Direct links to fixes
APAR status
Closed as program error.
Error description
Security vulnerabilities in ActiveMQ 5.2.0 affect IBM Sterling B2B Integrator (CVE-2015-1830, CVE-2015-8110, CVE-2015-3060, CVE-2015-1880, CVE-2015-1879, CVE-2015-6551, CVE-2015-6092, CVE-2015-1587, CVE-2015-1244, CVE-2015-0684) Multiple directory traversal, cross-site scripting, denial of service and cross-site request forgery security vulnerabilities in ActiveMQ 5.2.0.
Local fix
STRRTC - 475637 BD / BD Circumvention: None
Problem summary
Users Affected: All Problem Description: Security vulnerabilities in ActiveMQ 5.2.0 affect IBM Sterling B2B Integrator (CVE-2015-1830, CVE-2015-8110, CVE-2015-3060, CVE-2015-1880, CVE-2015-1879, CVE-2015-6551, CVE-2015-6092, CVE-2015-1587, CVE-2015-1244, CVE-2015-0684) Multiple directory traversal, cross-site scripting, denial of service and cross-site request forgery security vulnerabilities in ActiveMQ 5.2.0. Platforms Affected: All
Problem conclusion
Resolution Summary: IBM Sterling B2B Integrator has addressed the applicable CVEs. If using external ActiveMQ implementations consider upgrading to ActiveMQ 5.9.1 or above. For more information, see the security bulletin: http://www.ibm.com/support/docview.wss?uid=swg21968792 Delivered In: 5104_8 5020500_10 5020600
Temporary fix
Comments
APAR Information
APAR number
IT11695
Reported component name
STR B2B INTEGRA
Reported component ID
5725D0600
Reported release
525
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt
Submitted date
2015-10-13
Closed date
2015-10-30
Last modified date
2015-11-30
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
STR B2B INTEGRA
Fixed component ID
5725D0600
Applicable component levels
R510 PSY
UP
R526 PSY
UP
[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS3JSW","label":"IBM Sterling B2B Integrator"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"5.2.5","Edition":"","Line of Business":{"code":"LOB02","label":"AI Applications"}}]
Document Information
Modified date:
30 November 2015