IBM Support

JR61521: VULNERABILITIES IN JACKSON-DATABIND AFFECT IBM INFORMATION SERVER

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • The following vulnerabilities are addressed in this APAR
    
    
    CVE 2019-14379
    CVE 2019-14439
    CVE 2019-12086
    CVE 2019-12384
    CVE 2019-12814
    
    This APAR addresses the issue in the following connectors in the
    release(s) they are available in.
    
    Cloud Object Storage Connector
    Azure Data Lake Storage Connector
    Google Cloud Storage Connector
    

Local fix

Problem summary

  • Multiple vulnerabilities in
    jackson-databind affects Cloud Object Storage Connector.
    

Problem conclusion

  • Made changes required to overcome the vulnerability in the
    framework.
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR61521

  • Reported component name

    WIS DATASTAGE

  • Reported component ID

    5724Q36DS

  • Reported release

    801

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-09-22

  • Closed date

    2019-12-09

  • Last modified date

    2019-12-09

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WIS DATASTAGE

  • Fixed component ID

    5724Q36DS

Applicable component levels

  • RB71 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSVSEF","label":"InfoSphere DataStage"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.0.1","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
15 October 2021