IBM Support

PI95434: SECURITY FLAW FOR ICU FOR JAVA

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as fixed if next.

Error description

  • Using blackduck security scanner, the customer has found several
    vulnerabilities. Please see the component, the file touched, and
    the flaw.
    
    Component: ICU for Java
    Files Touched: bin/icu4j.jar
    Flaw: The resolveImplicitLevels function in common/ubidi.c in
    the Unicode Bidirectional Algorithm implementation in ICU4C in
    International Components for Unicode (ICU) before 55.1 uses an
    integer data type that is inconsistent with a header file, which
    allows remote attackers to cause a denial of service (incorrect
    malloc followed by invalid free) or possibly execute arbitrary
    code via crafted text.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * All Users                                                    *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * See Error Description                                        *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Upgrade to IBM Cognos Analytics 11.1.3                       *
    ****************************************************************
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    PI95434

  • Reported component name

    COG ANALYSIS ST

  • Reported component ID

    5724W12AS

  • Reported release

    B09

  • Status

    CLOSED FIN

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-03-20

  • Closed date

    2019-07-09

  • Last modified date

    2019-07-09

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSEP7J","label":"Cognos Business Intelligence"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"B09","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
06 March 2023