Skip to main content

IZ55562: IMS SERVER ? TOMCAT SERVER DOWNLEVEL

 

APAR status

  • Closed as program error.

Error description

  • Problem:
    
    There are a number of security vulnerability issues reported for
    the versions of tomcat provided with 8.0.x, 8.0.1 (5.5.23)
    
    
    Reference : http://tomcat.apache.org/security-5.html
    
    After analysis, two effect the IMS server, both referenced as
    low risk:
    
      CVE-2007-3382 and CVE-2007-3385
    
    Here is the ranking system described:
      http://tomcat.apache.org/security-impact.html
    
    Env:
      TAM E-SSO IMS Server 8.0.1
      Windows Server 2003, Standard Edition, SP2
      Enterprise Directory - AD
      Private Workstation - Private Desktop
    
    Expect Behavior:
      Security vulnerabilities to be resolved.
    

Local fix

  • NA
    

Problem summary

  • The exposures will be fixed in TAM ESSO 8.0.1 Fixpack 1 and
    8.0.0 Fixpack 2.
    

Problem conclusion

  • The exposures listed are low priority due to the fact that it
    requires Administrative authority on the IMS server to exploit
    

Temporary fix

Comments

APAR Information

  • APAR number

    IZ55562

  • Reported component name

    TAM ESSO IM SVR

  • Reported component ID

    5724V6700

  • Reported release

    800

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2009-07-20

  • Closed date

    2009-09-17

  • Last modified date

    2009-09-17

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    TAM ESSO IM SVR

  • Fixed component ID

    5724V6700

Applicable component levels

  • R800 PSY

       UP

  • R801 PSY

       UP

Copyright and trademark information

IBM, the IBM logo and ibm.com are trademarks of International Business Machines Corp., registered in many jurisdictions worldwide. Other product and service names might be trademarks of IBM or other companies. A current list of IBM trademarks is available on the Web at "Copyright and trademark information" at www.ibm.com/legal/copytrade.shtml.

Rate this page

Please take a moment to complete this form to help us better serve you.

This material provides me with the information I need.






This material is clear and easy to understand.






Did the information help you to achieve your goal?

What updates, improvements, or related information would you like to see in this document?

Your response will be used to improve our document content. Requests for assistance, if applicable, should be submitted through your normal support channel as we cannot respond from this site.


Input the verification number to submit feedback:



Maintenance Window

Unscheduled Maintenance Window

There is no unscheduled maintenance scheduled at this time.

Document information

Product categories:

Software

Security

Access

Tivoli Access Manager for Enterprise Single Sign-On

Base


Software version:

800


Reference #:

IZ55562


IBM Group:

Software Group


Modified date:

2009-09-17

Translate my page