IBM Support

IBM API Connect V5.0.8.4-iFix is available

Fix Readme


Abstract

IBM API Connect V5.0.8.4-iFix is available. This update addresses several field APARs reported since the availability of API Connect v5.0.8.4.

Content

IBM API Connect V5.0.8.4-iFix is now available. This update provides important development and APAR fixes.

We advise all users of IBM API Connect V5.0 to install this update to take advantage of the fixes.

Note: The Linux distribution for the Developer Portal OVA has moved from a Debian V7 base to an Ubuntu V16.04 base. Support for the Debian V7 OVA was withdrawn in May 2018. You are strongly encouraged to migrate your Developer Portal to the Ubuntu V16.04 base now, as support for Debian V7 upgrades was removed in May 2018.

Support lifecycle policy for IBM API Connect Version 5.0.8.4-iFix:

IBM API Connect Version 5.0.8.x is a Long Term Supported (LTS) release and is a recommended product level for which support, including defect and security updates, will be provided through cumulative, in-place Fix Packs until the effective end of support (EOS) date for IBM API Connect Version 5.0. An LTS release is intended for customers that may need a longer-term deployment for their environment. 

APAR fixes

The following APARs were addressed by IBM API Connect V5.0.8.4-iFix, along with other internally raised quality fixes:

APAR Summary
LI79869 USING IE11 IS NOT POSSIBLE IN EDIT VISIBILITY TYPE TEXT IN THE   FIELD WHEN THE CUSTOM VALUE IS SELECTED
LI79962 SHARE FUNCTION ON ANALYTICS DOES NOT WORK.
LI80003 WRONG URL IN "APPLICATION PLAN SUBSCRIPTION APPROVAL"
LI80142 USERS WITH CUSTOM ANALYTICS ROLES AT SPACES LEVEL CANNOT EXPORT/DOWNLOAD ANALYTICS EVENTS
LI80179 RED CMC INDEX WILL CAUSE LOGSTASH TO RUN OUT OF FILE HANDLES
LI80185 AFTER CHANGING THE GATEWAY ENDPOINT ON THE API MANAGEMENT SERVER, THE OAUTH REDIRECT URL STILL RETURNS THE OLD ENDPOINT.
LI80189 'YOUR E-MAIL ADDRESS' FIELD IN DEVELOPER PORTAL CONTACT FORM IS NOT READ-ONLY
LI80190 PUBLISHING DEPRECATED PRODUCT GENERATES APPOVAL SYSLOG ENTRY
LI80194 PHP_MAX_MEMORY, UPLOAD_MAX_SIZE, AND SET_TIMEZONE COMMANDS FAIL AFTER 5083 IFIX UPGRADE
LI80196 USER DEFINED POLICY PROPERTIES WITH AN ARRAY VALUE ARE CREATED  INCORRECTLY WHEN USING XSLT API :POLICYPROPERTIES FUNCTION.
LI80198 REST API TO LIST SUBSCRIPTION FAILS WITH HTTP 500 WHEN PRODUCT  IS NOT VISIBLE IN PORTAL
LI80200 MANAGEMENT SERVER THROWS INSUFFICIENT PERMISSION ERROR ON APIMANAGER WHEN TRYING TO CREATE A CATALOG
LI80205 API CONNECT IS VULNERABLE TO A POTENTIAL DENIAL OF SERVICE
LI80210 UNEXPECTED ERROR IS SHOWN DURING USER ACTIVATION WHEN LEGAL T&C IS ENABLED IN PORTAL
LI80218 CROSS FRAME SCRIPTING VULNERABILITY
LI80219 APIC MANAGEMENT SERVER MIGHT RETURN ERROR INTERMITTENTLY FOR  /V1/CATALOGS/CLOUD-METADATA REQUEST
LI80221 APPLICATION NAME REPLACED WITH APPLICATION ID AT EMAIL MESSAGE AND SYSLOG.
LI80222 DELETED APP CREDENTIAL IS MISSING FROM HOOK_IBM_APIM_APPLICATION_CREDS_DEL
LI80226 MULTICAST WEBAPI-PEERING LOCAL INTERFACE ADDR MIGHT NOT MATCH   XML MGMT INTERFACE IF MGMT AND API TRAFFIC INTERFACE DIFFERENT
LI80227 FAIL TO APPROVE SUBSCRIPTION REQUEST WITH ERROR "405 METHOD NOT ALLOWED"
LI80241 PREVENT DYNAMIC CONTEXT REFERENCES FROM INJECTING CODE INTO POLICIES
LI80242 UNABLE TO DELETE THE SUBSCRIPTION IN A SPACE BELONGS TO CATALOG
LI80244 INAPPROPRIATE MESSAGE OUTPUT IN EMAIL AND SYSLOG WHEN DECLINING APPS SUBSCRIPTION.
LI80245 'USERID' IS NOT APPROPRIATE WHEN CHANGING ORGANIZATION OWNER
LI80246 CATALOG, SPACD, ROLE NAME REPLACED WITH INSTANCE IDS AND NUMBER IN NOTIFICATION AND SYSLOG OUTPUT
LI80249 INSUFFICIENT INFORMATION ON AUDIT LOG WHEN WE DELETE DEVELOPER   ORG.
LI80250 THE SUBSCRIBING USER MIGHT NOT BE ABLE TO SEE PRODUCTS THAT ARE IN DEPRECATED STATE ON DEVELOPER PORTAL
LI80251 WHEN CREATING DEVELOPER ORGANIZATION, SYSLOG MESSAGE DISPLAY USER'S EMAIL ADDRESS INSTEAD OF USERNAME
LI80254 MAP POLICY XML OUTPUT WITH POLYMORPHIC ARRAY MAY NOT PRODUCE  CORRECT XML ELEMENTS FOR ARRAY ELEMENTS OTHER THAN FIRST ONE.
LI80255 UNKNOWN MESSAGE "DEPLOYED" IS WRITTEN IN AUDIT LOG.
LI80258 UNEXPECTED MESSAGE IN EMAIL, SYSLOG APPEARS WHEN DELETING A SUBSCRIPTION
LI80259 WRONG AUDIT MESSAGE IS LOGGED WHEN STAGING PRODUCT INTO SPACE USING DEVELOPER TOOLKIT.
LI80267 USER REGISTRATION MAY RETURN MESSAGE "THE WEBSITE ENCOUNTERED   AN UNEXPECTED ERROR" WHEN SUCCEDING
LI80268 AUTOCOMPLETE IS NOT DISABLED ON THE CHANGE PASSWORD PAGE
LI80269 DEVORG FIELD DISPLAYED IN PROFILE EDIT PAGE
LI80274 "COULD NOT CONVERT SOCKET TO TLS" ERROR WHEN TESTING THE SMTP SERVER CONFIGURATION FROM CMC
LI80276 PORTAL API EXAMPLE RESPONSES HAVE EXTRA SLASH '/' CHARACTERS
LI80279 API MANAGER DASHBOARD - PRODUCT PAGE NOT DISPLAYING ALL API PRODUCTS.
LI80281 ALLOW AN INVOKE POLICY TO SEND A PAYLOAD ON A HTTP DELETE
LI80283 OPTIMIZED SCHEMA DEFINITION DOES NOT CREATE THE CORRECT SCHEMA  IN SOME CASES.
LI80286 THE CONTEXT VALUE "PLAN.RATE-LIMIT" RETURN "UNLIMITED".
LI80287 NIC VMXNET3 DOESN'T WORK AFTER UPGRADE APIC MANAGEMENT SERVER TO V5084
LI80296 CUSTOM POLICY MAY HAVE ISSUES PASSING BINARY PAYLOADS THROUGH V5 FRAMEWORK
LI80297 CAN NOT SET "SUBSCRIBABLE BY" ON VISIBILITY FOR DRAFT PRODUCT  ONLY WHEN USING IE V11.
LI80298 UNABLE TO OPEN URL ERROR EVERY 5 MINUTES AFTER APPLYING APIC 5084
LI80299 EXCEPTION THROWN - WITHOUT AN REASON PHRASE IS NOT BEING CAUGHT BY NAMED CATCH POLICY
LI80305 GENERATE FROM SAMPLE JSON NOT POPULATING DEFINITIONS AND EXAMPLE VALUES
LI80311 SET VARIABLE POLICY OR SET VARIABLE FUNCTIONS WITH A CLEAR ACTION FOR MESSAGE.BODY DOES NOTHING
LI80312 DEVELOPER PORTAL UPGRADE REVERTS THE "ALLOW LIVE TESTING OF APIS" OPTION TO THE DEFAULT (I.E ENABLED).
LI80317 UI DO NOT SHOW "CONSUMES" AND "PRODUCES" SETTING ON OPERATION LEVEL WELL.
LI80323 COALESCED HEADERS SUCH AS A SET-COOKIE PARSING RULE CHANGED AFTER  DATAPOWER FIRMWARE UPGRADE.
LI80332 SPACE NAME IS NOT LOGGED ON AUDIT LOG WHEN WE APPROVE DEPRECATION REQUEST.
LI80335 NO MESSAGE IN SYSLOG WHEN CLICK 'UNSUBSCRIBE' BUTTON IN DEVELOPER PORTAL
LI80336 CATALOG NAME AND SPACE NAME IS NOT SHOWING CORRECTLY IN SYSLOG.
LI80339 PRODUCT IS PUBLISHED WITHOUT APPROVAL AT SPACE LEVEL IF CUSTOMER REPUBLISHES DEPRECATED PRODUCT
LI80340 AUDIT IS NOT LOGGED ON SYSLOG WHEN WE DELETE SUBSCRIPTION FROM   DEVELOPER PORTAL.
LI80342 ORGANIZATION AND CATALOG NAME IS NOT OUTPUT WHEN ROLE IS CHANGED AT SPACE LEVEL AFTER ADDING USER AT CATALOG LEVEL
LI80343 POLICY DEPLOYMENT TO CATALOG FAILS
LI80345 MAP UI INPUT FUNCTION "+ PARAMETERS FOR OPERATION" CREATES INCORRECT CONTEXT FOR HEADER PARAMETERS
LI80353 INCORRECT USER SPACE PERMISSIONS UNDER CERTAIN CONDITIONS
LI80355 CONSUMER ADVANCED SCOPE CONTEXT VARIABLE UNABLE TO BE CORRECTLY RESOLVED
LI80362 API CONNECT L1 TERMINAL FAULT SGX
LI80370 EMPTY XML ELEMENTS IN MAP INPUT ALWAYS MAPPED TO JSON AS AN EMPTY STRING
LI80371 NO ABILITY IN THE API CONNECT UI MAP POLICY TO SPECIFY AN EMPTY STRING DEFAULT
LI80372 MAP POLICY WITH XML INPUT ELEMENTS MAPPING TO A JSON OUTPUT PROPERTY WILL ALWAYS PRODUCE A STRING
LI80378 API CONNECT DEVELOPER PORTAL - MULTIPLE VULNERABILITIES
LI80394 CUSTOM POLICY GATEWAYSCRIPT ACTION UNABLE TO READ CONTEXT VARIABLE MESSAGE.BODY
LI80396 API CONNECT DEVELOPER PORTAL IMPACTED BY DRUPAL VULNERABILITIES
LI80404 CSV INJECTION VIA ANALYTICS DATA EXPORT
LI80417 MAP POLICY WITH THE RESOLVE XML INPUT DATATYPE PROPERTY ENABLED DOES NOT HANDLE SINGLE ELEMENT ARRAYS PROPERLY
LI80484 SENSITIVE INFORMATION DISCLOSURE FOR DEVELOPER PORTAL URL

Upgrade paths for API Connect:

For more information on IBM API Connect upgrade paths, see Supported Upgrade Paths.

There are specific validated upgrade paths between IBM® API Management Version 4.0 or later and IBM API Connect Version 5.0 or later. For more information, see Validated upgrade path for API Connect.

In addition to the specific validated upgrade paths for the API Management appliance, you must upgrade your IBM DataPower Gateway appliance. For more information, see Upgrading your DataPower appliances.

Upgrading the gateway to firmware level 7.5.0.1 is strongly recommended for the best experience.
 

Downloads:

Full installation and upgrade files for IBM API Connect Version 5.0.8.4-iFix (Enterprise, Professional & Essentials) can be downloaded from Fix Central: IBM API Connect Version 5.0.8.4-iFix

Ensure that you have read and understood the upgrade and installation instructions before downloading and using the installation or upgrade files. You can find detailed installation instructions in IBM API Connect Knowledge Center -- Installing API Connect.

 

 

 

Document information

More support for: IBM API Connect

Component: Not applicable

Software version: 5.0.8.0, 5.0.8.1, 5.0.8.2, 5.0.8.3, 5.0.8.4

Operating system(s): Platform Independent

Reference #: 0737099

Modified date: 03 January 2019