TOLERANT Bank Release 12.1
2026/09/24
Notices and Warnings
- TPR-14661: Keycloak has been updated to version 26.4.4
- TPR-15302: JVM memory configuration has been improved. The previous JVM_OPT_MIN_RAM_PERCENTAGE setting has been replaced by JVM_OPT_INITIAL_RAM_PERCENTAGE, which controls the initial Java heap size.
- TPR-15477: JMX beans and JMX bean access was removed due to security considerations and it not being used by customers.
- TPR-16237: The health endpoint now implements two additional selectors:
- readiness: service is up and ready to accept requests
- liveness: service is running. This represents a relaxed health check.
- TPR-16308: Introduced a Helm chart for deploying TOLERANT Bank in Kubernetes. The chart is available on TOLERANT GitHub
- TPR-17437: SCL service flags now combine BIC11-specific entries with their BIC8 wildcard, ensuring correct SEPA service availability for IBAN, account number, BIC, and bank searches.
- TPR-17516: General security updates:
- Upgraded Java version 21.0.12.1+1
- Upgraded Nginx to version 1.30.5
- Upgraded Spring Boot to version 4.1.1
Fixed the following vulnerabilities:
- CVE-2026-49844
- CVE-2026-40983
- CVE-2026-40984
- CVE-2026-54291
- GHSA-q6gh-6v2r-hjv3
- CVE-2026-54515
- GHSA-387m-935m-c4vw
- CVE-2026-71497
- CVE-2026-59903
- CVE-2026-65905
- CVE-2026-65182
- CVE-2026-68525
New Product Features
Service
- TPR-14727: The info endpoint now displays information of the last reference data update.
- TPR-15971: Updated Spring Boot version for SOAP to 4.0.6 and fixed vulnerabilities: CVE-2026-29145, CVE-2026-24734, CVE-2026-34483, CVE-2026-34487
- TPR-16264: New endpoints are now available to enable the execution of tolerant command line tools on the backend.
- TPR-16454: Extended service.sh/exe to support the nginx reload command.
- TPR-16933: Increased the maximum file upload size to 100 MB.
API
- TPR-16388: The PL/SQL client now supports OAuth 2.0 client credentials, including automatic token acquisition and refresh.
General
- TPR-13176: Introduced the OutputField attribute ignoreEmptyValues, which is set to Y by default. If set to N, positional delimiters are added when more than one OutputFieldMapItem is mapped to a single OutputField.
- TPR-15208: Upgraded micronaut framework to version 4.10.14 and fixed CVEs: CVE-2026-33012, CVE-2026-33013, CVE-2026-33870, CVE-2026-33871
- TPR-15652: The output of support.sh/bat will now be written to $TLLOGS if $TOLERANT_HOME is not writable.
- TPR-15720: Added support for Informix databases.
- TPR-15826: The usage of ECS Layout is now supported either by using a custom log4j2 profile or by activating the integrated layout by setting the environment variable LOGGING_PROFILE=ecs.
- TPR-15900: Added new env variable TOLERANT_JVM_CUST_PROPERTIES to extend the java properties.
- TPR-16105: Added support for MYSQL and MariaDB databases.
- TPR-16146: Fixed vulnerability GHSA-72hv-8253-57qq.
Fixed Bugs
Service
- TPR-15002: Proxy configuration were adjusted to handle escape sequences correctly.
- TPR-16857: Restored the SOAP namespace and XML element qualification settings used in earlier releases.
General
- TPR-14714: IBAN calculation now correctly rejects account numbers excluded by bank-specific IBAN rule 0020 02.
- TPR-15158: Security vulnerability CVE-2025-41249 was removed in the (optional) SOAP service coming with the installation.
- TPR-15632: Synonym replacement now handles integer output fields such as bank.ResultCode correctly.
- TPR-16553: JDBC URLs containing usernames or passwords are no longer logged at INFO level while connecting to a database.
Known Bugs
- Currently no known bugs.
