Nexeed
    • Introduction
    • Release notes
      • 2025.03.00
        • RC2
        • RC1
      • 2025.02.01
        • SP10
        • SP9
        • SP8
        • SP7
        • SP6
        • SP5
        • SP3
        • SP2
        • SP1
      • 2025.02.00
        • SP25
        • SP24
        • SP23
        • SP22
        • SP21
        • SP20
        • SP19
        • SP18
        • SP17
        • SP16
        • SP15
        • SP14
        • SP13
        • SP12
        • SP11
        • SP10
        • SP9
        • SP8
        • SP7
        • SP6
        • SP5
        • SP4
        • SP3
        • SP2
        • SP1
    • Getting started
      • Getting access
      • Login
      • Main screen
      • Welcome dashboard
      • Detecting process anomalies
      • Analyzing data and detecting event sequences
      • Analyzing KPIs
    • How-tos
      • Monitors on production lines
        • Configuring the automatic login in the Nexeed Industrial Application System
        • Configuring the automatic login to the identity provider with the Windows user
        • Setting cookies in the browser
        • Configuring the automatic logout in the Nexeed Industrial Application System
        • Configuring the command line parameters in the browser
        • Known limitations and troubleshooting
      • Try out the APIs
    • Integration guide
      • Underlying concepts
        • Underlying concepts
        • Onboarding
        • Security
        • Communication
      • Integration journey
      • Example integrations
        • Node-RED
        • Power BI
      • Overview of APIs
    • Operations manual
      • Release
      • System architecture and interfaces
      • System requirements
        • Cluster requirements
        • Database requirements
        • Support for service meshes
      • Migration from previous Nexeed IAS versions
      • Setup and configuration
        • Deployment process
        • Deployment with Helm
        • Advanced configuration
        • Integrations with external secret management solutions
        • Context paths
        • Service accounts and authorizations
        • Validation tests
        • Setup click once
        • Database user setup and configuration
      • Start and shutdown
      • Regular operations
        • User management & authentication
        • How to add additional tenants
        • How to access the cluster and pods
        • Automatic module role assignments in customer tenants
        • User credentials rotation - database and messaging secrets
      • Failure handling
        • Failure handling guidelines
        • Ansible operator troubleshooting
        • How to reach BCI for unresolved issues
      • Backup and restore
      • Logging and monitoring
        • The concept and conventions
        • ELK stack
        • ELK configurations aspects for beats
        • Proxy setup for ELK
        • Health endpoints configurations
      • Known limitations
      • Supporting functions
      • Security recommendations
        • Kubernetes
        • Security Best Practices for Databases
        • Certificates
        • Threat detection tools
    • Infrastructure manual
      • Release
      • System architecture and interfaces
        • RabbitMQ version support
      • System requirements
      • Migration from previous Nexeed infrastructure versions
      • Setup and configuration
        • Deployment process of the Nexeed infrastructure Helm chart
        • Deployment with Helm
      • Start and shutdown
      • Regular operations
        • RabbitMQ
          • User management & authentication
          • Disk size change
          • Upgrade performance with high performant disk type
          • Pod management policy
      • Failure handling
        • Connection failures
        • Data safety on the RabbitMQ side
        • Fix RabbitMQ cluster partitions
        • Delete unsynchronized RabbitMQ queues
        • How to reach BCI for unresolved issues
      • Backup and restore
      • Logging and monitoring
      • Known limitations
    • Training
    • Glossary
    • Further information and contact
Industrial Application System
  • Industrial Application System
  • Core Services
    • Block Management
    • Deviation Processor
    • ID Builder
    • Multitenant Access Control
    • Notification Service
    • Ticket Management
    • Web Portal
  • Shopfloor Management
    • Andon Live
    • Global Production Overview
    • KPI Reporting
    • Operational Routines
    • Shift Book
    • Shopfloor Management Administration
  • Product & Quality
    • Product Setup Management
    • Part Traceability
    • Process Quality
    • Setup Specs
  • Execution
    • Line Control
    • Material Management
    • Order Management
    • Packaging Control
    • Rework Control
  • Intralogistics
    • Stock Management
    • Transport Management
  • Machine & Equipment
    • Condition Monitoring
    • Device Portal
    • Maintenance Management
    • Tool Management
  • Enterprise & Shopfloor Integration
    • Archiving Bridge
    • Data Publisher
    • Engineering UI
    • ERP Connectivity
    • Gateway
    • Information Router
    • Master Data Management
    • Orchestrator

Nexeed Learning Portal

  • Industrial Application System
  • Release notes
  • 2025.02.00
  • SP16
preview 2026.01.00 2025.03.00

2025.02.00 SP16

Date:

23.10.2025

Change classification:

1 - Minor impact

Helm chart:

202502.0.16-rev1

Important Note - Delivery Schedule

  • Helm charts are already published

  • MESPKGs will be delivered delayed on Oct. 24, 2025

  • MESPKGs also available since Oct 24, 2025 10:55 CEST

Maintenance Management 2.4.2

Change classification:

1 - Minor impact

Artifacts:

mm:2.4.2-rev1

Changed

  • Update Angular & Web Core (460820)

Fixed

  • Fix CVE-2025-55315 (555332)

  • Locked/Unlocked filter does not work for list view
    TOMDESIGN-14457 (552964)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability

Tool Management 2.11.3

Change classification:

1 - Minor impact

Artifacts:

toma:2.11.3-rev1

Fixed

  • Fix CVE-2025-55315 (555333)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability

AGV Transport Orders 6.0.5

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9 = AGV Transport Orders 6.0.5

Change classification:

1 - Minor impact

Artifacts:

ies:6.0.5-rev1
iesedge:6.0.5-rev1

Changed

  • Updated translations for various languages
    Updated languages: DE, ES, FR, IT, PT, RO and ZH (552391)

Fixed

  • AGV mapping migration failure
    Resolved issues preventing transformed mappings in the front-end UI from applying to transport orders (TOs). Import/export functions now operate correctly without requiring deletion and re-creation of entries (554287)

  • Fixed CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9

Andon 2502.0.5

Change classification:

1 - Minor impact

Artifacts:

smessentials:2502.0.5-rev1

Fixed

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9 (555446)

  • Outdated token prevents break sound after 5 minutes (547740)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9

Archiving Bridge 3.1.3

Change classification:

1 - Minor impact

Artifacts:

archivingbridge:3.1.3-rev1

Fixed

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability (555811)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability

Block Management 2.3.3

Change classification:

1 - Minor impact

Artifacts:

blockman:2.3.3-rev1

Fixed

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability (555161)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability

DataPublisher 2.6.2

Change classification:

1 - Minor impact

Artifacts:

datapublisher:2.6.2-rev1

Fixed

  • Fixed CVE-2025-55315

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability

Deviation Processor 1.12.3

Change classification:

1 - Minor impact

Artifacts:

smdp:1.12.3-rev1

Fixed

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability (555159)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability

Engineering 2.1.3

Change classification:

1 - Minor impact

Artifacts:

engineering:2.1.3-rev1

Fixed

  • Fixed CVE-2025-55315

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability

ERP Connectivity 2502.0.4

Change classification:

2 - Major change

Artifacts:

erpconn:2502.0.4-rev1

General notes

  • Downtime required for upgrading to this version

Fixed

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9 (554947)

  • Log Retention: no clear description, when changes will have an effect (432051)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9

Global Production Overview 5.9.1

Change classification:

1 - Minor impact

Artifacts:

gpo:5.9.1-rev1

Fixed

  • Add missing attribute "COUNT_ALL_PROCESSES" (554056)

  • Duplicate shifts are not skipped (551326)

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9 (555446)

  • Replication stops if source data is invalid even though valid data is present for IAS source system in the future (546534)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9

ID Builder 3.7.2

Change classification:

1 - Minor impact

Artifacts:

idbuilder:3.7.2-rev1

Fixed

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability (555160)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability = Information Router 2.0.5

Change classification:

1 - Minor impact

Artifacts:

connectivity:2.0.5-rev1

Fixed

  • Fixed CVE-2025-55315

Security

KPI Reporting 2502.0.5

Change classification:

1 - Minor impact

Artifacts:

smessentials:2502.0.5-rev1

Fixed

  • Time templates are missing in some widgets (552633)

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9 (555446)

  • Downtimes are always shown in English (551325)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9

Line Control 5.2.1

Change classification:

1 - Minor impact

Artifacts:

linecon:5.2.1-rev3
lineasm:5.2.1-rev3

Fixed

  • Batch is not returned in ProcessRequest command (553192)

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9 (555223)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9

Master Data Management 8.8.2

Change classification:

1 - Minor impact

Artifacts:

mmpd:8.8.2-rev2

Fixed

  • Error definition import doesn’t work on Buel P (553445)

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability (555710)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability

Material Management 3.10.2

Change classification:

1 - Minor impact

Artifacts:

mat:3.10.2-rev1
MatControl_3.10.25203.02_MatClimateControl.mespkg
MatControl_3.10.25203.02_MaterialInfoPanel.mespkg

Fixed

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9 (555053)

  • ServiceClients: Some Patch calls via the ServiceClients fail with BadRequest on nginx (549690)

  • Using pure MES fails to start services after updating database to 3.x
    HybridMode (554119)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9

Multitenant Access Control 1.36.2

Change classification:

1 - Minor impact

Artifacts:

macma:1.36.2-rev2

General notes

  • Keycloak version used: 26.2.5

Fixed

  • /ping now correctly routes to Macma Core instead of Webapp

  • Fixed an issue where the UI crashes due to huge amount of memory needed after an excel import

Notification Service 1.29.1

Change classification:

1 - Minor impact

Artifacts:

notification:1.29.1-rev1

Fixed

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability

Operational Routines 2502.0.3

Change classification:

1 - Minor impact

Artifacts:

smor:2502.0.3-rev1

Fixed

  • Fix default roles regarding dashboard and meeting privileges (548027)

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9 (555446)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9

Orchestrator 2.0.2

Change classification:

1 - Minor impact

Artifacts:

orchestrator:2.0.2-rev1

Fixed

  • Fixed CVE-2025-55315

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability

Fixed

  • Memory increases permanently
    INC000030546660, INC000030548448, RQS000000441342

  • Repack stopped working
    TOMDESIGN-15005

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9 = Packaging Control 7.0.4

Change classification:

1 - Minor impact

Artifacts:

paco:7.0.4-rev1

Part Traceability 2.7.3

Change classification:

1 - Minor impact

Artifacts:

parttrace:2.7.3-rev2

Fixed

  • DataCollector: Telegram is stuck in the TRANSFER_QUEUE after it was inserted into both QDB OLTP and QDB OLAP (548272)

  • ASP.NET Security Feature Bypass Vulnerability CVE-2025-55315 (554911)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability

Known issues

  • DataBrowser RDS endpoints do not properly work (456005)

  • Archiving bridge stops exporting when invalid data is in the part telegrams table (467100)

  • Archiving bridge adapter export job does not limit query on part telegrams (467101)

  • No Data is sent to Data Publisher (479323)

  • Part Protocol does not show not packed part if too many rows (549838)

Product Setup Management 3.12.2

Change classification:

1 - Minor impact

Artifacts:

psm:3.12.2-rev2
ProductSetupManagement_3.12.25295.03_Client.mespkg

Fixed

  • CVE-2025-55315
    Microsoft ASP.NET Core Security Bypass Vulnerability

Security

  • CVE-2025-55315: Microsoft ASP.NET Core Security Bypass Vulnerability

Rework Control 6.3.3

Change classification:

1 - Minor impact

Artifacts:

rework:6.3.3-rev2
Rework_6.3.25289.01_Release_Client.mespkg

Fixed

  • Rework Client - Unknown LocationResultState 11 (545655)

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9 (555608)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9

Setup Specs 1.8.2

Change classification:

1 - Minor impact

Artifacts:

specs:1.8.2-rev2

Fixed

  • CVE-2025-55315
    Microsoft ASP.NET Core Security Bypass Vulnerability

  • Automated DAT file export to fileshare via orchestrator

Security

  • CVE-2025-55315: Microsoft ASP.NET Core Security Bypass Vulnerability

Change classification:

1 - Minor impact

Artifacts:

smessentials:2502.0.5-rev1

Fixed

  • Downtime Causes: Different behavior between web view and CSV export and return always full tree (448170)

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9 (555446)

  • Add missing attribute "COUNT_ALL_PROCESSES" (552439)

  • Improve handling of faulty data for GPO Replication (546760)

  • Prevent Quorum Queue migration from executing multiple times (554023)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9 = Shift Book 2502.0.5

Stock Management 6.0.5

Change classification:

1 - Minor impact

Artifacts:

ies:6.0.5-rev1
iesedge:6.0.5-rev1

Changed

  • Updated translations for various languages
    Updated languages: DE, ES, FR, IT, PT, RO and ZH (552391)

Fixed

  • Fixed CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9

  • Reservation fails if material does not exist

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9

Transport Management 6.0.5

Change classification:

1 - Minor impact

Artifacts:

ies:6.0.5-rev1
iesedge:6.0.5-rev1

Changed

  • Updated translations for various languages
    Updated languages: DE, ES, FR, IT, PT, RO and ZH (552391)

Fixed

  • TourPlanningService takes too long to plan tours with a lot of (>100) movements
    The TourPlanningService now avoids unnecessary back-fetches of tour movements, reducing load on the entity service and database. This significantly improves tour planning performance for tours with many movements (552934)

  • A misconfigured Tenant can render TourPlanning unhealthy for all tenants
    TourPlanning now manages cache locks separately for each tenant, preventing delays or failures in one tenant’s cache loading from affecting other tenants (554760)

  • Fixed CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability, CVE Score 9.9

Web Portal 5.23.1

Change classification:

1 - Minor impact

Artifacts:

portal:5.23.1-rev2

Fixed

  • CVE-2025-55315
    ASP.NET Security Feature Bypass Vulnerability (555158)

Security

  • CVE-2025-55315: ASP.NET Security Feature Bypass Vulnerability

Contents

© Robert Bosch Manufacturing Solutions GmbH 2023-2025, all rights reserved

Changelog Corporate information Legal notice Data protection notice Third party licenses