IBM Support

JR52138: ARE DATADIRECT ODBC DRIVERS AFFECTED BY THE SSLV3 POODLE VULNERABILITY?

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as Vendor Solution.

Error description

  • Progress DataDirect has reviewed Connect ODBC product and
    identified the following drivers impacted:
    Oracle Wire Protocol ODBC drivers
    Oracle Client ODBC driver
    SQL Server Wire Protocol ODBC drivers
    SQL Server Legacy ODBC driver
    DB2 ODBC drivers
    PostgreSQL ODBC drivers
    MySQL ODBC drivers
    Greenplum ODBC drivers
    Sybase ODBC drivers
    Teradata Client ODBC driver
    OpenEdge ODBC drivers
    Amazon Redshift ODBC drivers
    Salesforce ODBC drivers
    

Local fix

  • The Connect for Oracle Wire Protocol ODBC driver version 6.1 and
    higher can be configured to disable SSLv3 and avoid the POODLE
    vulnerability by setting the connect option EncryptionMethod=5.
    
    The SQL Server Legacy ODBC driver and client-based Connect ODBC
    drivers (Oracle Client, Informix Client, and Teradata Client)
    rely on the vendor-specific client libraries for SSL. Please
    consult the vendor-specific client library documentation for
    possible mitigation steps to avoid the POODLE vulnerability.
    

Problem summary

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    JR52138

  • Reported component name

    WIS DATASTAGE

  • Reported component ID

    5724Q36DS

  • Reported release

    910

  • Status

    CLOSED ISV

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2014-12-30

  • Closed date

    2015-03-27

  • Last modified date

    2015-03-27

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSVSEF","label":"InfoSphere DataStage"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"9.1","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
13 October 2021