Fixes are available
Download ISF roll-up 5 for InfoSphere Information Server Version 11.3.1.2
Download ISF roll-up 3 for InfoSphere Information Server Version 11.5.0.1
Download ISF roll-up 6 for InfoSphere Information Server Version 11.3.1.2
Download ISF roll-up 5 for InfoSphere Information Server Version 11.5.0.1
Download ISF roll-up 7 for InfoSphere Information Server Version 11.3.1.2
Download ISF roll-up 6 for InfoSphere Information Server Version 11.5.0.1
Download Data Integration Rollup 1 for InfoSphere Information Server 11.5.0.1
Download ISF roll-up 8 for InfoSphere Information Server Version 11.3.1.2
Download ISF roll-up 4 for InfoSphere Information Server Version 11.5.0.1
APAR status
Closed as program error.
Error description
Upgrade Apache HttpComponents version to address Apache HttpComponents vulnerabilities CVE-2012-6153 CVE-2014-3577 WebSphere addressed this issue in IFix PI50993, and that fix will be included in 8.5.5.9. Per the information in the WebSphere Security bulletin https://www-01.ibm.com/support/docview.wss?uid=swg21969251 installing either of these fixes will cause Information Server to report java.lang.NoClassDefFoundError, for example: ... webapp E com.ibm.ws.webcontainer.webapp.WebApp logServletError SRVE0293E: [Servlet Error]-[REST2]: java.lang.NoClassDefFoundError: org.apache.http.impl.client.DefaultHttpClient at java.lang.Class.getDeclaredMethodsImpl(Native Method) at java.lang.Class.getDeclaredMethods(Class.java:1001) at
Local fix
Problem summary
**************************************************************** USERS AFFECTED: Users of Information Server **************************************************************** PROBLEM DESCRIPTION: Security vulnerability in Apache HttpComponents affects Information Server **************************************************************** RECOMMENDATION: Refer to Security bulletin http://www.ibm.com/support/docview.wss?uid=swg21982420 for actions to perform. ****************************************************************
Problem conclusion
update version of Apache HttpComponents
Temporary fix
Comments
APAR Information
APAR number
JR55455
Reported component name
INFO SRVR PLATF
Reported component ID
5724Q3612
Reported release
870
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2016-03-14
Closed date
2016-10-14
Last modified date
2016-10-14
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
INFO SRVR PLATF
Fixed component ID
5724Q3612
Applicable component levels
R870 PSY
UP
R912 PSY
UP
RB31 PSY
UP
RB50 PSY
UP
Document Information
Modified date:
16 October 2021