PI Connector for UFL 1.3.2 release notes
- Last UpdatedSep 18, 2026
- 3 minute read
- PI System
- PI Connector for UFL 1.3.2.139
- Connectors
PI Connector for UFL transfers contextual and time-series data from textual data sources, such as ASCII and Unicode (UTF-8), to the PI System. AF elements and event frames, along with PI points, are created automatically when the connector receives data that pass the filters specified in the configuration (.ini) file.
PI Connector for UFL 1.3.2.139, released in August 2020, includes multiple bug fixes along with enhancements to improve processing performance.
For more information on product features and functions, including system requirements and installation/uninstallation instructions, refer to the PI Connector for UFL guide.
The latest information about the 1.3.2 release is available online on the AVEVA Documentation Portal.
New features and enhancements
This section lists enhancements in this release:
|
Work Items |
Description |
|---|---|
|
117408 |
Improved data processing performance through the configuration of Newline. |
|
118685 |
Compilation with Tau framework version 1.3.3. |
Resolved issues
This section lists items resolved in this release:
|
Work Items |
Description |
|---|---|
|
93051 |
Eliminated the need for connector restart following reconfiguration of PI Connector for UFLStoreInPIMode or IncomingTimeStamps. |
|
93895 |
REST Client mode modified so that cookie HTTP Headers are no longer ignored. |
Known Issues
There are no known issues for this release.
Security information and guidance
We are committed to releasing secure products. This section is intended to provide relevant security-related information to guide your installation or upgrade decision.
We proactively disclose aggregate information about the number and severity of security vulnerabilities addressed in each release. The tables below provide an overview of security issues addressed and their relative severity based on standard scoring.
Overview of new vulnerabilities - Fixed or Mitigated
This section is intended to provide relevant security-related information to guide your installation or upgrade decision. AVEVA is proactively disclosing aggregate information about the number and severity of PI Connector for UFL security vulnerabilities that are fixed in this release.
For this release of PI Connector for UFL, three high security vulnerabilities have been identified and fixed. The category of High (7.0-8.9) is based on the CVSS scoring system. These high-level security issues have been resolved in PI Connector for UFL itself and PI AF Client 2018 SP3 Patch 2 sub-component which have been packaged in this release. To reduce exposure to these security issues, upgrade to the latest release.
Security vulnerabilities fixed in the PI Connector for UFL 1.3.2 release
|
Severity Category |
CVSS Base Score Range |
Number of Fixed Vulnerabilities |
|---|---|---|
|
Critical |
9 - 10 |
0 |
|
High |
7.0 - 8.9 |
3 |
|
Medium |
4.0 - 6.9 |
0 |
|
Low |
0 - 3.9 |
0 |
Vulnerability mitigations in the PI Connector for UFL 1.3.2 release
This table lists the known vulnerabilities along with their mitigation in this product.
|
Component |
Version |
CVE or Reference |
CVSS |
Mitigation |
|---|---|---|---|---|
|
jQuery |
2.1.3 |
jQuery 2.2 and 1.12 Released (https://blog.jquery.com/2016/01/08/jquery-2-2-and-1-12-released/) |
7.9 |
The referenced component uglify.js is not used in this product’s development process. |
|
jQuery |
2.1.3 |
CVE-2015-9251 |
6.1 |
No cross-domain AJAX requests are made. |
|
jQuery |
2.1.3 |
CVE-2019-11358 |
6.1 |
Input is sanitized for all calls to the referenced ‘extend’ function. |
|
jQuery |
2.1.3 |
https://github.com/jquery/jquery/issues/2965 |
8.6 |
Input is sanitized for all calls to the referenced ‘parseHTML’ function. |
|
jQuery UI |
1.8.23 |
CVE-2016-7103 |
6.1 |
The referenced property ‘closeText’ is not used. |
|
jQuery UI |
1.8.23 |
CVE-2010-5312 |
4.3 |
The referenced “jQuery UI dialog” widget is not used. |
|
Knockout JS |
3.3.0 |
https://github.com/knockout/knockout/issues/1244 |
8.6 |
This product is not supported for use in Internet Explorer 7 (IE7). |
|
Knockout JS |
3.3.0 |
CVE-2019-14862 |
6.1 |
This product is not supported for use in Internet Explorer 7 (IE7). |
|
Bouncy Castle |
1.8.1 |
CVE-2020-15522 |
5.9 |
This vulnerability does not apply to PI Connectors because they do not use ECDSA Encryption. |
Microsoft Software Security Defenses
In addition to finding and fixing security bugs within the PI Connector for UFL, it is equally critical that we leverage security defenses provided by the Microsoft Visual C++ compiler that builds it and the Microsoft Windows operating system that runs it. Over the past decade, Microsoft has continually added new defenses and improved existing defenses with successive versions of the compiler and the operating system. To learn more about many of these key defenses, review the Mitigating Software Vulnerabilities white paper from Microsoft.
Distribution Kit Files
|
Product |
Software Version |
|---|---|
|
Microsoft .NET Framework 4.8 Setup |
4.8 |
|
Microsoft Visual C++ 2019 Redistributable (x86) |
14.21.27702.2 |
|
Microsoft Visual C++ 2019 Redistributable (x64) |
14.21.27702.2 |
|
PI AF Client 2018 SP3 Patch 2 |
2.10.8.440 |
|
PI Connector for UFL |
1.3.2.169 |