News
Abstract
IBM API Connect V5.0.6.5 is available, which addresses several APARs, and includes product enhancements.
Content
IBM API Connect V5.0.6.5 is now available, which provides important development and APAR fixes.
We advise all users of IBM API Connect V5.0.6 to install this update to take advantage of the fixes. Users of IBM API Connect 5.0 to 5.0.6 also should consider upgrading to V5.0.8.
Support lifecycle policy for IBM API Connect Version 5.0.6.x:
IBM API Connect Version 5.0.6.x is a Long Term Supported (LTS) release and is a recommended product level for which support, including defect and security updates, will be provided through cumulative, in-place Fix Packs until the effective EOS date for IBM API Connect Version 5.0. An LTS release is intended for customers that may need a longer-term deployment for their environment.
Note that IBM API Connect Version 5.0.8.x has also been designated an LTS release.
See http://www-01.ibm.com/support/docview.wss?uid=swg22006450 for more details on the IBM API Connect v5.0.x Support Lifecycle.
APAR fixes
The following APAR were addressed by IBM API Connect V5.0.6.5, along with other internally raised quality fixes:
| APAR | Summary |
| LI79821 | API CONNECT NODE.JS VULNERABILITIES |
| LI79846 | HTTP 302 WHEN A REFRESH TOKEN IS USED TO REQUEST AN ACCESS TOKEN AND THE RESOURCE OWNER IS REVOKED BY THE REVOCATION URL. |
| LI79852 | UNAUTHORIZED EXECUTE ACCESS |
| LI79854 | WEB.CONFIG FILE FOUND IN SCANNER TOOL AGAINST DEV PORTAL |
| LI79856 | PORTAL V4->V5 UPGRADE PROBLEMS WITH SITE CLEANUP |
| LI79863 | SET-COOKIE HEADERS SET IN AN ASSEMBLY WITHOUT A PROXY POLICY MAY BE UNEXPECTEDLY COALESCED |
| LI79866 | AUTOHOST BEHAVIOR IF NO IP DEFINITION IN /ETC/HOST OR FROM DNS |
| LI79867 | UNABLE TO EDIT / DELETE TLS PROFILES IN V5064 CLOUD MANAGER CONSOLE |
| LI79878 | WHEN BROWSER LANGUAGE SET TO JAPANESE USER CAN NOT STAGE A PRODUCT WHEN ITS APIS CONTAIN THE SAME BASE PATH INSIDE A PLAN |
| LI79881 | SYSTEM.TIME AND SYSTEM.DATETIME DO NOT SHOW SYSTEM LOCAL TIME BUT UTC |
| LI79885 | CROSS SITE SCRIPTING CAN BE DONE ON THE DESCRIPTION FIELD OF AN API |
| LI79919 | HA LIST CLI COMMAND INCORRECTLY REPORTS NETWORK, ROLE, AND RUNTIME STATUS IF ICMP IS DISABLED |
| LI79994 | NODE.JS DDOS VULNERABILITY |
Upgrade paths for API Connect:
For more information of details on IBM API Connect upgrade paths, see Supported Upgrade Paths.
There are specific validated upgrade paths between IBM® API Management Version 4.0 or later and IBM API Connect Version 5.0 or later. For more information, see Validated upgrade paths for API Connect
In addition to the specific validated upgrade paths for the API Management appliance, you must upgrade your IBM DataPower Gateway appliance. For more information, see Upgrading DataPower for Gateway servers.
Upgrading the gateway to firmware level 7.5.0.1 is strongly recommended for the best experience.
Downloads:
Full installation and upgrade files for IBM API Connect Version 5.0.6.5 (Enterprise, Professional & Essentials) can be downloaded from Fix Central: IBM API Connect Version 5.0.6.5
Ensure that you have read and understood the upgrade and installation instructions before downloading and using the installation or upgrade files. You can find detailed installation instructions in IBM API Connect Knowledge Center -- Installing API Connect.
| What is Fix Central (FC)? |
Was this topic helpful?
Document Information
Modified date:
15 June 2018
UID
swg22010745