IBM Support

JR52950: SECURITY APAR CVE-2014-6953/2015-0410 - MULTIPLE VULNERABILITIES IN IBM SDK FOR JAVA SHIPPED WITH INTEGRATION DESIGNER

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • There are multiple vulnerabilities in IBM SDK Java Technology
    Edition, which IBM Integration Designer and IBM WebSphere
    Integration Developer use. These issues were disclosed as part
    of the IBM SDK Java Technology Edition updates in January 2015.
    This bulletin also addresses the "FREAK: Factoring Attack on
    RSA-EXPORT keys" TLS/SSL client and server vulnerability.
    

Local fix

Problem summary

  • No additional information is available.
    

Problem conclusion

  • A fix is available for the latest fix pack of all supported
    releases of Integration Designer and WebSphere Integration
    Developer.
    
    On Fix Central (http://www.ibm.com/support/fixcentral), search
    for JR52950:
    
    Select IBM Integration Designer or IBM WebSphere Integration
    Developer from the product selector, the installed version to
    the fix pack level, and your platform, and then click Continue.
    Select APAR or SPR, enter JR52950, and click Continue.
    
    When you download fix packages, ensure that you also download
    the readme file for each fix. Review each readme file for
    additional installation instructions and information about the
    fix.
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR52950

  • Reported component name

    INTEGRATION DES

  • Reported component ID

    5725C9702

  • Reported release

    855

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2015-03-26

  • Closed date

    2015-04-17

  • Last modified date

    2015-04-17

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    INTEGRATION DES

  • Fixed component ID

    5725C9702

Applicable component levels

  • R751 PSY

       UP

  • R801 PSY

       UP

  • R850 PSY

       UP

  • R855 PSY

       UP

  • R856 PSY

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSTLXK","label":"IBM Integration Designer"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"855","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
14 October 2021