IBM Support

IBM API Connect V5.0.8.6-iFix2 is available

Fix Readme


Abstract

IBM API Connect V5.0.8.6-iFix2 is available. This update addresses several field APARs reported since the availability of API Connect v5.0.8.6-iFix.

Content

IBM API Connect V5.0.8.6-iFix2 is now available. This update provides important development and APAR fixes.

We advise all users of IBM API Connect V5.0 to install this update to take advantage of the fixes.

Notes:

1) The Linux distribution for the Developer Portal OVA has moved from a Debian V7 base to an Ubuntu V16.04 base. Support for the Debian V7 OVA was withdrawn in May 2018. You are strongly encouraged to migrate your Developer Portal to the Ubuntu V16.04 base now, as support for Debian V7 upgrades was removed in May 2018.

2) [LoopBack](loopback.io) is one of node modules packaged in API Connect v5.  Version 2 has reached end of life in April 2019, and customers should be migrating to version 3 if they haven't done so already.  IBM will be updating the node modules packaged with API Connect v5.0.8.x beginning with v5.0.8.6-iFix2.

For information to migrate from 2.x to 3.x, please see https://loopback.io/doc/en/lb3/Migrating-to-3.0.html.

Support lifecycle policy for IBM API Connect Version 5.0.8.6-iFix2:

IBM API Connect Version 5.0.8.x is a Long Term Supported (LTS) release and is a recommended product level for which support, including defect and security updates, will be provided through cumulative, in-place Fix Packs until the effective end of support (EOS) date for IBM API Connect Version 5.0. An LTS release is intended for customers that may need a longer-term deployment for their environment. 

APAR fixes

The following APARs were addressed by IBM API Connect V5.0.8.6-iFix2, along with other internally raised quality fixes:

APAR Summary
LI80847 API CONNECT V5.0.8.X GWSCRIPT FUNCTION CALL APIM.ERROR() ADDS 400-600 MS TO TRANSACTION
LI80860 NO CHECK TO THE REVOCATION URL ON ACCESS TOKEN WHEN CALLING AN API THAT THE FIRST SCOPE IS INVALID
LI80863 UNABLE TO ADD ERRORS IN API -> ASSEMBLE UI
LI80886 UNEXPECTED PAYLOAD MESSAGE RECORDED IN THE ACTIVITY LOG
LI80903 VALIDATE USERNAME TOKEN POLICY MAY NOT WORK WITH LDAP
LI80922 LOOPBACK QUERY INJECTION VULNERABILITY
LI80936 MAP POLICY TO ALLOW CUSTOMIZATION OF INPUT NOT FOUND MESSAGE SEVERITY
LI80941 CSRF VULNERABILITY
LI80958 PHP VULNERABILITIES

Upgrade paths for API Connect:

For more information on IBM API Connect upgrade paths, see Supported Upgrade Paths.

There are specific validated upgrade paths between IBM® API Management Version 4.0 or later and IBM API Connect Version 5.0 or later. For more information, see Validated upgrade path for API Connect .

In addition to the specific validated upgrade paths for the API Management appliance, you must upgrade your IBM DataPower Gateway appliance. For more information, see Upgrading your DataPower appliances .

Upgrading the gateway to firmware level 7.5.0.1 is strongly recommended for the best experience.
 

Downloads:

Full installation and upgrade files for IBM API Connect Version 5.0.8.6-iFix2 can be downloaded from Fix Central: IBM API Connect Version 5.0.8.6-iFix2

Ensure that you have read and understood the upgrade and installation instructions before downloading and using the installation or upgrade files. You can find detailed installation instructions in IBM API Connect Knowledge Center -- Installing API Connect .

What is Fix Central (FC)?

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSMNED","label":"IBM API Connect"},"Component":"Not applicable","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"5.0.8.0;5.0.8.1;5.0.8.2;5.0.8.3;5.0.8.4;5.0.8.5, 5.0.8.6, 5.0.8.6-iFix","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
27 July 2019

UID

ibm10887519