IBM Support

PJ45232: SECURITY APAR - CVE-2018-1844 - EXTERNAL DTD VULNERABILITY WITH ADMINISTRATION CLIENT

Direct links to fixes

IBM Case Manager V5.3.3 Interim Fix 12 for Linux for Z
IBM Case Manager V5.3.3 Interim Fix 12 for Windows
IBM Case Manager V5.3.3 Interim Fix 12 for Suse Linux
IBM Case Manager V5.3.3 Interim Fix 12 for Linux
IBM Case Manager V5.3.3 Interim Fix 12 for AIX
IBM Case Manager V5.3.3 Interim Fix 10 for AIX
IBM Case Manager V5.3.3 Interim Fix 10 for Linux
IBM Case Manager V5.3.3 Interim Fix 10 for SUSE Linux
IBM Case Manager V5.3.3 Interim Fix 10 for Windows
IBM Case Manager V5.3.3 Interim Fix 10 for Linux for Z
workflow.18001.delta.repository
IBM Case Manager V5.3.3 Interim Fix 3 for Linux for Z
IBM Case Manager V5.3.3 Interim Fix 3 for Windows
IBM Case Manager V5.3.3 Interim Fix 3 for Linux
IBM Case Manager V5.3.3 Interim Fix 3 for AIX
IBM Case Manager V5.3.3 Interim Fix 5 for AIX
IBM Case Manager V5.3.3 Interim Fix 5 for Linux
IBM Case Manager V5.3.3 Interim Fix 5 for Windows
IBM Case Manager V5.3.3 Interim Fix 5 for Linux for Z
IBM Case Manager V5.3.3 Interim Fix 6 for AIX
IBM Case Manager V5.3.3 Interim Fix 4 for AIX
IBM Case Manager V5.3.3 Interim Fix 4 for Windows
IBM Case Manager V5.3.3 Interim Fix 4 for Linux for Z
IBM Case Manager V5.3.3 Interim Fix 4 for Linux
IBM Case Manager V5.3.3 Interim Fix 6 for Linux for Z
IBM Case Manager V5.3.3 Interim Fix 6 for Windows
IBM Case Manager V5.3.3 Interim Fix 6 for Linux
IBM Case Manager V5.3.3 Interim Fix 7 for AIX
IBM Case Manager V5.3.3 Interim Fix 7 for Linux
IBM Case Manager V5.3.3 Interim Fix 7 for Windows
IBM Case Manager V5.3.3 Interim Fix 7 for Linux for Z
IBM Case Manager V5.3.3 Interim Fix 8 for AIX
IBM Case Manager V5.3.3 Interim Fix 8 for Linux
IBM Case Manager V5.3.3 Interim Fix 8 for Windows
IBM Case Manager V5.3.3 Interim Fix 9 for AIX
IBM Case Manager V5.3.3 Interim Fix 9 for Linux
IBM Case Manager V5.3.3 Interim Fix 9 for Windows
IBM Case Manager V5.3.3 Interim Fix 9 for Linux for Z
IBM Case Manager V5.3.3 Interim Fix 10 for AIX
IBM Case Manager V5.3.3 Interim Fix 10 for Linux
IBM Case Manager V5.3.3 Interim Fix 10 for SUSE Linux
IBM Case Manager V5.3.3 Interim Fix 10 for Windows
IBM Case Manager V5.3.3 Interim Fix 10 for Linux for Z

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Packages imported by using the Case Manager administration
    client are exposed to an external DTD vulnerability. See the
    Security Bulletin for more information
    ( http://www.ibm.com/support/docview.wss?uid=ibm10734193 ).
    

Local fix

Problem summary

  • No additional information is available.
    

Problem conclusion

  • A fix is available for IBM Case Manager V5.3.3 and will be
    included in a future release of IBM Business
    Automation Workflow that ensures solution packages that are
    imported by using the Case Manager administration client are not
     exposed to the external DTD vulnerability.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PJ45232

  • Reported component name

    CASE MGR ADM CL

  • Reported component ID

    5725A1506

  • Reported release

    532

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-02-12

  • Closed date

    2019-01-31

  • Last modified date

    2019-01-31

  • APAR is sysrouted FROM one or more of the following:

    PJ45226

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    CASE MGR ADM CL

  • Fixed component ID

    5725A1506

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSCTJ4","label":"Case Manager"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"532","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
12 September 2023