APAR status
Closed as program error.
Error description
See Problem Summary.
Local fix
NA
Problem summary
APAR NUMBER: IT39522 PRODUCT: TPF Operations Server Ver 1.2 FUNCTIONAL AREA: TPF OPERATIONS SERVER VER. 1.2 SHIPPED IN VERSION: 1.2.06 ABSTRACT: Address Apache Log4j Version 2.16 vulnerabilities in TPF Operations Server 64-bit Java support. PACKAGE CONTENTS: (C) com.ibm.tpf.tos64_1.2.6.jar (C) Log4jPlugin64_1.2.6.jar (C) TOSApi64_1.2.6.jar COMMENTS: The TPF Operations Server APAR IT39419 updated 64-bit Java support to Log4j version 2.16 to address CVE-2021-44228, which affected Apache Log4j2 version 2.15 or earlier. However, the Apache Log4j Version 2.16 is impacted by CVE-2021-45105.
Problem conclusion
SOLUTION: TPF Operations Server 64-bit Java support is upgraded to Apache Log4j Version 2.17.1 to address the latest Log4j vulnerabilities. COREQS: NO None. MIGRATION CONSIDERATIONS: YES Before you apply this APAR to your system, ensure that TPF Operations Server version 1.2.06 or later is installed and the following APARs are applied in the following order: IC98246 IT17682 IT20906 IT24582 IT33558 IT34114 IT36459 IT37161 IT27988 IT39419 To maintain a list of APARs that are applied to your system, you can create a directory named "APAR" under the TPF Operations Server base directory, and keep all APAR text files (ICxxxxx.txt and ITxxxxx.txt) that are applied to your system as a log. To apply this APAR to your system, complete the following steps: 1. Transfer and shut down any TPF Operations Server console and Java API clients. 2. Unzip IT39522.zip to a temporary location. 3. Run "tosapar.bat". 4. Start and transfer any TPF Operations Server console and Java API clients. UPDATED INFORMATION UNITS: NO None. See your IBM representative if you need additional information. DOWNLOAD INSTRUCTIONS: https://www.ibm.com/support/docview.wss?uid=swg27049608
Temporary fix
Comments
APAR Information
APAR number
IT39522
Reported component name
TPF OPS SRV W/2
Reported component ID
5799GKX00
Reported release
120
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2021-12-30
Closed date
2022-01-07
Last modified date
2022-01-07
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
TPF OPS SRV W/2
Fixed component ID
5799GKX00
Applicable component levels
[{"Line of Business":{"code":"LOB35","label":"Mainframe SW"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSZL53","label":"TPF"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"120"}]
Document Information
Modified date:
08 January 2022