ISM Endpoint Release History

Internal Scanning Management

Internal Scanning Management
Edition date
Last publication

View the list of changes included in the latest versions of the Veracode Internal Scanning Management endpoint.

If you are logged in to the Veracode Platform, you can download the installer to update your endpoint to the latest version.

22.12.3 - Released on December 19, 2022

  • Fixed an endpoint issue that caused threads to lock up until the ISM tunnel closes.
  • Improved endpoint logging that Veracode Technical Support can use for troubleshooting.

22.1.10 - Released on January 25, 2022

  • Endpoint upgraded to Log4j 2.17.1 to address security findings.
  • Improved thread management for connection stability.
  • Advanced memory usage diagnostics.

21.12.13 - Released on December 21, 2021

  • Endpoint upgraded to Log4j 2.17 to address known vulnerabilities CVE-2021-44228 and CVE-2021-45046.
  • Additional libraries upgraded to address security findings.

20.8.5 - Released on August 10, 2020

  • Endpoint now supports not resolving the hostname when accessing the ISM gateway via proxy. This support enables you to only allow the gateway hostname for outbound HTTPS calls.
  • Endpoint now supports not resolving the hostname when accessing scanned URLs via proxy. This support simplifies proxy configuration if you do not want to access external sites, such as Okta, during the scan.
  • Improved interface for configuring a proxy for the endpoint installer.
  • Endpoint installer supports configuring hostname resolution properties.
  • Java WebSocket library for the endpoint upgraded to version 1.5.1.
  • Endpoint supports specifying non-default network interface via endpoint properties, including the option to see a list of available network interfaces.
  • Endpoint process name on Linux includes a Veracode identifier.
  • Improved endpoint logging.

20.3.5 - Released on March 9, 2020

  • Endpoint installer supports client-side Java and 32-bit Java.
  • Endpoint installer supports proxy gateway-only property.
  • Endpoint supports running diagnostics through a DSE tunnel.
  • Endpoint supports new advanced diagnostics options.
  • Consolidated direct diagnostic options and diagnostics options that run through a DSE tunnel.
  • The ISM service from the Windows installer runs under the less privileged LocalService account instead of LocalSystem.
  • Proxy configuration in the installer no longer requires web access to
  • Resolved issue with property merge in the endpoint installer.
  • Improved endpoint memory management and out of memory protection.