and finally I want to note that
Accept IT also just announced their annual regional conferences
2. Dec. 2025 - Germany/Paderborn

4. Dec. 2025 - Germany/Düsseldorf

9. Dec. 2025 - Germany/Leipzig

11. Dec 2025 - Germany/Stuttgart

for more information see
AcceptIT Anwendertage 2025

So pack your bags and join in for awesome talks and news around Domino!

Comments [0]
Tagged with: Conference

Webinar : HCL Notes 14.5 Feature Highlights an Enhancements

17 July 2025 Thomas Hampel
Image:Webinar : HCL Notes 14.5 Feature Highlights an Enhancements

Webinar anouncement
HCL Notes 14.5: Feature Highlights and Enhancements

We will explore the latest updates designed to improve performance, usability, and user experience.
This webinar will cover key enhancements in the product such as the new Custom Application Builder, improved PWA and web client integration, and other improvements.

Learn how these updates can streamline your workflows and modernize your HCL Notes environment.
Whether you're an admin, developer, or end user, this webinar will provide valuable insights into what’s new and what to expect in Notes 14.5.

When?
Tuesday, 29 July 2025

16:00 CET - 17:00 CET

Registration Link

https://attendee.gotowebinar.com/register/3489002631583294813

Comments [0]
Tagged with: Community

Next Domino Events near you: DominoHUB (Tokyo/Japan) and DACHNUG in (Vienna/Austria)

17 June 2025 Thomas Hampel
Busy days ahead with two conferences on (almost) opposite time zones.
See me next week in Tokyo (Japan) and the week after in Vienna (Austria)


1. DominoHUB - The premiere event for Japan


Image:Next Domino Events near you: DominoHUB (Tokyo/Japan) and DACHNUG in (Vienna/Austria)

With this years event theme "#DX (Domino Experience) - The Truth About Domino” the conference will be held in Tokyo to delve deeper into the latest information and usage of HCL Notes/Domino.

The power and potential of Domino will be introduced with actual case studies, and the latest technology trends will be explained.

This is a great opportunity to learn the truth about Domino and accelerate your business DX!


19. + 20. June 2025

https://www.dominohub.net/

I'm going to present on our new features in Domino 14.5 together with my colleague Matsuura-san

Image:Next Domino Events near you: DominoHUB (Tokyo/Japan) and DACHNUG in (Vienna/Austria)

2. DACHNUG - Expert knowledge, networking & a unique supporting program

Image:Next Domino Events near you: DominoHUB (Tokyo/Japan) and DACHNUG in (Vienna/Austria)
DACHNUG is far more than just a classic specialist conference ‐ it is the central meeting place for the German-speaking Notes/Domino and HCL software community.
This is where experts, decision-makers and users come together to exchange ideas, learn from each other and make valuable contacts.


23.-25.June.2025 ‐ Vienna / Austria

https://dnug.de/en/dachnug/

At this conference, you can find me in several sessions:

(1.) Carsten Jenn (TimeToAct) and me will host a workshop about Domino IQ,
(2.) Wannes Rams (ISW) and me will talk about Sovereign Cloud (a very hot topic these days!)

of course I'll be presenting (3.) the Domino Roadmap on Wednesday and finally will do a deep dive on (4.) Domino IQ together with Daniel Nashed


Image:Next Domino Events near you: DominoHUB (Tokyo/Japan) and DACHNUG in (Vienna/Austria)

Safe Travels & See you soon !

またね

Comments [0]
Tagged with: Cloud Domino Events

HCL Domino 14.5 - Join me for the Launch Event on Tuesday June 17th at 16:00 CET

15 June 2025 Thomas Hampel
HCL Domino 14.5 is (almost) here, and it’s built for what matters now:
Private AI, Secure Collaboration, and complete control over your data.


Join us for the live launch on June 17 at 16:00 CET to explore what’s new in Domino 14.5 and Sametime 12.0.3, including:
  • Domino IQ: Secure AI, behind your firewall
  • Smarter chat, persistent meetings
    • Full deployment control: On-prem or trusted cloud
      Register
      here

      The launch event is scheduled to take place online at Linkedin. To join, you'll need to have a Linkedin account.


      Image:HCL Domino 14.5 - Join me for the Launch Event on Tuesday June 17th at 16:00 CET

  • Comments [0]
    Tagged with: Domino Security Sametime
    Thomas Hampel, All rights reserved.