Fix packs for DataPower XML Security Gateway version 5.0

Downloadable files


Abstract

List of fixes in fix packs for IBM WebSphere DataPower XML Security Gateway XS40 version 5.0.

Download Description

Fix packs are located on Fix Central.


Important:



5.0.0.18

Release date: 26 November 2014
Last modified: 24 November 2014
Status: Available

APAR
Description
IT03931 DATAPOWER MIGHT INTERMITTENTLY FAIL TO PARSE DATA FROM THE DOCUMENT CACHE WHEN CONSTANTLY AT MAXIMUM XML NAME LIMIT
IT04351 UNDER CERTAIN CONDITIONS QUIESCE/UNQUIESCE OPERATION MIGHT RESULT IN AN IMMEDIATE RESTART OF THE DEVICE
IT05116 MORE DETAILED SECURE SOCKETS LAYER (SSL) PROTOCOL ERROR MESSAGES NEEDED



5.0.0.17

Release date: 30 September 2014
Last modified: 29 September 2014
Status: Available

APAR
Description
IT02341 ENABLING DATAPOWER WEB SERVICES MANAGEMENT MIGHT CAUSE A RESTART
IT02803 WHEN THE "PROCESS MESSAGES WHOSE BODY IS EMPTY" OPTION IS SET TO ON, UNEXPECTED TIMEOUT WOULD HAPPEN UPON RECEIVING HTTP 304 RESPONSE
IT02925 CREATING CHECKPOINT FAILS WITH OPERATION TIMEOUT ERROR DUE TO TOO MANY FILES IN CONFIGURATION
IT02956 ENHANCED SECURITY ON SEVERAL WEBGUI PARAMETERS
IT03874 CVE-2014-3508 - PRETTY-PRINT RESULTS OVER SSL MIGHT INCLUDE EXTRANEOUS DATA



5.0.0.16

Release date: 8 August 2014
Last modified: 22 August 2014
Status: Available

APAR
Description
IT00914 REFLECTED XSS VULNERABILITIES IN WEBGUI
IT01563 APPLIANCES WITH HSM FEATURE MIGHT EXPERIENCE IMMEDIATE RESTART UNDER LOAD
IT01586 DATAPOWER MIGHT NOT RE-SYNCHRONIZE WSDL FILES FROM WSRR SERVER WHEN IT FAILS TO RETRIEVE THE FILES DUE TO AN ERROR CONDITION
IT01688 SOME WEB SERVICE PROXY SETTINGS ARE LOST WHEN SERVICE IS MODIFIED
IT01873 POSSIBLE RESTART MIGHT OCCUR DURING TRANSACTION WHEN MEDIATION-METRICS OPTION IS ENABLED AND AN ASYNC ACTION IS CONFIGURED IN A SERVICES PROCESSING POLICY
IT02050 ENHANCED SECURITY ON WEBGUI PARAMETERS
IT02708 SSL/TLS RENEGOTIATION MIGHT RESULT IN FAILURE IN SOME SCENARIOS
IT03781 DATAPOWER WEBGUI RENDERING ISSUE OCCURS WHEN ONE OR MORE DOT CHARACTERS ARE USED IN OBJECT NAMES



5.0.0.15

Release date: 19 June 2014
Last modified: 18 June 2014
Status: Available

APAR
Description
IT02314 CVE-2014-0224 - VULNERABILITY IN SSL CHANGECIPHERSPEC PROCESSING



5.0.0.14

Release date:30 May 2014
Last modified: 28 May 2014
Status: Available

APAR
Description
IC98670 DATAPOWER DOES NOT VALIDATE AND ACCEPT OAUTH TOKENS THAT ARE URL SAFE BASED ON RFC 4648 SPECIFICATIONS
IC99165 INCORRECT DATAPOWER SOMA INTERFACE SCHEMA DEFINITIONS FOR SOME STATUS PROVIDERS
IC99260 AAA POST PROCESSING LTPA TOKEN MIGHT NOT GENERATE LARGE EXPIRY DURATION
IT00247 ASYNCHRONOUS CALL RULE AFTER RESULTS ACTION STRIPS ATTACHMENTS FROM MESSAGE
IT00290 CRL FETCH URL FIELD REJECTS VALID URL WITHOUT FILE NAME PORTION
IT00516 COMPILATION OF STYLESHEET WITH <DP:SERIALIZE> AS THE CHILD OF <FUNC:FUNCTION> CAUSES AN APPLIANCE RESTART
IT01245 DATAPOWER APPLIANCE MIGHT RESTART WHEN A PROCESSING POLICY ERROR RULE CONTAINS ASYNCHRONOUS ACTION



5.0.0.13

Release date: 4 April 2014
Last modified: 2 April 2014
Status: Available

APAR
Description
IC98103 NO USER NAME IS LOGGED IN DATAPOWER AUDIT-LOG WHEN USING USER CERTIFICATE LOGIN
IC98526 DATAPOWER APPLIANCE MIGHT RESTART WHEN ACCESSING A SFTP SERVER
IC98530 PROBE NOT WORKING WHEN ALLOW COMPRESSION IS ENABLED IN THE USER AGENT
IC98637 DATAPOWER C14N DEBUG FILES MIGHT NOT OPEN WHEN CERTAIN CHARACTERS APPEAR IN THE FILE NAME
IC99081 DATAPOWER MIGHT RESTART WHEN A REQUEST IS RECEIVED WITH CONTENT-TYPE: MULTIPART/RELATED
IC99140 SECURITY IMPROVEMENTS NEEDED ON A URL PARAMETER WITHIN A WEBGUI TOOL
IC99149 SFTP SERVER DISRUPTION MIGHT CAUSE AN APPLIANCE TO RESTART OR GENERATE A WATCHDOG ERROR REPORT



5.0.0.12

Release date: 29 January 2014
Last modified: 27 January 2014
Status: Available

APAR
Description
IC93504 WS-PROXY HTTP CLIENT IP LABEL CHANGES AUTOMATICALLY WHEN WS-PROXY IS MODIFIED FROM WEBGUI
IC93876 NBLEAK COLLECTION MIGHT CAPTURE DATA IN A FORMAT THAT IS LESS THAN OPTIMAL TO ANALYZE THE MEMORY USE RESULTS.
IC96067 XC10: INCORRECT DATA MIGHT BE RETRIEVED WHEN READING FROM THE XC10
IC96920 DOMAIN EXPORT USING WEBGUI MIGHT CAUSE HANG AND WATCHDOG RESTART
IC97354 A DATAPOWER APPLIANCES DNS CONFIGURATION SET TO ROUND ROBIN DOES NOT HONOR THE TIME TO LIVE (TTL) SETTING
IC97356 PROCESSING A WSDL UPDATE IN A WEB SERVICE PROXY WHILE SERVICING TRAFFIC MIGHT CAUSE A RESTART
IC97378 LOG TARGET WITH EVENT TRIGGERS MIGHT CAUSE RESTART DUE TO HIGH MEMORY
IC97391 DATAPOWER MIGHT RESTART IN RARE SITUATIONS WHEN PARSING XML
IC97688 WEB APPLICATION FIREWALL PORT REMOVED FROM TCP TABLE UPON DOMAIN RE-ENABLE
IC97869 SOME RAID FOLDERS MIGHT BE MISSING IN THE LOCAL: AND LOGSTORE: DIRECTORIES AFTER A FIRMWARE UPGRADE
IC97930 HIGH LATENCY MIGHT OCCUR ON 5.0.0.0 OR LATER FIRMWARE



5.0.0.11

Release date: 26 November 2013
Last modified: 22 November 2013
Status: Available

APAR
Description
IC93918 DATAPOWER MIGHT NOT PREVENT SENDING MULTIPLE HTTP CONTENT-LENGTH HEADERS WHEN MAKING A URL-OPEN CALL
IC94241 DATAPOWER RADIUS AUTHENTICATION FAILS WITH ONE TIME PASSWORD (OTP)
IC94414 MEMORY GROWTH MIGHT OCCUR WHEN PROCESSING MESSAGES WITH ATTACHMENTS
IC95137 DATAPOWER MIGHT RESTART WHEN WEB SERVICE MANAGEMENT PROCESSES EXTENSION VARIABLE AS A NODESET
IC95531 DATAPOWER ACCEPTS INVALID JSON MESSAGE WITH TRAILING COMMA
IC95557 EXCESSIVE CONCAT() ARGUMENTS MIGHT CAUSE DATAPOWER TO RESTART
IC95735 'REJECTED BY FILTER' FAULT RECEIVED WHEN SENDING REQUESTS WITH ATTACHMENTS USING MTOM TO WEB SERVICE PROXY SERVICE
IC95739 NO ERROR REPORTED WHEN IMPORTING AN INVALID WSDL CONTAINING TWO ADDRESS TAGS FOR A SINGLE PORT
IC95760 SECURITY IMPROVEMENTS FOR WEBGUI FORMS
IC95887 SUB-ERROR CODES ARE NOT POPULATED IN THE WEB SERVICES MANAGEMENT(WSM) RECORD
IC95952 WEB SERVICE PROXY RETURNS TWO SOAP ENVELOPES WHEN PROBE IS ENABLED AND WEB SERVICE MANAGEMENT IS ENABLED IN BUFFER MODE
IC95973 DISABLING A DOMAIN CONFIGURED WITH A MULTICAST SLM PEER GROUP MIGHT RESULT IN A DATAPOWER APPLIANCE RESTART
IC95977 WHEN A PRIVILEGED USER IS RESTRICTED TO A DOMAIN, CERTAIN STEPS MIGHT ALLOW THAT USER TO ACCESS TO OTHER DOMAINS
IC96015 LOAD BALANCER ODCINFO IS NOT IMMEDIATELY RETRIEVED AFTER DOMAIN RESTART
IC96065 AAA POLICY DOES NOT WORK WITH GENERATED LTPA TOKEN
IC96154 DELAYED RESPONSE FROM DNS SERVER MIGHT CAUSE APPLIANCE TO RESTART
IC96195 PSIRT (PRODUCT SECURITY INCIDENT RESPONSE TEAM) LOGIN THREAT IDENTIFIED
IC96197 SECURITY IMPROVEMENTS FOR THE PROCESSING OF URL PARAMETERS IN THE WEBGUI



5.0.0.10

Release date: 30 September 2013
Last modified: 29 September 2013
Status: Available

APAR
Description
IC90422 DATAPOWER INCORRECTLY APPLIES XPATH EXPRESSION WHEN USING WS SECURITY POLICY SP:ENCRYPTEDELEMENTS ASSERTION
IC91596 CANNOT PERFORM A SECURE-RESTORE ON AN APPLIANCE IF THE FIRMWARE LEVEL OF THE APPLIANCE IS A DEBUG BUILD.
IC91647 WEB SERVICE PROXY DOES NOT RETURN THE RESPONSE BODY IF THE OPERATION CONFORMANCE POLICY EXISTS AND THE PROBE IS ENABLED
IC92151 CLIENT CONNECTION HANGS WHEN ON-ERROR ACTION CAUSES PROCESSING TO CONTINUE AFTER A FAILED TIBCO LOG ACTION
IC92153 UNEXPECTED RESTART MIGHT OCCUR AND A FATAL EXCEPTION IPMI EVENT IS LOGGED WHEN USING NFS
IC92808 RESPONSE BODY INCORRECTLY SENT TO CLIENT OF WEB SERVICE CONFIGURED WITH ONE-WAY PATTERN IN CASE OF SOAP FAULT
IC92982 WEB SERVICE PROXY MIGHT FAIL TO DETECT THE BOUNDARY DELIMITER STRING WHEN PARSING AN MIME MESSAGE
IC93006 ENABLING PROBE WITH NON-XML REQUEST TYPE RULE AND FLOW CONTROL ENABLED, WHEN INPUT NOT CONSUMED, MIGHT CAUSE TRANSACTION ERROR
IC93531 THE CLIENT SIDE SSL CONFIGURATION ADVANCED TAB DISPLAYS THE CIPHERS DEFAULT VALUE AS 'DEFAULT'
IC93730 USING AN ILLEGAL FILE NAME FOR AN EXPORT FILE MIGHT CAUSE THE DATAPOWER APPLIANCE TO RESTART
IC93780 THE LATEST PACKET CAPTURE FILE IS DUPLICATED WHEN CONTINUOUS PACKET CAPTURE IS TAKEN
IC93907 DATA ON A PERSISTENT STORAGE MIGHT BE LOST UNDER CERTAIN CIRCUMSTANCES
IC94225 IF STREAMING MESSAGES IS ENABLED, THE BACKEND MIGHT BE ACCESSED EVEN IF AAA REJECTS THE REQUEST
IC94481 WATCHDOG RESTARTS WHEN SAVING CONFIGURATION, IF DHCP IS CONFIGURED BUT NOT AVAILABLE
IC94877 DATAPOWER SSL SERVER INCORRECTLY REJECTS LARGE CLIENT_VERIFY MESSAGES



5.0.0.9

Release date: 16 August 2013
Last modified: 12 August 2013
Status: Available

APAR
Description
IC90782 FAILURE NOTIFICATION WITH UPLOAD ERROR REPORT AND BACKGROUND MEMORY TRACE MIGHT RESTART THE APPLIANCE
IC90878 CHANGES TO VALID XC10 GRID CONFIGURATION COLLECTIVE OBJECTS DO NOT TAKE EFFECT UNTIL A DOMAIN RESTART
IC91039 CANNOT WRITE TO XC10 OF PAYLOADS GREATER THAN 16 MB
IC91048 INEFFICIENT COMMUNICATION WITH XC10 REST GATEWAY MIGHT LEAD TO SUB-OPTIMAL PERFORMANCE
IC91227 DATAPOWER APPLIANCE MIGHT RESTART WHILE SYNCHRONIZING WITH WSRR
IC91345 NEED THE ABILITY TO SAVE STYLESHEET-CACHE-USAGE INFORMATION VIA CLI
IC91444 A RESTART MIGHT OCCUR UNDER CERTAIN CONDITIONS WHEN LOADING A DOMAIN CONTAINING SLM PEERING OBJECTS
IC91589 VALID XPATH EXPRESSION USED IN RESPONSE RULE MATCH ACTION CAUSES A PARSE ERROR WITH JSON REQUEST AND XML/SOAP RESPONSE TYPE
IC91815 OAUTH ACCESS TOKEN MIGHT BE REJECTED AS INVALID IF TWO OAUTH CLIENT NAMES ARE TOO SIMILAR
IC91969 A MULTI-PROTOCOL GATEWAY WITH DOCUMENT CACHE POLICY MIGHT HANG DURING A GET REQUEST AND RESTART DURING SHOW DOCUMENT-*
IC92083 DATAPOWER FAILS TO PROCESS SOME VALID JSON NUMBERS IN SCIENTIFICNOTATION
IC92092 APP-MGMT-PROTOCOL WSDL FILES CONTAIN ERRORS
IC92114 MESSAGE DURATION MONITORS DO NOT RESET PROPERLY WHEN STATISTICS COLLECTION IS DISABLED
IC92129 FRONT SIDE HANDLER AND USER AGENT TIMEOUTS MIGHT NOT BE EFFECTIVE WHEN A REMOTE SERVER IS NOT RESPONDING TO URL-OPEN()
IC92190 SUSTAINED HIGH CPU IS SEEN BECAUSE OF SSL CHURNING
IC92240 DEPLOYMENT POLICY INTENDED TO UPDATE A USER-AGENT REGULAR EXPRESSION ALSO UPDATES ALL OTHER REGULAR EXPRESSIONS
IC92257 WHEN A DATAPOWER APPLIANCE IS UNDER HEAVY WORKLOAD, A RACE CONDITION OCCURS AND MIGHT RESULT IN AN APPLIANCE RESTART
IC92270 A DATAPOWER APPLIANCE MIGHT GO INTO FAILSAFE MODE WHEN THE DEVICE LICENSE INFORMATION AND THE FIRMWARE GET OUT OF SYNC
IC92287 DISABLING SYSPLEX DISTRIBUTOR TARGET CONTROL SERVICE MIGHT CAUSE DATAPOWER TO RESTART
IC92324 WITH ROUND ROBIN ALGORITHM, CERTAIN EVENTS MIGHT CAUSE AN AO GROUPMEMBERS WEIGHT TO BE 0 EVEN AFTER EVENT IS RESOLVED
IC92443 SECURITY IMPROVEMENTS FOR PROCESSING OF URLS IN THE WEBGUI
IC92492 AN APPLIANCE WITH A SYSPLEX DISTRIBUTOR CONFIGURED MIGHT RELOAD DURING PROCESSING
IC92507 DATAPOWER DOES NOT USE NEXT DNS IN THE LIST AFTER RECEIVING SERVFAIL
IC92619 VIRTUAL: APPLIANCE RESTART MIGHT OCCUR AFTER A CHANGE TO THE CONFIGURATION OF AN EXISTING STANDBY CONTROL GROUP OBJECT
IC92638 WS-PROXY PROCESSING RULES AT WSRR-SAVED-SEARCH-SUBSCRIPTION LEVEL NOT INVOKED WHEN THE SERVICE HAS MULTIPLE SAVED SEARCH SUBSCRIPTIONS
IC92646 AN IMPORT OF DOMAINS WITH MANY WEB SERVICE PROXY SERVICES MIGHT RESULT IN AN APPLIANCE RESTART
IC93162 A PACKET CAPTURE FOR ALL INTERFACES, WITH A MAXIMUM SIZE OF THE FILE IN KILOBYTES SPECIFIED, MIGHT TERMINATE PREMATURELY
IC93183 VULNERABILITIES IN TWO ADMINISTRATIVE COMMANDS OR AN EXTENSION FUNCTION
IC93253 ASYNCHRONOUS ACTIONS IN A MULTISTEP PROCESSING RULE THAT INCLUDES DUMPERROR MIGHT RESULT IN A RESTART
IC93263 POSSIBLE UNAUTHENTICATED ACCESS WITH SOME KERBEROS AAA POLICIES
IC93277 A SECOND LOGIN MIGHT BE REQUIRED IF A SESSION FAILOVER OCCURS WHEN USING FORMS-BASED LOGIN
IC93295 HIDDEN TEMPORARY FILES ARE CREATED AFTER EXECUTING NESTED CFG SCRIPTS IN THE CLI
IC93296 AN INCORRECT URL IS DISPLAYED IN THE CLIENT BROWSER AFTER FORMS-BASED LOGIN
IC93910 CERTAIN LARGE AND CONTIGUOUS MEMORY ALLOCATIONS ARE OBSERVED TO CAUSE UNPREDICTABLE RESULTS



5.0.0.8

Release date: 31 May 2013
Last modified: 23 May 2013
Status: Available

APAR
Description
IC89561 UNEVEN LOAD DISTRIBUTION WITH AMONGST MEMBERS OF AN AO SELF-BALANCING SERVICES
IC90141 COMBINATION OF POLICIES IN WSDL BINDING WITH MULTIPLE OPERATIONS HAS MIXED POLICY ENFORCEMENT
IC90158 KEY ALGORITHM CHANGED IN WS-POLICY ENFORCED RESPONSE
IC90188 WITH MULTIPLE ROUTEMESSAGE, VALIDATEMESSAGE, OR EXECUTEXSL ACTION INSTANCES IN AN ACTION ELEMENT, ONLY THE FIRST INSTANCE OF AN ACTION TYPE IS ENFORCED
IC90200 TWO APPLIANCES CONFIGURED WITH THE SAME PHYSICAL ADDRESS ON THEIR INTERFACE COULD CAUSE AN ACTIVE APPLIANCE TO RESTART
IC90272 GENERATING LTPA TOKEN IN AAA ACTION MIGHT CAUSE AN UNEXPECTED RESTART
IC90273 USING LOG ACTION ON NON UTF-8 ENCODED CONTEXT TO LOG INTERNALLY MIGHT CAUSE AN UNEXPECTED RESTART
IC90280 DELAY NEEDED IN STANDBY CONTROL AT INTERFACE-UP TIME, ALLOWING SPANNING TREE TO RECONVERGE, TO PREVENT UNNECESSARY TAKE OVER
IC90316 WEB APPLICATION FIREWALL SERVICE WITH SQL INJECTION FILTERING ENABLED MIGHT CAUSE AN APPLIANCE RESTART
IC90359 ONLY THE FIRST COOKIE MIGHT REMAIN AFTER PASSING AAA ACTION WITH FORM BASED AUTHENTICATION
IC90388 A PROCESSING POLICY THAT OPENS A BINARY SOAP ATTACHMENT AS BASE64 ENCODED MIGHT CAUSE AN APPLIANCE RESTART
IC90431 LUCKY 13 PLAINTEXT RECOVERY ATTACK AGAINST SSL/TLS WITH CBC CIPHERS (CVE-2013-0169)
IC90435 S/MIME SIGNATURES USE LF AS THE LINE TERMINATOR INSTEAD OF CRLF
IC90458 HIGH LATENCY MIGHT BE OBSERVED DURING DNS FIRST ALIVE RESOLUTION
IC90601 XML-ACCELERATOR OFF SYSTEM SETTING FAILS TO PROPERLY DISABLE THE XML HARDWARE ACCELERATOR
IC90661 MESSAGE THAT IS GENERATED BY STYLESHEET AND DOES NOT CONTAIN ANY WSSECURITY HEADER ERROR APPEARS IN THE ERROR REPORT
IC90684 STORE.TGZ IS GENERATED IN THE SECURE BACKUP
IC90688 UNABLE TO IDENTIFY DNS SERVER ISSUES BY LOOKING AT DATAPOWER LOGS
IC90741 EXCEPTIONAL SITUATIONS MIGHT CAUSE A PROBLEM THAT INTERFERES WITH FUTURE XML NAME AUTOMATIC FREEING
IC90742 DATAPOWER ATTEMPTS THE FIRST ALIVE DNS SEARCHES BY USING A NULL DOMAIN WHEN NO SEARCH DOMAIN IS CONFIGURED
IC90745 REQUIRE TO LIMIT PERSISTENT REUSE OF MULTI-PROTOCOL GATEWAY FRONT-SIDE HANDLER CONNECTIONS
IC90766 CERTAIN DIME PAYLOADS OVER HTTP MIGHT CAUSE A RESTART
IC90781 POOR PERFORMANCE ON JSONX TO JSON CONVERSION
IC90793 UNPREDICTABLE BEHAVIOR MIGHT OCCUR IF THERE IS A NETWORK FAILURE ON A PORT IN A DOMAIN WITH A VERY LONG NAME
IC90924 APPLICATION OPTIMIZATION (AO) SELF BALANCING INCREASED LATENCY AND SENDING ICMP FRAGMENTATION REQUIRED
IC91025 GRADUAL MEMORY GROWTH MIGHT OCCUR WHEN USING LDAP HEALTH CHECK IN DATAPOWER
IC91037 IMPORTING CERTAIN SLM OBJECTS MIGHT CAUSE A DEVICE TO RESTART
IC91147 APPLIANCE RESTART MIGHT OCCUR WHEN A RESTART DOMAIN COMMAND IS ISSUED AND HEAVY TRAFFIC IS ON A WSPROXY IN THE RESTARTED DOMAIN
IC91183 DATAPOWER MESSAGE 0X00C3000C CONTEXT DOES NOT EXIST WHEN MULTIPLE POLICY ATTACHMENTS ARE ADDED TO THE SERVICE
IC91270 TERMINATING NSS SERVER MIGHT CAUSE DATAPOWER APPLIANCE TO RESTART
IC91312 CUSTOM XSLT WHICH USES OCSP EXTENSION FUNCTIONS MIGHT CAUSE A RESTART ON CERTAIN OCSP RESPONSES (CVE-2013-0166)
IC91446 ALLOW ADDITIONAL PASSPORT ADVANTAGE LICENSE FEATURES FOR NEW 7199/7198/4195 APPLIANCES



5.0.0.7

Release date: 3 May 2013
Last modified: 19 April 2013
Status: Available

XS40 version 5.0.0.7 contains no APAR fixes.


5.0.0.6

Release date: 30 March 2013
Last modified: 28 March 2013
Status: Available

APAR
Description
IC88032 PROCESSING XML INPUT IN WSP WITH TRANSFORM BINARY ACTION FROM INPUT CONTEXT RESULTS IN PARSE ERROR FOR REQUEST SIZES > 4KB
IC88222 APPLIANCE MIGHT RESTART IF CERTAIN UNSUPPORTED CIPHERS ARE SPECIFIED IN THE CRYPTO PROFILE
IC89045 MINOR SECURITY IMPROVEMENTS FOR WEBGUI INCORRECT PROCESSING OF SPECIFIC FORM DATA
IC89451 POTENTIAL COMPATIBILITY ISSUES WHEN USING HTML FORM BASED AUTHENTICATION WITH IBM WORKLIGHT CLIENT
IC89490 STATIC ROUTES FOR A DATAPOWER VLAN CONFIGURATION ARE MISSING FOLLOWING AN AUTOMATIC DEVICE RESTART
IC89568 SOME TRANSACTIONS CANNOT BE COMPLETED BECAUSE OF AN ERROR MESSAGE READ ERROR (7)
IC89589 SOME FIELDS IN THE WSM RECORD WRITTEN TO THE WSM BUFFER ARE MISSING WHEN AN ERROR OCCURS EARLY IN MULTISTEP PROCESSING
IC89794 XML MANAGEMENT SCHEMA CONTAINS INVALID SINGLE CHARACTER ESCAPES
IC89888 DATAPOWER AND WORKLIGHT INTEGRATION WITH LOCAL SUPPORT OF HTML FORM BASED AUTHENTICATION
IC89908 MINOR SECURITY IMPROVEMENTS FOR WEBGUI URL HANDLING
IC90106 AN ERROR REPORT MIGHT OMIT SOME ARCHIVED FILES



5.0.0.5

Release date: 31 January 2013
Last modified: 30 January 2013
Status: Available

APAR
Description
IC86286 MEMORY GROWTH OCCURS WHILE RETRIEVING ATTACHMENTS IN MULTI-STEP PROCESSING.
IC86845 A DELAYED RESPONSE FROM ASYNC ACTION WHEN USING PROBE MIGHT CAUSE UNEXPECTED RESTART.
IC86945 SOME EXSLT STRING MODULE EXTENSION FUNCTIONS DO NOT HANDLE NON-ASCII XML CHARACTERS PROPERLY.
IC86959 REGULAR EXPRESSIONS USED IN EXSLT REGEX FUNCTIONS MIGHT CAUSE MEMORY ERRORS AND APPLIANCE RESTART.
IC87052 DOMAIN UNQUIESCE DOES NOT UNQUIESCE HTTP FRONT SIDE HANDLER OBJECTS ON DATAPOWER.
IC87183 USER GROUP 'NONE' AUTOMATICALLY CREATED FOR A NEW LOG TARGET.
IC87642 SAML RECIPIENT IS NOT INCLUDED IN SAML ASSERTION.
IC88028 FTP AND SFTP POLLER UNEXPECTEDLY STOP POLLING AND NEVER RESTART.
IC88111 UNEXPECTED RESTART MIGHT BE TRIGGERED BY COMPILING STYLESHEET WITH NON-COMPLIANT <XSL:FOR-EACH> SELECT XPATH EXPRESSION.
IC88147 DATAPOWER ACL FILTER MODIFICATION FAILED.
IC88230 SHARED CONTEXT IS UNAVAILABLE ON RESPONSE RULE.
IC88952 UNPROCESSED ATTACHMENT PROCESSING MODE DOES NOT STREAM RESPONSE MESSAGE.
IC88966 WEB APPLICATION FIREWALL ENCRYPTS ONLY THE FIRST COOKIE.
IC88983 FTP POLLER FRONT SIDE HANDLER DOES NOT RENAME SUBDIRECTORIES ACCORDING TO THE ERROR RENAME RULE.
IC88993 UNDER CERTAIN CONDITIONS, ENCRYPTED BODY MIGHT NOT BE CHECKED PROPERLY BY WS-SECURITY POLICY.
IC89009 TRANSACTION ABORT IN RULE PROCESSING MIGHT CAUSE UNRECOVERED MEMORY AND/OR INTERFERE WITH FUTURE XML NAMES CLEANUP.
IC89014 INACTIVE OR DEACTIVATED FEATURE LICENSES ARE LOST UPON REINITIALIZATION OR FACTORY REINITIALIZATION OF AN APPLIANCE.
IC89054 THE POLICY-RELATED CLI SHOW COMMANDS MIGHT FAIL TO DISPLAY EXPECTED RESULTS.
IC89113 THE NETWORK INTERFACE COUNTERS FOR VLANS ALWAYS DISPLAY 0, EVEN WHEN THEY ARE ACTIVELY BEING USED FOR TRAFFIC.
IC89137 SOME ACTIONS AVAILABLE ON CONFIGURATION OBJECTS MIGHT NOT WORK PROPERLY.
IC89147 IF MULTIPLE WEBSPHERE CELL OBJECTS ARE USED WITH SSL, MODIFYING ONE OBJECT MIGHT OVERWRITE SETTINGS OF ANOTHER.
IC89194 PROVIDE ADDITIONAL DEBUG LEVEL LOG MESSAGES WHEN DATAPOWER ESTABLISHES CONNECTION WITH AN LDAP SERVER.



5.0.0.4

Release date: 29 November 2012
Last modified: 26 November 2012
Status: Available

APAR
Description
IC85372 APPLIANCE FAILS TO RESTART WHEN AN INTERNAL OPERATING SYSTEM ERROR OCCURS
IC85607 APPLIANCE MIGHT RESTART WHILE PROCESSING "VALIDATE BY SCHEMA ATTRIBUTE" ACTION
IC86209 DATAPOWER WSRR SERVER OBJECT INCORRECTLY USES DEFAULT DOMAIN USER AGENT
IC86244 UNEXPECTED RESTART MIGHT OCCUR WHEN USING LDAP EXTENSION IN XSL FOR PROCESSING POLICY
IC86342 APPLIANCE MIGHT RESTART WHEN TURNING ON WS-ADDRESSING WITH ATTACHMENT STREAMING ENABLED
IC86640 WSDL MISSING CERTAIN TARGETNAMESPACE ELEMENTS MIGHT CAUSE APPLIANCE RESTART
IC86687 CERTAIN SSH CONNECTIONS MIGHT RESULT IN TEMPORARY FILES BEING CREATED
IC86760 SQL DATA SOURCE RESTARTS IF ORACLE OBJECTS ARE ENABLED AND THE DATABASE CONNECTIVITY STATE CHANGES
IC86817 FALSE SLM TRIGGERING MIGHT OCCUR IF MESSAGE COUNT MONITORS ARE IN USE WHEN UPTIME VALUE EXCEEDS MAXIMUM
IC86912 DATAPOWER DOES NOT USE TTL VALUE IN DNS CNAME RECORD
IC86960 APPLIANCE MIGHT RESTART WHILE TRANSFERRING BIG FILES VIA WEBGUI
IC87282 SUPPORT FOR SSL COMPRESSION ALLOWS CRIME ATTACK (CVE-2012-4929)
IC87974 DATAPOWER XC10 URL OPENER SUPPORT



5.0.0.3

Release date: 19 October 2012
Last modified: 19 October 2012
Status: Available

APAR
Description
IC84925 URL-OPEN() FAILS UNDER SOME CONDITIONS
IC89641 NULL DP:VARIABLE WITH XS:DECIMAL ARITHMETIC CAUSES AN APPLIANCE RESTART IN CASE OF XSLT 2.0 XSLT PROCESSING MODE
IC85121 RESPONSE SOAP FAULT MESSAGES ARE VALIDATED ALTHOUGH SCHEMA VALIDATE FAULTS MESSAGES IS DISABLED
IC85268 CERTIFICATE DETAILS ARE NOT DISPLAYED WHEN SUBJECTKEYID IS EMPTY
IC85276 EXTENSION FUNCTION DP:GET-CERT-SUBJECT() STOPS PARSING IF SUBJECT CONTAINS BACKSLASH
IC85441 MESSAGE SIZE IN DATAPOWER WEB SERVICES MANAGEMENT RECORD MIGHT BE LARGER THAN THE SIZE OF THE MESSAGE SENT BY CLIENT
IC85659 XML MANAGER AND REFERENCED OBJECTS SOMETIMES CANNOT BE DELETED DUE TO BEING IN USE
IC85684 QUIESCE MIGHT PREVENT SUBSEQUENT DELETION OF FRONT SIDE HANDLERS AND REFERENCED OBJECTS DURING DOMAIN DELETION, RESET, OR RESTART
IC85912 COMPILING WSDL THAT DOES NOT HAVE AN ENDPOINT DEFINED MIGHT CAUSE AN UNEXPECTED RESTART
IC86010 THE DOCUMENT CACHE CLEAR COMMAND FAILS WHEN A SPECIFIC FILE PATTERN IS PROVIDED AND 'ENFORCE RBM ON CLI' IS ENABLED



5.0.0.2

Release date: 28 September 2012
Last modified: 21 September 2012
Status: Available

XS40 version 5.0.0.2 contains no APAR fixes.


5.0.0.1

Release date: 27 August 2012
Last modified: 27 August 2012
Status: Available

APAR
Description
IC82395 ASYNCHRONOUS OUTER ACTION/TRANSFORM ACTION PAIR RESULTS IN MEMORY GROWTH INTERFERING WITH FUTURE XML NAME AUTOMATIC FREEING
IC82693 DP:DEFLATE() WITH COMPRESS FORMAT FAILS IF COMPRESSION RATIO IS VERY LOW (GREATER THAN 2)
IC83121 CLI SHOW COMMANDS CAUSE SMALL MEMORY GROWTH IF ENFORCE RBM ON CLI IS ENABLED
IC83166 DATAPOWER APPLIANCE RESTARTS WHEN SSLPROXY IS USED IN AN ENVIRONMENT WHERE DNS RESOLUTION IS SLOW
IC83231 DISABLED KDC SERVER OBJECT MIGHT BREAK AP-REQ TOKEN GENERATION IN THAT DOMAIN
IC83501 DIAGNOSTIC COMMAND SHOW MEMORY PROC MIGHT CAUSE APPLIANCE RESTART
IC83509 IMPROVED TERMINATION PROCESSING FOR SSH CONNECTIONS
IC83574 WEB SERVICE PROXY POLICY NOT EXPANDING IN IBM DATAPOWER GUI TO SHOW WSDL OPERATIONS
IC83595 IBM SUPPORT DIAGNOSTIC COMMAND SHOW TASK MODIFIED TO ENHANCE SERVICEABILITY
IC83678 WSDL OPTION CHANGES AFTER FIRMWARE UPGRADE FROM 3.7.3 to 3.8.1 OR LATER
IC83746 A WS-POLICY REQUIRED-PARTS ELEMENT DOES NOT ALLOW MORE THAN ONE ELEMENT
IC83755 STYLESHEET WITH ISO-8859-1 XSL:OUTPUT ENCODING MIGHT PRODUCE INCORRECT OUTPUT
IC83863 DATAPOWER EXTENSION FUNCTION DP:GET-KERBEROS-APREQ FAILS WITH "INVALID NETWORK RESPONSE FROM KDC" ERROR
IC83935 WEB SERVICE PROXYS <SP:NOPASSWORD> FILTER MIGHT NOT REJECT A REQUEST HAVING A PASSWORD
IC83951 APPLIANCE RESTARTS WHEN A SERVICES PROBE IS ENABLED AND ITS WSDL LACKS A <WSDL:INPUT> ELEMENT
IC84042 RUNNING SFTP POLLING UNDER HEAVY LOAD MIGHT CAUSE THE APPLIANCE TO RESTART WHEN USING A LITERAL IP ADDRESS.
IC84111 GLOBAL MODE CACHE SCHEMA COMMAND FAILS WHEN EXECUTED USING XML MANAGEMENT INTERFACE
IC84743 MEMORY USED IN WSM AGENT STATUS INCREASES OVER TIME FOR MULTI-PROTOCOL GATEWAY SERVICE
IC84747 FIRST LINE OF SAVED APPLICATION DOMAIN CONFIGURATION MIGHT BE INCORRECT
IC84858 POTENTIAL EARLY TERMINATION OF SLM PROCESSING STATEMENTS
IC84993 DEFAULT SSL CONFIGURATION FOR WEB AND XML MANAGEMENT INTERFACES MISSING CA CERTIFICATES ON 9235 AND 4195 PLATFORMS
IC85135 DATAPOWER AAA TAM MAPPED RESOURCE DOES NOT GET PASSED TO RESOURCEMAP
IC85168 A RESTART MIGHT BE TRIGGERED WHEN THE CORRESPONDING FILE FOR THE TAM CONFIGURATION IS MISSING
IC85230 SLA POLICIES SHARING THE SAME MESSAGE CONTENT FILTER ARE NOT COMBINED



5.0.0.0

Release date: 26 June 2012
Last modified: 26 June 2012
Status: Available

APAR
Description
IC75097 CONFIGURATION COMPARISON TOOL REPORTS DIFFERENCES BETWEEN PERSISTED AND RUNNING CONFIGURATIONS AFTER COMMITTING TO FLASH
IC76498 USING A LOCALHOST DESTINATION FOR WSDL SOURCE-LOCATION IN A WEB SERVICE PROXY MIGHT FAIL TO LOAD WSDL CONFIGURATION
IC76570 PORT CONFLICT OCCURS WHEN MULTI-PROTOCOL GATEWAY FRONT SIDE HANDLER USES ADDRESS OF 0.0.0.0 AND A PORT THAT IS ALREADY USED BY ANOTHER SERVICE
IC76589 CLEARING THE STYLESHEET CACHE MIGHT CAUSE A RESTART ON A SYSTEM RUNNING DATA TRAFFIC
IC76859 FRONT AND BACK TIMEOUTS DO NOT EXPIRE IF SSL HANDSHAKE DOES NOT COMPLETE
IC77563 MONITORS CREATED BY ENABLING MMXDOS PROTECTION OPTION CANNOT BE REMOVED BY DISABLING THE OPTION WHEN EDITING SERVICES
IC77600 WHEN EDITING A FILE IN WEBGUI WITH SPECIAL CHARACTERS, THE 'HTTP 500' ERROR OCCURS ON FILE SUBMIT
IC77696 UNABLE TO ADD A WSDL FROM AN NFS SERVER
IC77705 ADDING A VLAN INTERFACE MIGHT CAUSE THE SHOW THROUGHPUT STATUS PROVIDER TO REPORT THE VLAN NAME AS (ILLEGAL)
IC77755 THE STATUS OF THE HOST ALIAS THAT A FRONT SIDE HANDLER USES GOES DOWN AFTER RESTARTING THE DEFAULT DOMAIN
IC78584 AAA CACHE TTL CAN BE OVERRIDDEN BY BROAD XML MANAGER DOCUMENT CACHE POLICIES
IC78891 DP:IMPORT FAILS IF THE DOMAIN NAME IN THE SOMA COMMAND DIFFERS IN CASE FROM THE DOMAIN NAME DEFINED IN DATAPOWER
IC78905 CANNOT REWRITE THE PATH-ATTRIBUTE ON THE SET-COOKIE HEADER-ELEMENT
IC78917 REQUEST AND RESPONSE ATTACHMENT PROCESSING MODES ARE NOT VISIBLE WHEN THE REQUEST AND RESPONSE TYPE IS NON-XML
IC79123 RBM POLICY FOR DATAPOWER FILE SYSTEM ACCESS DOES NOT TAKE EFFECT WHEN ACCESSING FILES THROUGH URLS ENTERED TO DATAPOWER
IC79207 A LENGTH ATTRIBUTE OF 4096 BYTES RESULTS IN INCORRECT OUTPUT. THE OUTPUT MIGHT BE NON-XML.
IC79413 THE 'PERMIT CONNECTIONS TO INSECURE SSL SERVERS' VALUE MIGHT BE UNEXPECTEDLY CHANGED WHEN CONFIGURING THE MULTI-PROTOCOL GATEWAY
IC79906 INCONSISTENT FILE NAME LENGTH LIMITATIONS FOR CRYPTO KEY, CERTIFICATE, SHARED SECRET KEY, AND KERBEROS KEYTAB OBJECTS
IC79925 STATUS PROVIDER SHOWS THROTTLED MESSAGES IN ALL STATEMENTS WHEN ONLY ONE STATEMENT IS THROTTLED
IC80416 EXECUTING SYSTEMUSAGE QUERIES DURING SYSTEM STARTUP MIGHT TRIGGER UNEXPECTED WATCHDOG RESTARTS
IC80582 LOGTARGET: IN OBJECT FILTER REFERENCED OBJECTS NOT ALL BEING REFERENCED
IC80765 OVERTYPE OF WEBGUI URL DOES NOT PRESENT '404 FILE NOT FOUND' ERROR
IC80956 NFS CONNECTIONS USING KERBEROS FAIL
IC81824 DATAPOWER NFS WRITE OPERATIONS MIGHT NOT REPORT FAILURE WHEN PERFORMED AGAINST AN UNRELIABLE REMOTE NFS SERVER
IC83827 CLIENT-KNOWN-HOST COMMAND INCORRECTLY RECEIVES 'TYPE IS NOT VALID MESSAGE' WHEN RBM IS ON FOR CLI
IC84088 ASN.1 PARSING VULNERABILITY IN SOME DATAPOWER SERVICES AND COMMANDS (CVE-2012-2110)
IC85080 WHEN USING NON-PTY (SSH WITH -T), EXIT COMMAND DISABLES ACCESS UNTIL CONNECTION TIMES OUT OR SSH SESSION IS CLOSED WITH CTRL-C



Change history
Last modified: 24 November 2014

  • 26 June 2012: Created fix list page.
  • 26 June 2012: Updated fix list details of 5.0.0.0.
  • 27 August 2012: Updated fix list details of 5.0.0.1.
  • 21 September 2012: Updated fix list details of 5.0.0.2.
  • 19 October 2012: Updated fix list details of 5.0.0.3.
  • 26 November 2012: Updated fix list details of 5.0.0.4.
  • 30 January 2013: Updated fix list details of 5.0.0.5.
  • 28 March 2013: Updated fix list details of 5.0.0.6.
  • 19 April 2013: Updated fix list details of 5.0.0.7.
  • 23 May 2013: Updated fix list details of 5.0.0.8.
  • 12 August 2013: Updated fix list details of 5.0.0.9.
  • 29 September 2013: Updated fix list details of 5.0.0.10.
  • 22 November 2013: Updated fix list details of 5.0.0.11.
  • 27 January 2014: Updated fix list details of 5.0.0.12.
  • 2 April 2014: Updated fix list details of 5.0.0.13.
  • 28 May 2014: Updated fix list details of 5.0.0.14.
  • 18 June 2014: Updated fix list details of 5.0.0.15.
  • 7 August 2014: Updated fix list details of 5.0.0.16.
  • 22 August 2014: Edited fix list details of 5.0.0.16.
  • 29 September 2014: Edited fix list details of 5.0.0.17.
  • 24 November 2014: Edited fix list details of 5.0.0.18.


Getting help and technical support
See Contacting IBM WebSphere DataPower Appliances support.


Problems (APARS) fixed
IC75097, IC76498, IC76570, IC76589, IC76859, IC77563, IC77600, IC77696, IC77705, IC77755, IC78584, IC78891, IC78905, IC78917, IC79123, IC79207, IC79413, IC79906, IC79925, IC80416, IC80582, IC80765, IC80956, IC81824, IC84088, IC85080, IC83827, IC82395, IC82693, IC83121, IC83166, IC83231, IC83501, IC83509, IC83574, IC83595, IC83678, IC83746, IC83755, IC83863, IC83935, IC83951, IC84042, IC84111, IC84743, IC84747, IC84858, IC84993, IC85135, IC85168, IC85230, IC84925, IC89641, IC85121, IC85268, IC85276, IC85441, IC85659, IC85684, IC85912, IC86010, IC85372, IC85607, IC86209, IC86244, IC86342, IC86640, IC86687, IC86760, IC86817, IC86912, IC86960, IC87282, IC87974, IC86286, IC86845, IC86945, IC86959, IC87052, IC87183, IC87642, IC88028, IC88111, IC88147, IC88230, IC88952, IC88966, IC88983, IC88993, IC89009, IC89014, IC89054, IC89113, IC89137, IC89147, IC89194, IC88032, IC88222, IC89045, IC89451, IC89490, IC89568, IC89589, IC89794, IC89888, IC89908, IC90106, IC89561, IC90141, IC90158, IC90188, IC90200, IC90272, IC90273, IC90280, IC90316, IC90359, IC90388, IC90431, IC90435, IC90458, IC90601, IC90661, IC90684, IC90688, IC90741, IC90742, IC90745, IC90766, IC90781, IC90793, IC90924, IC91025, IC91037, IC91147, IC91183, IC91270, IC91312, IC91446, IC85116, IC78905, IC90782, IC90878, IC91039, IC91048, IC91227, IC91345, IC91444, IC91589, IC91815, IC91969, IC92083, IC92092, IC92114, IC92129, IC92190, IC92240, IC92257, IC92270, IC92287, IC92324, IC92443, IC92492, IC92507, IC92619, IC92638, IC92646, IC93162, IC93183, IC93253, IC93263, IC93277, IC93295, IC93296, IC93910, IC90422, IC91596, IC92151, IC92153, IC92982, IC93531, IC93730, IC93780, IC93907, IC94225, IC94481, IC94877, IC91647, IC92808, IC93006, IC93918, IC94241, IC94414, IC95137, IC95531, IC95557, IC95735, IC95739, IC95760, IC95887, IC95952, IC95973, IC95977, IC96015, IC96065, IC96154, IC96195, IC96197, IC93504, IC93876, IC96067, IC96920, IC97354, IC97356, IC97378, IC97391, IC97688, IC97869, IC97930, IC98103, IC98526, IC98530, IC98637, IC99081, IC99140, IC99149, IC98670, IC99165, IC99260, IT00247, IT00290, IT00516, IT01245, IT02314, IT00914, IT01563, IT01586, IT01688, IT01873, IT02050, IT02708, IT03781, IT02341, IT02803, IT02925, IT02956, IT03874, IT03931, IT04351, IT05116

Rate this page:

(0 users)Average rating

Document information


More support for:

WebSphere DataPower XML Security Gateway XS40

Software version:

5.0.0

Operating system(s):

Firmware

Software edition:

Edition Independent

Reference #:

4032651

Modified date:

2014-11-25

Translate my page

Machine Translation

Content navigation