IBM Support

IT47395: ADDRESS FALSE POSITIVE RESULTS FROM VULNERABILITY SCAN

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • The following issues are falsely reported by various security
    scanning utilities and have been remediated; though the product
    was not vulnerable:
    CVE-2024-31449 CVE-2024-31227
    CVE-2024-31228 CVE-2024-50602
    
    
    
    CVE-2024-10917 CVE-2024-9143
    

Local fix

Problem summary

  • The related components have been upgraded to prevent false
    positive results from vulnerability scanners.
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    IT47395

  • Reported component name

    DATAPOWER

  • Reported component ID

    DP1234567

  • Reported release

    A5X

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2024-12-10

  • Closed date

    2024-12-10

  • Last modified date

    2025-01-22

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    DATAPOWER

  • Fixed component ID

    DP1234567

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateways"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"A5X","Line of Business":{"code":"LOB67","label":"IT Automation \u0026 App Modernization"}}]

Document Information

Modified date:
22 January 2025