diff --git a/java/pom.xml b/java/pom.xml
index 0e26d9572..81bd03449 100644
--- a/java/pom.xml
+++ b/java/pom.xml
@@ -67,12 +67,14 @@ under the License.
2.10.5.1
UTF-8
${env.IMPALA_ICEBERG_VERSION}
- 4.0.3
+ 4.5.5
- 2.2.1
- 1.64
- 4.3.29.RELEASE
+ but they are needed by pac4j. This uses a newer xmlsec to address a CVE,
+ but bcprov-jdk15on and springframework versions match the versions from
+ pac4j 4.5.5. -->
+ 2.2.3
+ 1.68
+ 5.2.9.RELEASE
2.4.7