APAR status
Closed as program error.
Error description
The change addresses the following alerts so that they are no longer falsely flagging DataPower firmware: CVE-2021-27219, CVE-2020-25648, CVE-2020-25692, CVE-2018-11798 CVE-2021-23343, CVE-2021-32804, CVE-2021-32803, CVE-2021-22940 While the firmware was not vulnerable to these exploits some security tools would flag the firmware as being vulnerable so this change would make sure to prevent that misconception.
Local fix
Problem summary
The noted CVEs will no longer be flagged as false positives.
Problem conclusion
For these apars CVE-2021-27219, CVE-2020-25648, CVE-2020-25692, CVE-2021-32804, CVE-2021-22940 & CVE-2021-32804 the update will be in 10.0.1.5 and for these it will be in 10.0.1.5 & 2018.4.1.18 - CVE-2018-11798, CVE-2021-23343 For a list of the latest fix packs available, please see: https://www.ibm.com/support/pages/node/83105
Temporary fix
Comments
APAR Information
APAR number
IT37949
Reported component name
DATAPOWER
Reported component ID
DP1234567
Reported release
A0X
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2021-08-20
Closed date
2021-09-29
Last modified date
2021-09-29
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
DATAPOWER
Fixed component ID
DP1234567
Applicable component levels
[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateways"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"A0X"}]
Document Information
Modified date:
30 September 2021