IBM Support

PH68672: SECURITY VULNERABILITY CVE-2024-5535

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Security scans have caught a vulnerability on our systems that
    appears to be from ADDI. The vulnerability is CVE-2024-5535, and
    
    the source is an SSL related .dll: "...\IBM Application
    Discovery and Delivery Intelligence\IBM Application Discovery
    Build Client\Bin\Release\libssl-1_1.dll"
    

Local fix

  • n/a
    

Problem summary

  • SECURITY VULNERABILITY CVE-2024-5535 was identified in several
    dependencies used by ADDI Build.
    

Problem conclusion

  • All the affected modules had their dependencies updated to newer
    versions where the vulnerability is fixed.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH68672

  • Reported component name

    APPL DISCOVERY

  • Reported component ID

    5737B1600

  • Reported release

    614

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2025-10-24

  • Closed date

    2025-12-16

  • Last modified date

    2025-12-16

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    APPL DISCOVERY

  • Fixed component ID

    5737B1600

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSRR9Q","label":"IBM Application Discovery"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"614","Line of Business":{"code":"LOB70","label":"Z TPS"}}]

Document Information

Modified date:
17 December 2025