IBM Support

Cognos Business Intelligence 10.2.x interim fixes address a security vulnerability

Download


Abstract

Cognos Business Intelligence interim fixes address a security vulnerability affecting IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1 and 10.2.2.

Download Description

The following interim fixes provide important product corrections related to a security vulnerability affecting IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1 and 10.2.2:

  • IBM Cognos Business Intelligence 10.2 Interim Fix 16 (Implemented by file 10.2.1104.512)
  • IBM Cognos Business Intelligence 10.2.1 Interim Fix 13 (Implemented by file 10.2.5000.508)
  • IBM Cognos Business Intelligence 10.2.1.1 Interim Fix 12 (Implemented by file 10.2.5009.501)
  • IBM Cognos Business Intelligence 10.2.2 Interim Fix 7 (Implemented by file 10.2.6103.506)
Note - This Security Updater contains two instances of the Commons Collections library as .jar files (commons-collections-3.2.1.jar & commons-collections-3.2.2.jar). For this updater, the commons-collections-3.2.1.jar is the commons-collections-3.2.2.jar renamed.

It is recommended that you apply the appropriate fix to all affected environments. After installing the IBM Cognos BI security updater, follow the instructions in Updating the IBM Cognos gateway after security kit installation. It is important to update the IBM Cognos BI gateway as there could be a potential mix of 32 bit and 64 bit libraries resulting in errors when accessing the gateway.

IBM Cognos Business Intelligence 10.2.x Security Interim Fixes are now cumulative. The updater files provided contain all the security fixes applicable to 10.2.x releases made available since January 2015. The updater files identified in the Download section can be applied if security fixes made available previously (including those available since January 2015) have already been installed.

Please refer to the Security Bulletin for more details.

Prerequisites

These interim fixes require the following releases are installed as prerequisites:

  • Cognos BI 10.2 Interim Fix 16 (10.2.0 IF16) requires that Cognos Business Intelligence 10.2 is already installed
  • Cognos BI 10.2.1 Interim Fix 13 (10.2.1 IF13) requires that Cognos Business Intelligence 10.2.1 is already installed
  • Cognos BI 10.2.1.1 Interim Fix 12 (10.2.1.1 IF12) requires that Cognos Business Intelligence 10.2.1.1 is already installed
  • Cognos BI 10.2.2 Interim Fix 7 (10.2.2 IF7) requires that Cognos Business Intelligence 10.2.2 is already installed

These Interim Fixes are compatible with all Fix Packs and Interim Fixes that have previously been made available for these releases.

Installation Instructions

To download an interim fix

  1. Review the prerequisites.
  2. Download the appropriate compressed tar file using the links in the Download package section.

Some browsers might change the downloaded file type from .tar.gz to a file type not recognized by the operating system. To correct this, change the file type back to tar.gz. Use of Download Director will prevent inadvertent renaming of files at download

To install an interim fix on Linux or UNIX
  1. Copy the downloaded interim fix to the appropriate operating system.
  2. Change to the directory where you have copied the downloaded interim fix image.
  3. Enter the following command: gunzip <filename> .tar.gz | tar xvf –
  4. If you want to see the version of a component before you install it, unpack the tar file to disk, or read the table of contents of the tar file.
  5. Follow the installation instructions in the IBM Cognos Business Intelligence Installation and Configuration Guide.
  6. Apply the interim fix to all installations.
Note: GNU Zip can be obtained from www.gzip.org and GNU tar can be obtained from www.gnu.org/software/tar

To install an interim fix on Windows
  1. Change to the directory where you have downloaded the interim fix.
  2. Using your file compress and decompress utility, decompress the .tar.gz file. If you are using WinZip, select the option "use folder names".
  3. If you want to see the version of a component before you install it, unpack the tar file to disk, or read the table of contents of the tar file.
  4. Follow the installation instructions in the IBM Cognos Business Intelligence Installation and Configuration Guide.
  5. Apply the interim fix to all installations.

Applicable Tech Notes
Fix Pack and Interim Fix Rollback - http://www-01.ibm.com/support/docview.wss?uid=swg21341204
Customization Considerations When Installing Interim Fixes - http://www-01.ibm.com/support/docview.wss?uid=swg21632409

[{"INLabel":"Cognos BI Installation and Configuration Guide 10.2","INLang":"Language Independent","INSize":"7000","INURL":"http://www.ibm.com/support/knowledgecenter/SSEP7J_10.2.0/com.ibm.swg.ba.cognos.cbi.doc/welcome.html"},{"INLabel":"Cognos BI Installation and Configuration Guide 10.2.1","INLang":"Language Independent","INSize":"7000","INURL":"http://www.ibm.com/support/knowledgecenter/SSEP7J_10.2.1/com.ibm.swg.ba.cognos.cbi.doc/welcome.html"},{"INLabel":"Cognos BI Installation and Configuration Guide 10.2.2","INLang":"Language Independent","INSize":"7000","INURL":"http://www-01.ibm.com/support/knowledgecenter/SSEP7J_10.2.2/com.ibm.swg.ba.cognos.cbi.doc/pathway_install.html"}]

Download Package

It is recommended that you install the latest generally available interim fix.

On
[{"DNLabel":"Cognos BI Server 64-bit 10.2 IF16 AIX","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"202550000","DNPlat":{"label":"AIX","code":"PF002"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2&platform=All&function=fixId&fixids=10.2-BA-CBI-AIX64-IF0016","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2 IF16 HP-UX Itanium","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"242690000","DNPlat":{"label":"HP-UX","code":"PF010"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2&platform=All&function=fixId&fixids=10.2-BA-CBI-HPUXIA64-IF0016","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2 IF16 Linux pSeries","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"141550000","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2&platform=All&function=fixId&fixids=10.2-BA-CBI-Linuxppc64-IF0016","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2 IF16 Linux x86","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"151270000","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2&platform=All&function=fixId&fixids=10.2-BA-CBI-Linuxi38664-IF0016","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2 IF16 Linux zSeries","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"142420000","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2&platform=All&function=fixId&fixids=10.2-BA-CBI-zLinux64-IF0016","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2 IF16 Solaris","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"164340000","DNPlat":{"label":"Solaris","code":"PF027"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2&platform=All&function=fixId&fixids=10.2-BA-CBI-Solaris64-IF0016","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 32-bit 10.2 IF16 Windows ","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"214540000","DNPlat":{"label":"Windows","code":"PF033"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2&platform=All&function=fixId&fixids=10.2-BA-CBI-Win32-IF0016","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2 IF16 Windows","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"308560000","DNPlat":{"label":"Windows","code":"PF033"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2&platform=All&function=fixId&fixids=10.2-BA-CBI-Win64-IF0016","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.1 IF13 AIX","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"165480000","DNPlat":{"label":"AIX","code":"PF002"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.1&platform=All&function=fixId&fixids=10.2.1-BA-CBI-AIX64-IF0013","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.1 IF13 HP-UX Itanium","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"181200000","DNPlat":{"label":"HP-UX","code":"PF010"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.1&platform=All&function=fixId&fixids=10.2.1-BA-CBI-HPUXIA64-IF0013","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.1 IF13 Linux pSeries","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"129410000","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.1&platform=All&function=fixId&fixids=10.2.1-BA-CBI-Linuxppc64-IF0013","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.1 IF13 Linux x86","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"133030000","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.1&platform=All&function=fixId&fixids=10.2.1-BA-CBI-Linuxi38664-IF0013","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.1 IF13 Linux zSeries","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"131750000","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.1&platform=All&function=fixId&fixids=10.2.1-BA-CBI-zLinux64-IF0013","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.1 IF13 Solaris","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"142860000","DNPlat":{"label":"Solaris","code":"PF027"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.1&platform=All&function=fixId&fixids=10.2.1-BA-CBI-Solaris64-IF0013","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 32-bit 10.2.1 IF13 Windows ","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"224560000","DNPlat":{"label":"Windows","code":"PF033"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.1&platform=All&function=fixId&fixids=10.2.1-BA-CBI-Win32-IF0013","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.1 IF13 Windows","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"333460000","DNPlat":{"label":"Windows","code":"PF033"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.1&platform=All&function=fixId&fixids=10.2.1-BA-CBI-Win64-IF0013","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.1.1 IF12 AIX","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"220550000","DNPlat":{"label":"AIX","code":"PF002"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.1.1&platform=All&function=fixId&fixids=10.2.1.1-BA-CBI-AIX64-IF0012","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.1.1 IF12 HP-UX Itaniu","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"247600000","DNPlat":{"label":"HP-UX","code":"PF010"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.1.1&platform=All&function=fixId&fixids=10.2.1.1-BA-CBI-HPUXIA64-IF0012","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.1.1 IF12 Linux pSerie","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"158910000","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.1.1&platform=All&function=fixId&fixids=10.2.1.1-BA-CBI-Linuxppc64-IF0012","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.1.1 IF12 Linux x86","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"161950000","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.1.1&platform=All&function=fixId&fixids=10.2.1.1-BA-CBI-Linuxi38664-IF0012","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.1.1 IF12 Linux zSerie","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"160390000","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.1.1&platform=All&function=fixId&fixids=10.2.1.1-BA-CBI-zLinux64-IF0012","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.1.1 IF12 Solaris","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"177880000","DNPlat":{"label":"Solaris","code":"PF027"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.1.1&platform=All&function=fixId&fixids=10.2.1.1-BA-CBI-Solaris64-IF0012","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 32-bit 10.2.1.1 IF12 Windows ","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"243580000","DNPlat":{"label":"Windows","code":"PF033"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.1.1&platform=All&function=fixId&fixids=10.2.1.1-BA-CBI-Win32-IF0012","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.1.1 IF12 Windows","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"364330000","DNPlat":{"label":"Windows","code":"PF033"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.1.1&platform=All&function=fixId&fixids=10.2.1.1-BA-CBI-Win64-IF0012","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.2 IF7 AIX ","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"220750000","DNPlat":{"label":"AIX","code":"PF002"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.2&platform=All&function=fixId&fixids=10.2.2-BA-CBI-AIX64-IF007","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.2 IF7 Linux pSeries","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"193770000","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.2&platform=All&function=fixId&fixids=10.2.2-BA-CBI-Linuxppc64-IF007","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.2 IF7 Linux Sys p LE","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"159230000","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.2&platform=All&function=fixId&fixids=10.2.2-BA-CBI-Linuxple64-IF007","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.2 IF7 Linux x86","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"198430000","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.2&platform=All&function=fixId&fixids=10.2.2-BA-CBI-Linuxi38664-IF007","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.2 IF7 Linux zSeries","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"197010000","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.2&platform=All&function=fixId&fixids=10.2.2-BA-CBI-zLinux64-IF007","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.2 IF7 Solaris","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"207010000","DNPlat":{"label":"Solaris","code":"PF027"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.2&platform=All&function=fixId&fixids=10.2.2-BA-CBI-Solaris64-IF007","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 32-bit 10.2.2 IF7 Windows ","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"304570000","DNPlat":{"label":"Windows","code":"PF033"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.2&platform=All&function=fixId&fixids=10.2.2-BA-CBI-Win32-IF007","DNURL_FTP":" ","DDURL":null},{"DNLabel":"Cognos BI Server 64-bit 10.2.2 IF7 Windows","DNDate":"30 Nov 2015","DNLang":"Language Independent","DNSize":"404250000","DNPlat":{"label":"Windows","code":"PF033"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Cognos&product=ibm/Information+Management/Cognos+8+Business+Intelligence&release=10.2.2&platform=All&function=fixId&fixids=10.2.2-BA-CBI-Win64-IF007","DNURL_FTP":" ","DDURL":null}]
[{"Product":{"code":"SSEP7J","label":"Cognos Business Intelligence"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"--","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"10.2.2;10.2.1;10.2","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
15 June 2018

UID

swg24041199