Direct links to fixes
APAR status
Closed as program error.
Error description
IBM B2B Advanced Communications V1.0.0.4_3 --- IBM B2B Advanced Communications is leaking the client's production IP address within the error response. The masked response is provided below. This is a serious security concern and must be addressed. ======================= <?xml version="1.0" encoding="utf-8"?><soapenv:Envelopexmlns:soapenv=" http://www.w3.org/2003/05/soap-envelope"><soapenv:Header><ns2:Me ssaging xmlns:ns2="http://docs.oasis-open.org/ebxml-msg/ebms/v3.0/ns/cor e/200704/" soapenv:mustUnderstand="true"><ns2:SignalMessage><ns2:MessageInf o><ns2:Timestamp>2017-05-03T12:06:38.962Z</ns2:Timestamp><ns2:Me ssageId>a6d678aa-c164-48ed-b86b-67a5a9e6c096@1493813198962</ns2: MessageId><ns2:RefToMessageId>A1493813121587.af83e8a0-879a-4c52- a60e-759cf3636c7e@1493813121587</ns2:RefToMessageId></ns2:Messag eInfo><ns2: Error category="InternalProcess" errorCode="EBMS:0004" origin="ebMS" severity="failure" shortDescription="ConfigLookUpErr"><ns2:Description xml:lang="en">Error occurred while unpacking the message.</ns2:Description><ns2:ErrorDetail>Error occurred while looking up the configuration details for the incoming message.</ns2:ErrorDetail></ns2:Error></ns2:SignalMessage></ns2: Messaging></soapenv:Header><soapenv:Body><soapenv:Fault xmlns:axis2ns4120="http://www.w3.org/2003/05/soap-envelope"><soa penv:Code><soapenv:Value>axis2ns4120:Receiver</soapenv:Value></s oapenv:Code><soapenv:Reason><soapenv:Text xml:lang="en">Error occurred while unpacking the message.</soapenv:Text></soapenv: Reason><soapenv:Detail><DetailError>MessageTimeOutException:xs.x io.protobuf.ContainerMessages$GetRequestMessage/reqID=1745475 await timeout after 30000 ms contacting XX.X.XX.XXX:YYYYYY queue size on insert=2, waiter {id: 15899932, index:163}</DetailError></soapenv:Detail></soapenv:Fault></soape nv:Body></soapenv:Envelope> =======================
Local fix
STRRTC - 41517
Problem summary
Users Affected: Customers hosting IBM B2B Advanced Communications. Problem Description: It is observed that B2B Advanced Communications sends IP address of the machine hosting B2B Advanced Communication when it fails to connnect any node or production down scenario. Platforms Affected: All
Problem conclusion
Resolution Summary: A code fix is provided. Delivered In: 1002_6
Temporary fix
Comments
APAR Information
APAR number
IT20768
Reported component name
B2B ADV COMMUNI
Reported component ID
5725Q7200
Reported release
100
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2017-05-26
Closed date
2017-12-22
Last modified date
2018-08-09
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
B2B ADV COMMUNI
Fixed component ID
5725Q7200
Applicable component levels
R100 PSY
UP
[{"Line of Business":{"code":"LOB59","label":"Sustainability Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSYJCD","label":"Multi-Enterprise Integration Gateway"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"1.0.0"}]
Document Information
Modified date:
28 September 2021