Direct links to fixes
NetView for z/OS WebApp 5.4.0.11 for Windows
NetView for z/OS WebApp 5.4.0.11 for Linux on zSeries
NetView for z/OS WebApp 5.4.0.11 for Linux
NetView for z/OS WebApp 5.4.0.11 for AIX
NetView for z/OS WebApp 5.4.0.10 for Windows
NetView for z/OS WebApp 5.4.0.10 for Linux on zSeries
NetView for z/OS WebApp 5.4.0.10 for Linux
NetView for z/OS WebApp 5.4.0.10 for AIX
NetView for z/OS WebApp 5.4.0.9 for Windows
NetView for z/OS WebApp 5.4.0.9 for Linux on zSeries
NetView for z/OS WebApp 5.4.0.9 for Linux
NetView for z/OS WebApp 5.4.0.9 for AIX
NetView for z/OS WebApp 5.4.0.8 for Windows
NetView for z/OS WebApp 5.4.0.8 for Linux on zSeries
NetView for z/OS WebApp 5.4.0.8 for Linux
NetView for z/OS WebApp 5.4.0.8 for AIX
APAR status
Closed as program error.
Error description
Possible hang or loop in the Web Application component of Tivoli NetView for z/OS.
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: All V5R4 IBM Tivoli NetView for z/OS * * users who use the NetView Web Application * * server with the embedded WebSphere * * Application Server. * **************************************************************** * PROBLEM DESCRIPTION: A problem in the way that Java * * handles specific numerical conversion * * can be exploited by a malicious * * user and can cause affected server * * to hang. * **************************************************************** * RECOMMENDATION: * **************************************************************** The JDK/JRE shipped with IBM WebSphere Application Server may have an exposure to the numerical conversion problem in Java which may cause a hang. The NetView Web Application server embeds the WebSphere Application Server.
Problem conclusion
The NetView Web Application server is being re-packaged with the embedded WebSphere Application Server 7.0.0.15, which includes the fix for service pack for JDK 1.6. This remedies the Java numerical conversion vulnerability. The fixes are included in the packages that are available for download from the URL that is documented in the PSP upgrade for the NetView for z/OS product release. The downloads will be available on April 21, 2011.
Temporary fix
Comments
APAR Information
APAR number
OA35932
Reported component name
NETVIEW FOR Z/O
Reported component ID
5697ENV00
Reported release
54B
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt
Submitted date
2011-03-14
Closed date
2011-04-19
Last modified date
2011-04-19
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Modules/Macros
EGVNMCS
Fix information
Fixed component name
NETVIEW FOR Z/O
Fixed component ID
5697ENV00
Applicable component levels
R54B PSN
UP
Document Information
Modified date:
19 April 2011