IBM Support

IT14418: CVE-2015-7450 AFFECTS WEBSPHERE APPLICATION SERVER USED BY TPC

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

Local fix

  • See security bulletin.
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * TPC 5.1.x and 5.2.x users as noted in the security bulletin. *
    * Security Bulletin: Vulnerability in Apache Commons affects   *
    * IBM WebSphere Application Server (CVE-2015-7450)             *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * See security bulletin.                                       *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Follow the recommendation in the security bulletin.  It may  *
    * require manual steps in addition to applying a fix level.    *
    ****************************************************************
    

Problem conclusion

  • The fix for this APAR is targeted for the following maintenance
    package:
    
    | refresh pack | 5.2-TIV-TPC-RP0008
    | fix pack | 5.1-TIV-TPC-FP0010 target March 2016
    
    Fixed in IBM Spectrum Control 5.2.8 and Tivoli Storage
    Productivity Center 5.1.1.10.  The fix is not included in 5.2.9.
    See the security bulletin for details and any additional manual
    steps required.
    http://www.ibm.com/support/docview.wss?uid=swg21971859
    
    Latest Downloads
    http://www.ibm.com/support/docview.wss?&uid=swg21320822
    
    The target dates for future refresh packs do not represent a
    formal commitment by IBM. The dates are subject to change
    without notice.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT14418

  • Reported component name

    TPC

  • Reported component ID

    5608TPC00

  • Reported release

    527

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2016-03-22

  • Closed date

    2016-04-05

  • Last modified date

    2016-04-05

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Modules/Macros

  • SECURITY
    

Fix information

  • Fixed component name

    TPC

  • Fixed component ID

    5608TPC00

Applicable component levels

  • R520 PSY

       UP

  • R527 PSY

       UP

  • R511 PSY

       UP

  • R510 PSY

       UP

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SS5R93","label":"IBM Spectrum Control"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"527","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
22 February 2022