IBM Support

Fix packs for DataPower Gateway 10.0.1.x

Download


Downloadable File

File linkFile sizeFile description
   
   
   
   
   

Abstract

Lists of fixes in IBM DataPower Gateway 10.0.1.x fix packs.

Download Description

Fix packs and firmware images are located in either Fix Central, Passport Advantage, or the Entitled Registry.

In IBM Documentation you can find information about new and changed features, limitations, and restrictions.

For integration with API Connect 10.0.1.x, the DataPower Gateway and API Connect releases must be within one fix pack of each other. For example, API Connect 10.0.1.n runs with DataPower Gateway 10.0.1.n, 10.0.1.n-1, or 10.0.1.n+1.

ATTENTION

10.0.1.9 - The support to process IBM Transformation Extender maps with a binary transform action are no longer included as a feature in the Integration Module and the B2B Module. If your existing configuration contains a processing rule that includes a binary transform action to process Transformation Extender maps, you must download and activate the new Transformation Extender Module. To validate whether you need this new module, export your complete configuration and search each domain configuration file for the tx-map command.

10.0.1.1 - Includes APAR IT34068 that addresses the inability to use keys that are stored on an HSM whether an HSM-equipped appliance or a network HSM. In versions earlier than 10.0.1.1, support for TLS version 1.3 prevented operations that use keys stored on an HSM.

10.0.0.0 - Adds support for TLS version 1.3 that required the following changes.

  • Consider whether these changes impact your environment before you upgrade.
    • FIPS mode is no longer available
    • SSL version 2 is no longer supported
  • When you create new TLS profile, the following changes apply that do not impact existing profiles.
    • TLS version 1.0 is disabled by default for new TLS profiles
    • 3DES ciphers are disabled by default for new TLS profiles
  • In a stylesheet that uses the dp:get-cert-subject extension, an OID that was numeric might now be replaced by its textual equivalent. In 2018.4.1.x, this extension reported the OID as 2.5.4.97, but after upgrade reports this same OID as organizationIdentifier.

Important



10.0.1.19

Release date: 24 April 2024
Last modified: 24 April 2024
Status: Available

APAR
Description
IT44537DATAPOWER MATCH ACTION MIGHT NOT ESCAPE URIS PROPERLY WHEN USING BACKSLASH CHARACTERS
IT45245DATAPOWER MIGHT RESTART WHEN MONITORING GATEWAYSCRIPT FILES FOR UPDATES
IT45298OAUTH CACHE UPDATES EXISTING ENTRIES RATHER THAN CREATE NEW ENTRIES
IT45308DATAPOWER MIGHT RELOAD WHEN TRANSACTIONS HAVE ERRORS AND CONNECTIONS TIME OUT ON MQV9+ OR MQMFT
IT45330API GATEWAY: UNABLE TO GENERATE CORRECT CONFIGURATIONS IF SWAGGER CONTAIN EQUIVALENT CASE-INSENSITIVE PATHS
IT45355UPDATE OPENSSL LIBRARY TO ADDRESS CVE-2023-567
IT45357UPDATE OPENSSH LIBRARY TO ADDRESS CVE-2023-48795
IT45514DATAPOWER RELOADS WHEN USING A LONG CONTEXT VARIABLE NAME WITH MANY DOT CHARACTERS
IT45515API GATEWAY REJECTS CALLS WHEN A HEADER NAME STARTS WITH '-'.
IT45542APIC ASSEMBLY FUNCTION ALLOWS DUPLICATE PARAMETER NAMES
IT45570DATAPOWER MIGHT RESTART WHEN HANDLING IMS HEALTH CHECKS
IT45582DATAPOWER MIGHT RESTART WHEN LOGGING TLS ERROR
IT45664DATAPOWER MQ TLS SNI SETTING NOT TAKING EFFECT
IT45666DATAPOWER MIGHT RESTART IF CLUSTER-BASED GATEWAY PEERING IS MODIFIED WHILE A PREVIOUS MODIFICATION IS BEING PROCESSED
IT45668UPDATE OPENSSH LIBRARY TO ADDRESS CVE-2023-48795
IT45669UPDATE OPENSSL LIBRARY TO ADDRESS CVE-2024-0727
IT45699GATEWAY EXTENSION PUSH WITH POLICY TYPE DP-IMPORT DOES NOT UPDATE THE CHANGES.
IT45742DATAPOWER MIGHT RELOAD WHEN SENDING MESSAGES FROM IDGMQ URL-OPENER HAS ERRORS.
IT45743DATAPOWER RELOADS WHEN MQV9+ HANDLER WITH ENABLED PARSE PROPERTIES AND THE RECEIVED MESSAGES EXCEEDS 16 KB
IT45764AN EBMS MESSAGE PROCESSING ERROR IS GENERATED WHEN STRICT COMPILE OPTION IS ENABLED
IT45769ERROR:14094417:SSL ROUTINES:SSL3_READ_BYTES:SSLV3 ALERT ILLEGAL PARAMETER
IT45773FLOAT IS ROUNDED DURING DEEP COPY OF JSON
IT45774MEDIUM SEVERITY VULNERABILITY IN GOLANG(CVE-2023-45289)
IT45777MEDIUM SEVERITY VULNERABILITY IN GOLANG CRYPT/X509 (CVE-2024-24783)
IT45787DATAPOWER MIGHT RESTART WHEN GENERATING A DOMINO-STYLE LTPA TOKEN
IT45820ERROR LOG SHOWS 2053 Q_FULL BUT FOUND THE MESSAGE IS NOT STAYED IN SYSTEM UNTIL IT COULD BEEN BACKOUT.
IT45829DATAPOWER HTTP/2 SERVER THROWING TLS ERRORS UNEXPECTEDLY
IT45830REMAINING ASSEMBLY COUNT LIMIT MIGHT GET UNSYNCED IF CLUSTER-MODE GATEWAY-PEERING IS USED FOR RATELIMIT
IT45833MEDIUM SEVERITY VULNERABILITIES IN GOLANG
IT45853DATAPOWER B2B AS4 SERVICE VARIABLES ARE NOT AVAILABLE IN B2B GATEWAY
IT45866UPGRADE OF A MULTI-GATEWAY CLUSTER TO 10.5.0.9 OR HIGHER MIGHT FAIL TO PERFORM CLOUD UPGRADE
IT45869QUOTA ENFORCEMENT CANNOT DELETE RATE LIMIT KEY WHILE CLUSTER-MODE GATEWAY PEERING IS USED
IT45899APIC NESTED V5C SWITCH POLICY WITH AN EMPTY OTHERWISE CLAUSE FAILS TO LOAD.
IT45930DATAPOWER MIGHT RESTART WHEN MIGRATING XSLT MANUALLY FROM APIC V5
IT45944ADDRESS LOW SEVERITY VULNERABILITY IN OPEN VM TOOLS (CVE-2023-20867)

10.0.1.18

Release date: 1 March 2024
Last modified: 1 March 2024
Status: Available

APAR
Description
IT44150GW SERVICE RESTART DURING A DRR CAUSES CLEARING ISSUE WITH EXTENSION DEPLOYER
IT44405DATAPOWER ON CONTAINER PLATFORM CANNOT DECRYPT MASKED PASSWORDS
IT44823DATAPOWER MQ V9+ QUEUE MANAGER MIGHT FAIL WITH MQRC_SSL_INITIALIZATION_ERROR (RC 2393)
IT44917DATAPOWER SIDECAR MIGHT NOT SHUTDOWN CORRECTLY CAUSING A SYSTEM RELOAD
IT44959SUPPORT MESSAGE PROPERTIES IN AS4 USER MESSAGES
IT44975KAFKA HANDLER IS IN SLOW PERFORMANCE AFTER THE QUEUE IS EMPTY
IT45008MPGW MQ CANNOT SET RESPONSE HEADER THROUGH XSLT OR GWS PROPERLY
IT45032USE OF RSA-PSS VERIFICATION MIGHT CAUSE THE DATAPOWER APPLIANCE TO RESTART.
IT45057APIGW RELOAD WHEN MULTIPLE GATHER-AND-SEND LOG POLICIES ENFORCED
IT45086DATAPOWER COULD EXPERIENCE AN ABRUPT RELOAD IF V5E IN APIC V10 IS APPLIED.
IT45129APIGW RESPONSE CACHE STOPS WORKING AFTER CACHING INITIAL REQUEST
IT45132DATAPOWER MIGHT NOT RELEASE ALL MEMORY WHEN USING HTTP/2 PROTOCOL HANDLER
IT45133APIC USER DEFINED POLICY UPLOAD MIGHT FAIL IF FILES SECTION ISEMPTY
IT45134APIC GATEWAYSCRIPT MIGHT NOT RELEASE ALL MEMORY WHEN WRITING TO SESSION OUTPUT WHEN USING APIM MODULE
IT45144APIC GATEWAY SERVICE DOES NOT COME UP DUE TO PASSWORD
IT45159DATAPOWER MEMORY USAGE GROWTH WHEN ACCEPTING HTTP/2 TRAFFIC AS THE SERVER
IT45180DATAPOWER LDAP CONNECTION POOL ENTRIES PAGE SHOWS INCORRECT PORT NUMBER
IT45214DATAPOWER MIGHT RESTART WHEN COMPILING AN INVALID JSV
IT45227API SWAGGER FILE MAY BE DELETED WHEN THE API CONNECT GATEWAY SERVICE IS RESTARTED.
IT45254DATAPOWER MIGHT RESTART AFTER CLI COMMAND FLUSH-ANALYTICS-ENDPOINT-BUFFER
IT45321DATAPOWER MIGHT RESTART WHEN HANDLING LDAP HEALTH CHECKS
IT45323MEDIUM SEVERITY VULNERABILITY IN NODE.JS MSGPACKR MODULE (CVE-2023-52079)
IT45337MEDIUM SEVERITY VULNERABILITY IN IBM JRE (CVE-2023-22081, CVE-2023-5676)
IT45340OAI3 FORM DATA IS NOT BEING RECOGNIZED
IT45341FOR OAI3, THE PRODUCES AND SOAPELEMENTNAME CONFIG INFORMATION IS GENERATED INCORRECTLY
IT45347WHEN USING PIV AUTHENTICATION LOGIN AND LOGOUT BEHAVIOR PREVIOUSLY LOOPED
IT45359MQV9 HANDLER CANNOT GET THE CORRECT SIZE OF THE PARSED INPUT MESSAGE VIA VAR://SERVICE/INPUT-SIZE
IT45367MEDIUM SEVERITY VULNERABILITY IN GO (CVE-2023-39326)
IT45368DATAPOWER UNEXPECTEDLY RESTARTS AFTER DELETING DOMAIN WITH AMQP HANDLER
IT45387APIC RATE LIMIT DATA MIGHT NOT DISPLAY CORRECTLY IN STATUS PROVIDER
IT45393APIC GATEWAY PEERING IN CLUSTER MODE CANNOT USE STRICT RATE LIMIT POLICY
IT45402APIC GATEWAY SERVICE FAILS TO START IF DOMAIN NAME IS JUST A NUMBER
IT45404APIC LOG POLICY NOT BEHAVING CORRECTLY
IT45406DATAPOWER DOMAIN CANNOT BE DELETED AFTER APIC CONFIGURATION IS LOADED
IT45441APIC CUSTOM POLICY DEPLOY FAILURE LEADS TO CONFUSING ERRORS IN LOG
IT45455APIGW DOES NOT PROCESS MULTIPART MESSAGE WITH BAD BOUNDARY CORRECTLY
IT45495DATAPOWER AND APIC GATEWAY VULNERABILITY IN JRE CVE-2024-20952, CVE-2024-20918, CVE-2024-20921, CVE-2023-33850
IT45576CRITICAL SEVERITY VULNERABILITY IN NODE.JS

10.0.1.17

Release date: 8 December 2023
Last modified: 8 December 2023
Status: Available

APAR
Description
IT43302GATEWAY PEERING USING TLS MIGHT LEAK MEMORY
IT43425DATAPOWER KAFKA CLUSTER NAME MUST BE LIMITED TO 60 BYTES OR LESS INCLUDING THE DOMAIN NAME
IT44179ORIGINAL URL IN REDIRECT EI FLOW SHOULD RETURN DOMAIN NAME
IT44212ALLOCATED MEMORY DOES NOT MATCH CONFIGURED MEMORY FOR A TENANT
IT44514DataPower GatewayScript indexOf and lastIndexOf functions fail on a Buffer object
IT44538DATAPOWER MIGHT UNEXPECTEDLY RELOAD WHEN COMPLETING A DISPATCHED TASK
IT44544TENANT MANAGEMENT INTERFACES MIGHT BE INACCESSIBLE AFTER A SECURE RESTORE
IT44732APIC PARAMETER INLINE VARIABLE SUBSTITUTION MIGHT NOT RELEASE ALL MEMORY USED
IT44752WRONG PAYLOAD MIME TYPE IN OUTGOING EBMS3 GZIP MESSAGES
IT44766DATAPOWER MIGHT RESTART WHEN USING HTTP/2
IT44768DUPLICATE X-GLOBAL-TRANSACTION-ID HEADER RESPONDED TO THE CLIENT IF IT EXISTS IN THE REQUEST HEADER
IT44788GRAPHQL INCORRECT ARGUMENT TO BACKEND SERVER
IT44799APIM.SETVARIABLE FUNCTION FAILS WHEN THE VALUE IS THE RESULT OF A QUERYSTRING.PARSE FUNCTION
IT44803FIX THE RATELIMIT TOKEN FROM LAST INTERVAL TO CONSUME THE LAST REMAINING INSTEAD OF REJECTING.
IT44822DATAPOWER MIGHT RESTART IF ASSEMBLY LOG ACTION DOES NOT SPECIFY A LOG LEVEL
IT44826DATAPOWER MIGHT RELOAD WITH HTTP CLIENT TRAFFIC
IT44843APIC GATEWAY EXTENSION OR POLICY ZIP CREATED ON WINDOWS OS CANNOT BE IMPORTED TO THE GATEWAY
IT44844PROBE MIGHT NOT RELEASE ALL MEMORY WHEN STARTED AND THEN STOPPED
IT44845DATAPOWER OR APIC USE OF JSONATA $MATCH FUNCTION MIGHT CAUSE MEMORY GROWTH
IT44846USE OF $APICTX JSONATA FUNCTION MIGHT RESTART DATAPOWER
IT44861USER-DEFINED POLICY IN A MULTI-NODE CLUSTER MIGHT NOT BE ADVERTISED TO APIM
IT44874APIC GATEWAY SERVICE MIGHT LOG INCORRECT ERROR MESSAGES
IT44877DATAPOWER XML PARSER FAILS TO PARSE IF ENTITY REFERENCE HAS SPECIFIC SIZE IN RELATION TO INTERNAL BUFFERS
IT44903API CONNECT API RESULT ACTION MIGHT NOT RETURN ALL MEMORY IF THERE IS AN ERROR DURING THE TRANSACTION
IT44916PAYLOAD/DATA IS GETTING PRINTED IN ACTIVITY LOGS
IT44923MULTISTEP RULE CALLED FROM API GATEWAY CALLRULE FUNCTION DOES NOT PROPAGATE STATUS CODE AND REASON PHRASE
IT44962OAI YAML WITHOUT COMPONENTS SECTION CAUSES TYPEERROR: CANNOT READ PROPERTIES OF UNDEFINED (READING SCHEMAS)
IT44963APIS NOT PUBLISHING AFTER UPGRADE ERROR:  MAXIMUM CALL STACK SIZE EXCEEDED
IT44969DATAPOWER MIGHT RESTART WHEN APIC ASSEMBLY LOG TRIES TO SEND NON-JSON DATA
IT44976TIMING WINDOW WHERE SOMEHOW PUBSUB RUNS PRIOR TO UPDATING THE SNAPSHOT
IT44978GATEWAYPEERINGCLUSTERSTATUS MIGHT NOT RELEASE ALL MEMORY
IT44987POLICYTITLE PROPERTY OF ERROR OBJECT DOES NOT HAVE VALUE IN GLOBAL ERROR RULE
IT44988DATAPOWER STORE:ENCRYPT/DECRYPT.XSL FAILS TO COMPILE WHEN STRICT COMPILE OPTION IS SELECTED
IT44991DATAPOWER AS4 MESSAGE WITH ENCRYPTED PAYLOAD IN SOAP BODY MIGHT FAIL TO DECRYPT ACCORDING TO SPECIFICATION
IT44992MODIFYING DATAPOWER GATEWAY PEERING OBJECTS MIGHT NOT CLOSE ALL EXISTING CONNECTIONS LEADING TO UNEXPECTED ERRORS
IT45033RESTARTING APIC-GW-SERVICE OR CHANGING ANALYTICS WHILE CATALOG UPDATES ARE PROCESSING MIGHT CAUSE UPDATES TO BE LOST
IT45034MEDIUM SEVERITY VULNERABILITY IN NODE.JS (CVE-2023-38552, CVE-2023-39333)
IT45065LOW SEVERITY VULNERABILITY IN REDIS (CVE-2023-45145)
IT45068MEDIUM SEVERITY VULNERABILITY IN NET-SNMP (CVE-2022-44792, CVE-2022-44793)
IT45493DATAPOWER B2B GATEWAY CPA FILE IMPORT FAILS DUE TO ADD AND WRITE PERMISSION

10.0.1.16

Release date: 25 October 2023
Last modified: 25 October 2023
Status: Available

APAR
Description
IT44026GETTING ENTRIES IN THE FAILURE NOTIFICATION STATUS WITH REASON CRASH AFTER UPGRADE TO 10.0.1.13.
IT44141API CONNECT GATEWAY SERVICE MIGHT RESTART IF MISCONFIGURED
IT44196API GATEWAY MIGHT RETURN UNEXPECTED 404 ERRORS FOR SOAP 1.2 REQUESTS
IT44360XPATH ROUTING MAP DOES NOT LOG CORRECTLY
IT44427DATAPOWER MIGHT RESTART IF DNS REQUEST HAS A TIMEOUT
IT44438API GATEWAY MIGHT NOT RETURN VALID SOAP ERROR RESPONSES FOR FAILED SOAP REQUESTS
IT44453URL SHOULD NOT BE ESCAPED IN ASSEMBLY-USER-SECURITY ACTIONS PROPERTIES
IT44461DATAPOWER MIGHT RESTART WHEN GENERATING ERROR REPORT ON STARTUP
IT44470IDG-X3 TEST HARDWARE COMMAND DID NOT SHOW POWER SUPPLY FAILURE
IT44481DATAPOWER TLS SNI SERVER OBJECT DOES NOT USE CORRECT CIPHER SUITES
IT44487WSDL ZIP ERROR
IT44507APIC ENCRYPTED PROBE DATA NOT RECORDED WHEN CERTIFICATE NAME IS SPECIFIED WITHOUT NAME PREFIX
IT44509FOR API GATEWAY SOAP REQUESTS MIGHT FAIL WITH 404 ERRORS BECAUSE DOCUMENT SIZE LIMIT EXCEEDS IN THE API ROUTING ACTION
IT44515IN A MULTI-GATEWAY CLUSTER, A COLLECTION MIGHT BE ERRONEOUSLY DELETED FROM ONE GATEWAY
IT44543GATEWAY PEERING SWITCH PRIMARY COMMAND MIGHT NOT RETURN MESSAGE FOR GATEWAY PEERING WHEN IN CLUSTER MODE
IT44557APIC RATE LIMIT MIGHT THROW UNEXPECTED RATE LIMIT EXCEEDED ERRORS
IT44558DATAPOWER MIGHT RELOAD WHILE A CSPPASSWORDALIAS IS CONFIGURED FOR A MQ V9+ QUEUE MANAGER
IT44580SUPPORT NULLABLE ENFORCEMENT IN OAI3.0 IN APIM/APIC
IT44588UPDATE GO LIBRARY TO 1.20.8
IT44591API GATEWAY TEMPORARILY LOSES ASSEMBLY RATE/BURST LIMITS ON PUBLISH OR CONFIGURATION CHANGE
IT44605DATAPOWER EXTENSION FUNCTION DP:AUTH-INFO SHOULD INDICATE IF NO CERTIFICATE WAS PRESENTED IN RESULT XML NODE
IT44650DATAPOWER MIGHT RESTART DURING INSTALLATION WIZARD IF SHELL DISCONNECTS
IT44665DATAPOWER KEYGEN CLI COMMAND USES WRONG DEFAULT FOR SHA DIGEST
IT44716POTENTIAL DENIAL OF SERVICE VULNERABILITY IN OPENSSL (CVE-2023-4807)
IT44720MULTIPLE SECURITY ISSUES IN SECURE GATEWAY CLIENT
IT44748RAPID RESET DDOS VULNERABILITY (CVE-2023-44487 & CVE-2023-39325)
IT45049DATAPOWER SENDS GRAPHQL JSON PAYLOAD WITH AN ADDITIONAL KEY "OPERATIONTYPE", WHICH IS NOT TO THE STANDARD

10.0.1.15

Release date: 30 August 2023
Last modified: 30 August 2023
Status: Available

APAR
Description
IT42195MISSING HTTP CONTENT-SECURITY-POLICY RESPONSE HEADER IN WEBGUI
IT42964DOMAIN AVAILABILITY FEATURE DELAYS DOMAIN STARTUP FOR 1 MINUTE EVEN WHEN DISABLED
IT43003DataPower might leak memory when the probe is enabled
IT43809ADD SAMESITE ATTRIBUTE TO THE CSRFTOKEN COOKIE
IT43870THE APPLIANCE COULD BE RELOADED WHEN THE MQ-QM IS SHUT DOWN DUE TO NETWORK ERRORS, AND A NEW MQ CONNECTION IS INITIALIZED.
IT43925DATAPOWER GWS CANNOT FIND DEPENDENCY
IT43927DATAPOWER PARAMETERS DUPLICATE IN USER AGENT FOR BASIC AUTH CAUSING LARGER CONFIGURATION AND OVERHEAD
IT43943THE VARIABLE SUBSTITUTION DOES NOT CURRENTLY CHECK THE REPLACEMENT VALUE TO DETERMINE IF THERE ARE VARIABLES INSIDE OF IT
IT43995API GATEWAY DOES NOT RETURN RESPONSE BODY FROM BACKEND FOR REQUESTS WITH OPTIONS METHOD
IT44115DATAPOWER SSHD TASK ENCOUNTERED CHANNEL ERROR.
IT44126PARSE OAUTH REQUEST SCOPE VALUES FOR EXTRA WHITESPACES
IT44143C org creating incorrectly drives config sequence execution
IT44145ADD FRAME-ANCESTORS: SELF DIRECTIVE IN CONTENT-SECURITY-POLICY
IT44165APIC API ROUTING WILL FAIL IF URI IS ENCODED BUT THE API PATH IS NOT
IT44208API GATEWAY : UNABLE TO USE THE OAUTH SHARED SECRET FOR REGISTERING A GATEWAY SERVICE SET IN THE API MANAGEMENT SERVERS CLOUD
IT44231CERTIFICATE MISMATCH ERROR IN DATAPOWER LOGS
IT44237MQ OBJECT IS DOWN WHEN 20-LENGTH MQCHANNEL NAME IS SET
IT44240WSDL APIS THAT ARE SINGLE FILES MIGHT TRIGGER API GATEWAY UPDATES EVEN IF UNCHANGED
IT44255CONTINUOUS INCREASE IN MEMORY UTILIZATION AND NOT COMING DOWN.
IT44257KAFKA DP:URL-OPEN USING KEY PARAMETER MIGHT RESTART DATAPOWER
IT44262GATEWAY PEERING OBJECT CANNOT BE ASSIGNED TO ANYTHING ELSE AFTER BEING ASSIGNED TO PROBE-SETTINGS
IT44280APIC WEBHOOKS CANNOT BE PROCESSED EVEN AFTER MISCONFIGURATION IS CORRECTED
IT44281DATAPOWER MQ CLIENT ADDS SUPPORT FOR TLS 1.3 CIPHERS
IT44293APIC GATEWAY PEERING GROUP WHEN IN CLUSTER MODE SHOULD NOT BE OPERATIONAL STATE UP IF PEER IP ADDRESSES ARE DUPLICATED
IT44338DATAPOWER QUOTA ENFORCEMENT KEYS MIGHT NOT BE REMOVED AFTER SERVER IS MODIFIED/RESTARTED
IT44339APIC GATEWAY SERVICE MIGHT LEAK TEMPORARY FILES IF FILESYSTEM IS FULL
IT44340APIC ASSEMBLY FUNCTION MAY BE IN OPERATIONAL STATE UP EVEN IF PARAMETERS ARE MISCONFIGURED
IT44341APIC DEVICE MIGHT RESTART WHILE ROUTING A REQUEST IF API DEFINITION IS MISSING ASSEMBLY
IT44351USE OF JAEGER TRACING CAUSES V5 EMULATED POLICIES TO FAIL
IT44381DATAPOWER FORCES CLOUD POLICY UPDATE.
IT44383SUBSCRIPTION LOSS AFTER UPDATES.
IT44630CREATING APIC PROBE CAPTURE SETTING MIGHT RESTART DATAPOWER
IT44654UPDATE NODE.JS TO ADDRESS MULTIPLE CVES
IT44649DENIAL OF SERVICE VULNERABILITY IN NODE SEMVER PACKAGE (CVE-2022-25883)

10.0.1.14

Release date: 28 June 2023
Last modified: 28 June 2023
Status: Available

APAR
Description
IT39216DATAPOWER ON DOCKER DOES NOT SAVE SNMP COMMUNITIES OR CUSTOM WEBGUI USER AGENT
IT41799ZE IT41039 FIX APAR - RELOAD MIGHT OCCUR WHEN URLOPEN HAS INCORRECT ENDPOINT SYNTAX
IT43107CANNOT DELETE PASSWORD MAP OR CRYPTO KEY OBJECT WHEN THE SSH CLIENT PROFILE ASSOCIATED WITH IT IS DELETED
IT43125HTTP2 BASED CLIENTS USING AN EXPECT HEADER WITH A VALUE OF 100-CONTINUE CAN CAUSE RELOAD
IT43150APIC GATEWAY MIGHT RESTART WHEN USING API DEBUG PROBE AND A GATEWAYSCRIPT ASSEMBLY IN THE GLOBAL ERROR RULE
IT43251APIC DURING DRR WITH A LARGE AMOUNT OF CATALOGS, THERE MIGHT BE A TEMPORARILY INCONSISTENT CATALOG LIST
IT43409SELF BALANCING MIGHT FAIL TO REGISTER ALL CONFIGURED DATAPOWERS AND SERVICE.
IT43445DATAPOWER USER ACCOUNT IS NOT LOCKED WHEN WRONG PASSWORD IS USED TOO MANY TIMES
IT43506FORMAT OF CONTEXT VARIABLE OAUTH.VERIFIED_ACCESS_TOKEN.NOT_BEFORE IS NOT CORRECT.
IT43513APIC GATEWAY MIGHT RESTART WHEN GATEWAYSCRIPT THROWS AN ERROR SETTING MESSAGE HEADERS
IT43524ANALYTICS ENDPOINT MIGHT GO DOWN AND FAIL TO COME BACK UP
IT43593CONTEXT VARIABLE REQUEST.URI RETURNS INCORRECT URL IF USING HTTP2
IT43595V5 EMULATION FRAMEWORK FAILS IF A MESSAGE HEADER HAS A NULL VALUE
IT43640DATAPOWER BOOT SWITCH FAILS WITH ERROR: SECONDARY INSTALL NOT AVAILABLE
IT43641COMPILATION OF XSLT WHICH USE DPFUNC:ZULU-TIME BY AN XML MANAGER WITH COMPILE OPTIONS POLICY MIGHT FAIL.
IT43681DATAPOWER HTTP/2 DOES NOT ALLOW USER TO SET THE :AUTHORITY HEADER
IT43703DATAPOWER X2/X3 DEVICE MIGHT HAVE UNUSUAL LATENCY WHEN USING DOCUMENT CACHE
IT43729APIC REQUEST USING TRACE METHOD MIGHT BE ROUTED INCORRECTLY
IT43730APIC SCOPE HANDLING REGRESSION IN V10.0.1.8 AND V10.5.0.X
IT43755VALIDATE POLICY FAILS TO FIND CORRECT WSDL
IT43769DATAPOWER RELOADS WHEN THE AMQP CLIENT STARTS
IT43773DATAPOWER MIGHT RESTART WHEN UNABLE TO CALCULATE LOGGING TIMESTAMP
IT43813AMQP CONNECTION HANDLING CAUSES UNEXPECTED RELOAD ON DATAPOWER
IT43814IN APIGW APIM.GETVARIABLE(REQUEST.PARAMETERS) SHOULD NOT RETURN PARAMETERS WHICH LOCATION IS HEADER
IT43839TOPIC STRINGS GREATER THAN 48 CHARACTERS LONG DO NOT WORK WITH DATAPOWER MQ V9+ CLIENT.
IT43850CHILD ELEMENTS MIGHT BE MISSING FROM RECEIPT WHEN PROCESSING AN AS4 MESSAGE WITH A ONE-WAY/PUSH MEP EXCHANGE
IT43852APIC GATEWAY RESTART WHEN REPARSING NESTED JSON COMPONENT
IT43853DATAPOWER MIGHT RESTART WHEN STARTING GATEWAY PEERING WITH MONITOR-PORT OR LOCAL-PORT ALREADY IN USE
IT43871APIC-GW-SERVICE IS IN PENDING STATE.
IT43873DATAPOWER MIGHT GENERATE UNRELATED ERROR MESSAGES IF AN SNMP QUERY IS MADE ON AN INVALID OR UNLICENSED OBJECT
IT43890INVOKE_1.5.0 AND PROXY_1.5.0 POLICIES SHOULD NOT ATTEMPT TO PARSE A MULTIPART RESPONSE BODY
IT43891ZE IT43288 FIX APAR - DATAPOWER HTTP/2 CLIENT MIGHT RESTART DEVICE WHEN UNDER LOAD
IT43899DATAPOWER OAUTH PROVIDER OPTIONS NOT DISPLAYING CORRECTLY IN UI
IT43900DATAPOWER HTTP/2 SERVER MIGHT RESTART
IT43907APIGW DEBUG PROBE TEMPORARY FILE TEMPORARY://APIGATEWAY-TID_*, IS NOT DELETED AND PILL UP
IT43915APIGW ASSEMBLY FUNCTION PARAMETER SUBSTITUTION CANT GET A DECODED VALUE
IT43917DPOD LOG DOES NOT SHOW SPACE NAME AS API DEBUG PROBE DOES
IT43919TLS PROFILES AT ORG AND CLOUD LEVEL MIGHT COLLIDE
IT43924APIC GATEWAY SECONDARY PEER NOT RESET
IT43931IBM DATAPOWER WEB UI IS NOT STABLE
IT43933POTENTIAL DENIAL OF SERVICE VULNERABILITY IN OPENSSL (CVE-2023-2650)
IT43935APIC JWT VALIDATE ISSUER CLAIM DOES NOT RESOLVE VARIABLE.
IT43980PROBLEM WITH PREFLOW GLOBAL POLICY IN V10
IT44028ADDRESS FALSE-POSITIVE VULNERABILITY FINDINGS REPORTED BY SCAN UTILITIES
IT44112TIMING SIDE-CHANNEL IN GSKIT (CVE-2023-32342) FOR DATAPOWER
IT44114PROVIDE MITIGATION FOR MULTIPLE CVES

10.0.1.13

Release date: 26 April 2023
Last modified: 26 April 2023
Status: Available

APAR
Description
IT39416WEB APPLICATION FIREWALL INCORRECTLY BLOCKS ALL JSON TRAFFIC IF SQL INJECTION FILTERING IS ENABLED FOR A REQUEST PROFILE
IT41761DATAPOWER DOMAIN RESTART OR CONFIGURATION CHANGE MIGHT CAUSE SLM PEERING HASH ERRORS
IT42607LUNA HSM GROUP REMAINS DOWN AFTER STARTUP
IT42681GATEWAY POD FAILS READINESS CHECK AFTER RESTART WHEN FILESTORE EXTENSION IS REMOVE OR UPDATE
IT42988UNDOCUMENTED XSLT EXTENSION FUNCTION SIMPLEDATEFORMAT.FORMAT MIGHT RELOAD DATAPOWER
IT43070API FAILS IF REDACT 1.5 POLICY PARSE FAILS
IT43083DATAPOWER HTTP/2 CLIENT THROWS A TIMEOUT ERROR WHEN BACKEND SERVER PUTS ENDSTREAM FLAG IN HEADER FRAME.
IT43095DATAPOWER MIGHT RELOAD WHEN MEMORY CORRUPTION/EXHAUSTION OCCURS FROM AN MQ LIBRARY
IT43121ERROR RELATED SERVICE VARIABLES NOT SYNC WITH APIGW ASSEMBLY CONTEXT ERROR OBJECT IN V5E MODE
IT43122DataPower might unexpectedly reload after recommitting a routed API Path
IT43137INVOKE 1.5 IS NOT ENCODING PARAMETERS LIKE V5 DID
IT43155B2B GATEWAY PARSING ERROR FOR COMPRESSED MESSAGE
IT43156FOR APIGW THE CONTEXT VARIABLE CLIENT.APP.METADATA IS MISSING IN THE OAUTH FLOW
IT43157DataPower might restart under load
IT43161TLS PROFILES MIGHT FAIL TO SET TLSV1.3 CIPHERS IN SOME CASES.
IT43168APIM COMPATIBILITY MODULE FUNCTIONS ISJSON AND ISXML MIGHT FAIL
IT43202CERTAIN OBJECTS MIGHT NOT BE ABLE TO BE DELETED AFTER BEING USED BY GATEWAY PEERING OBJECT
IT43223APIC CANNOT DYNAMICALLY RECONFIGURE THE API CONNECT GATEWAY FROM THE API MANAGER
IT43232APIC RATE LIMIT REMAINING COUNTER MIGHT NOT BE CORRECT IF RATE LIMIT GATEWAY PEERING IF DOWN
IT43234APIC GLOBAL ERROR RULE MIGHT RESTART GATEWAY
IT43245DOWN TO ONE GATEWAY, QUORUM RECOVERY MIGHT CLEAR THE SUBSCRIPTION CACHE, RESULTING IN 401s FROM ALL APIS
IT43246Recovery of the peering quorum might result in 401s from all APIs on all gateways
IT43253APIC ACTIVITY LOGS MIGHT BE LOST WHEN USING THE ASSEMBLY LOG ACTION
IT43254APIC GATEWAY MIGHT RESTART IF SET VARIABLE POLICY USED TO SET A HEADER ON A NEW CONTEXT
IT43257DATAPOWER MQ V9 CLIENT MIGHT CAUSE A RESTART UNDER HEAVY LOAD
IT43264RATE LIMITS MIGHT PRODUCE INVALID 429 RATE LIMIT RESPONSES
IT43288DATAPOWER HTTP/2 CLIENT MIGHT RESTART DEVICE WHEN UNDER LOAD
IT43292DATAPOWER AMQP HANDLER WILL CYCLE STATE REPEATEDLY IF MISCONFIGURED
IT43298APIGW DOES NOT INCLUDE X-POST-BODY-IN HEADER WHEN CALLING THE AUTHENTICATION URL IN AN USER SECURITY ACTION
IT43318APIGW INVOKE ASSEMBLY ACTION CAN LEAK MEMORY IF RESPONSE IS SOAP ERROR
IT43331V5 EMULATION FRAMEWORK FAILS WHEN A CONTROL CHARACTER IS PRESENT IN THE API
IT43332V5 EMULATED POLICY IN A GLOBAL POLICY OUTPUTS INCORRECT RESPONSE PAYLOAD AND HTTP STATUS CODE
IT43340PLAN.SPACEID IS NOT AVAILABLE IN THE V5C CONTEXT
IT43358DATAPOWER HTTP/2 CLIENT TIMEOUT WHEN RST_STREAM FLAG IS RECEIVED
IT43359APIC SUBSCRIBER CACHE MIGHT GROW IN MEMORY FOR CERTAIN ERRORS
IT43360DATAPOWER MIGHT RESTART IF PASSWORD ALIAS IS REPEATEDLY MODIFIED IN A SHORT PERIOD OF TIME
IT43363DATAPOWER HTTP/2 PROTOCOL HANDLER MIGHT NOT CLEANUP STREAM IF GET REQUEST HAS CONTENT-LENGTH HEADER BUT NO DATA
IT43379APIC GATEWAY-PEERING-CLUSTER-REMOVE-STALE-NODE COMMAND MIGHT NOTWORK FOR PRIMARY STALE NODE
IT43389DATAPOWER AMQP HANDLER GOES INTO PENDING STATE WHEN PULLING MESSAGES
IT43390AMQP HANDLER MIGHT CRASH UNDER TRAFFIC
IT43393APIC GATEWAY SERVICE MIGHT LEAK SNAPSHOT DATA
IT43402DATAPOWER MIGHT UNEXPECTEDLY RELOAD WHILE TRYING TO READ A PAYLOAD OVER TLS WITH AN INVALID SESSION ID
IT43421Return the format of free memory in log message 0x804000a1 back to percent
IT43430DATAPOWER RELOAD WHILE ATTEMPTING TO VALIDATE AN INVALID ARGUMENT IN A GRAPHQL QUERY
IT43431APIC GATEWAY PEERING FAILS TO RESTART AND UNABLE TO RECOVER UNDER LOAD
IT43432API CONNECT GATEWAY SERVICE MIGHT NOT USE UPDATED SERVICE PARAMETERS
IT43434DATAPOWER MIGHT RESTART WHEN INTERNAL LIMIT REACHED FOR LARGE NUMBER OF DOMAINS
IT43441DEFAULT CIPHER CONFIGURATION MIGHT NOT PROVIDE PERFECT FORWARD SECRECY
IT43474DB2 CONNECTION ERRORS, DB2 DRIVER UPDATED
IT43475APIC API PATH PARAMETER SETTINGS MIGHT RESTART GATEWAY
IT43487APIC ANALYTICS ENDPOINT DOES NOT RECOVER MEMORY WHEN SENDING TO A KAFKA-CLUSTER THAT IS DOWN
IT43500API CALL MIGHT HANG IF RATE LIMIT GATEWAY PEERING IS DOWN
IT43519APIC PATH REGULAR EXPRESSION DOES NOT CORRECTLY ESCAPE PARENTHESES
IT43551APIC GATEWAY MIGHT RESTART WHEN CHANGING CONFIGURATION UNDER LOAD
IT43572APIC USERDEFINEDPOLICY THAT HAS ONEOF PROPERTY IS NOT GENERATING CORRECT DATAPOWER CONFIGURATION
IT43640DATAPOWER BOOT SWITCH FAILS WITH ERROR: SECONDARY INSTALL NOT AVAILABLE
IT43661ADDRESS VULNERABILITY IN NODE.JS REPORTED IN CVE-2023-23920.

Back to top


10.0.1.12

Release date: 22 February 2023
Last modified: 22 February 2023
Status: Available

APAR
Description
IT41417DATAPOWER MIGHT RESTART WHILE CONFIGURING WEB APPLICATION FIREWALL
IT42057DATAPOWER SLM MIGHT RESTART WHEN PEER GROUP IS MODIFIED
IT42063DATAPOWER SLM EXTENSION FUNCTIONS DP:SLM-SET-THRESHOLD-* MIGHT WATCHDOG IF USED INCORRECTLY
IT42064APIC PARSE ASSEMBLY CONVERTING JSON TO XML CAN RESTART DEVICE IF JSON OBJECT PROPERTY SIZE EXCEEDS INTERNAL LIMITS
IT42421DATAPOWER MIGHT RESTART WHEN APIC PRODUCT PUBLISH
IT42488Unlimited rate limit for operation override not set properly
IT42521APIC GATEWAY SERVICE THROWS ERRORS AFTER SERVICE IS DEREGISTERED FROM THE API MANAGER
IT42524DATAPOWER MIGHT UNEXPECTEDLY RESTART WHEN TAKING A PACKET CAPTURE
IT42538APIC GATEWAY MIGHT RESTART IF TRANSACTION CANNOT COMPLETE
IT42571REFERENCE COUNT PROBLEM IN THE DYNAMIC MQ-QM OBJECT MIGHT CAUSE RELOAD
IT42616APIC JSON TO XML CONVERSION MIGHT NOT RECOVER ALL USED MEMORY
IT42655MIGRATED V5 GATEWAY EXTENSION RULES MIGHT THROW AN EXCEPTION IN SOME CASES FOR THE V10 API GATEWAY
IT42729MORE ERRORS IN THE INTERNAL CONFIGURATION CAN CAUSE DATAPOWER TO THROW 0X8100002E LOG MESSAGES AND ALERTS
IT42733APIC MEMORY GROWTH WHEN APIGW SENDS THE LOG TO ANALYTICS
IT42734DATAPOWER MIGHT RESTART IF PASSWORD ALIAS IS MODIFIED REPEATEDLY DURING DOMAIN RESTART
IT42735POSSIBLE MEMORY GROWTH WHEN GATEWAY PEERING IS CONFIGURED
IT42742DATAPOWER STATUS PROVIDER MIGHT BECOME STUCK SHOWING INCORRECT CPU USAGE VALUE
IT42755CONFIGURATION SEQUENCE ERROR FILES CREATED FOR PASSWORD ALIASES WHEN AN API IS DELETED
IT42804LEAKED GATEWAY TRANSACTIONS
IT42849API GATEWAY MIGHT RESTART WHEN API PROBE IS ENABLED AND A PARSE ASSEMBLY IS RUN ON NONEXISTENT CONTEXT
IT42955GATEWAYSCRIPT URLOPEN.OPEN INSTRUMENTATION MIGHT GIVE INCORRECT CONTENT-TYPE HEADER
IT42978DATAPOWER MIGHT RESTART WHILE GATEWAY PEERING IN CLUSTER MODE IS CONFIGURED WITH ADMIN DISABLED
IT42982DATAPOWER MIGHT RESTART WHILE CONFIGURING A GROUP OF GATEWAY PEER IN CLUSTER MODE
IT42983APIC GATEWAY MEMORY GROWTH WHEN GATEWAY FAILS TO RESEND THE ANALYTICS LOG TO THE SERVER
IT42984CONFIGURING ATTEMPT STREAMING RULE ON DATAPOWER RARELY MIGHT RESULT IN DATAPOWER RESTART WHEN COMPILING A STYLESHEET
IT42987APIGW UDP TYPE DOES NOT ALLOW VERSION WITH . IN THE FILENAME
IT42996PASSING NON-NUMBER $TIME PARAMETER FOR DPFUNC:ZULU-TIME() IN STORE:///UTILITIES.XSL MIGHT CAUSE A RESTART OF DATAPOWER
IT43160UPDATE OPENSSL LIBRARY TO ADDRESS MULTIPLE CVES.

Back to top


10.0.1.11

Release date: 14 December 2022
Last modified: 14 December 2022
Status: Available

APAR
Description
IT40689OAUTH CONTROLLER DOESN'T CORRECTLY HANDLE HEADER FOR MTOM MESSAGES
IT41601"BYTES_SENT" AND "BYTES_RECEIVED" VALUES IN ACTIVITY LOG ARE SOMETIMES INCORRECT
IT41642DATAPOWER MIGHT RESTART DUE TO RACE CONDITION ON HTTP HANDLER
IT41910APIC API GATEWAY MIGHT RESTART IF LOCATION HEADER IS MISSING ON A REDIRECT
IT42076UNABLE TO DELETE AN ASSEMBLY CONTEXT VARIABLE IF ITS PARENT OBJECT DOES NOT EXIST
IT42089DATAPOWER MQ CLIENT TIMEOUTS SEEN WITH USERS OF MQ IMS BRIDGE
IT42162DATAPOWER GATEWAY MIGHT RESTART IF APIC RESTORE INCLUDES VERY LARGE NUMBER OF FILES
IT42249SECURITY FIX FOR JRE (CVE-2022-21626)
IT42255GRAPHQL QUERY CAN HAVE ONLY QUERY, OPERATIONNAME, AND VARIABLES KEYS.
IT42263CLOUD AND CATALOG WEBHOOKS PROCESSED IN PARALLEL CAN RESULT IN CATALOG DELETION
IT42293DATAPOWER MQ CLIENT V9+ SHOWS PENDING STATE WHEN DEPLOYED IN KUEBERNETS ENVIRONMENT.
IT42299DATAPOWER MIGHT RESTART AFTER GATEWAY PEERING IS DISABLED DURING DOMAIN RESTART
IT42336INVOKE_1.5.0 POLICY SUPPORT OF X-IBM-GATEWAY-INVOKE-V4-NOMAP-EMULATION API PROPERTY
IT42356EC CURVES OVER BINARY FIELD WHICH WERE DISABLED ARE NOW AVAILABLE AGAIN
IT42364INVALID GATEWAY PEERING PEER UPDATE LOCK STATE
IT42372"+ (%2)" IN THE QUERY PARAMETER "USERNAME" IS CONVERTED TO "(HALF-WIDTH SPACE)"
IT42375V5 EMULATED UDP FAILS TO RETRIEVE DATA FOR READINPUTAS FUNCTIONS
IT42400DATAPOWER MIGHT RESTART WHEN ADDING/DELETING PASSWORD OR WHEN RESTARTING DOMAIN
IT42406DATAPOWER APIC GATEWAY MIGHT RESTART IF OAUTH REVOKE URL IS UNDEFINED
IT42478APIC API PATH MIGHT BE OPERATIONAL EVEN WITH INVALID CONFIGURATION
IT42479APIC RATE LIMIT BECOMES INCORRECT FOR STANDALONE GATEWAY IF REMAINING IS EXCEEDED BEFORE CACHE IS CLEARED
IT42480FORM-DATA LENGTH ERROR.
IT42483GW MEMORY IS LEAKING WHEN RECOMMIT THE API COLLECTION IF THERE'S RATELIMIT IN THE TRANSACTION
IT42493APIC GATEWAY MIGHT RESTART IF API PATH WITH PARAMETERS IS MODIFIED
IT42510DATAPOWER GATEWAY MIGHT RESTART IF XML MANAGEMENT INTERFACE IS ENABLED WHILE APIC GATEWAY SERVICE IS PENDING
IT42520APIC V5C POLICIES MIGHT FAIL IF V5E POLICIES ARE REMOVED
IT42528COLLECTION MIGHT BECOME DETACHED FROM API GATEWAY
IT42543POTENTIAL REQUEST SMUGGLING VULNERABILITY (CVE-2022-35256)

Back to top


10.0.1.10

Release date: 26 October 2022
Last modified: 18 January 2023
Status: Available

APAR
Description
IT31382EDITING A JSV OR FLUSHING IT FROM CACHE MIGHT RESTART IF IT PROCESSED TRAFFIC EARLIER
IT36173DATAPOWER MIGHT RESTART WHEN ACCESSING THE PEER GROUP FROM AN SLM POLICY THAT NO LONGER EXISTS.
IT38762MQRC_PROP_CONV_NOT_SUPPORTED ERROR WILL OCCUR WHEN DATAPOWER USES IBM MQV9+
IT39395DATAPOWER MIGHT RESTART IF APIC OAUTH IS MODIFIED WHILE PROCESSING API
IT41159DATAPOWER MIGHT RESTART WHEN RUNNING THE SERVICE SHOW COMPONENT-FIRMWARE COMMAND.
IT41163DATAPOWER IBM MQV9+ OBJECTS CANNOT BE CONFIGURED WITH WEB SERVICE PROXY
IT41319DATAPOWER MIGHT RESTART AFTER 2 BILLION MESSAGES ARE LOGGED OVER SYSLOG-TCP
IT41352DATAPOWER UNABLE TO UPDATE HSM FW
IT41394TLS INTERMEDIARY CERTIFICATES MIGHT FAIL TO CLEAN UP IN V5C GATEWAY
IT41459APIGW DOES NOT USE THE LOG LEVEL FROM THE LAST ASSEMBLY LOG ACTION AT THE END OF THE TRANSACTION
IT41521HTTP RESPONSE HEADER SPACE TRUNCATED WHEN REASON PHRASE NOT INCLUDED
IT41551APIC RATE LIMIT INCORRECTLY ENFORCED FOR STANDALONE GATEWAY WHEN CACHE IS CLEARED
IT41552DATAPOWER MIGHT RESTART WHEN DPOD CONFIGURES DEVICE DURING BOOTUP
IT41558DATAPOWER SSH CLI CLIENT LOGIN MIGHT CAUSE SLOW MEMORY GROWTH
IT41600GATEWAY-PEERING INSTANCES LEAK KEYS.
IT41601BYTES_SENT AND BYTES_RECEIVED VALUES IN ACTIVITY LOG ARE SOMETIMES INCORRECT
IT41632IDG-MQ-QM STATUS IS STILL UP EVEN AFTER DISABLING ON MQ SERVER
IT41657POLICY RULE WEBAPI-V5E-POLICY-INVOKE-GSCRIPT FAILED WITH EXCEPTION DUE TO API PROPERTIES WITH NEWLINE
IT41677APIC APIM.GETVARIABLE(OAUTH.MISCINFO) RETURNS UNDEFINED
IT41678MEMORY SPIKES OR OUT OF MEMORY WHEN APIC CATALOGS REFRESHED.
IT41685REMOVE EXTRANEOUS API SCHEMA DEFINITIONS AND DUPLICATES FROM CONFIGURATION
IT41699DATAPOWER MIGHT RESTART WHEN SAVING CONFIGURATION AND NO OBJECTS HAVE BEEN CHANGED
IT41737RATE LIMIT ON API OPERATIONS IN DIFFERENT PRODUCTS MIGHT COLLIDE
IT41741DATAPOWER MIGHT RESTART WHEN INVALID MIME REQUEST SENT TO API GATEWAY
IT41776UPDATE DATAPOWER SECURE GATEWAY CLIENT TO 1.8.8FP1 AND NODE 14.20.0
IT41786APIC UNCAUGHT EXCEPTION IN GATEWAY DIRECTOR WHEN WEBHOOK NOT SET
IT41794APIC DOES NOT ALLOW WILDCARD IN CORS RULE ALLOW-ORIGIN FIELD
IT41801APIC GATEWAY MIGHT RESTART WHEN API IS PUBLISHED
IT41802DATAPOWER MIGHT RESTART WHEN SHOW GATEWAY-PEERING-KEY-STATUS IS EXECUTED
IT41817THE RESPONSE HEADER SET BY HEADER-METADATA WONT PROPAGATE TO THE END OF TRANSACTION IF THERE IS AN INVOKE ACTION
IT41896API COLLECTION CONFIG CREATED AND CONFIGURED BUT IT IS NOT ADDED TO GATEWAY CONFIG
IT41908DATAPOWER MIGHT RESTART WHEN UPDATING PASSWORD_MAP
IT41936APIC API COLLECTIONS MIGHT BE MISSING WHEN AN API IS PUBLISHED WITH UNDEFINED UDP OR OTHER USER ERRORS
IT41963TENANT CANNOT ACCESS PORTS LESS THAN 1024
IT42005DETECT DUPLICATE APIS
IT42051SQL METHOD TO_TIMESTAMP_TZ0 CAUSES DATABASE INSERT FAILURE
IT42060REMOVING TRUSTSTORE FROM TLS CLIENT PROFILE IN APIC IS NOT REFLECTED ON THE DATAPOWER GATEWAY
IT42095APIC PROCESSES UDP FROM SNAPSHOT IN WRONG ORDER
IT42101ON PASSWORD CHANGE, OTHER SESSIONS ARE NOT INVALIDATED (CVE-2022-40228)
IT42104DATAPOWER MIGHT RESTART DURING KERBEROS PROTOCOL TRANSITION
IT42141DATAPOWER MIGHT RESTART WHEN PARSE ACTION USES GRAPHQL DETECTION
IT42165INSECURE OPTION IN TLS CLIENT PROFILE FROM APIM HAS A DIFFERENT BEHAVIOR THAN APIC V5
IT42166IF AN ERROR IS DETECTED IN A PLAN, THE PLAN SHOULD BE DISABLED. PREVIOUSLY THE WHOLE CATALOG WAS DISABLED.
IT42171REDACT_1.5.0 POLICY MIGHT CHANGE THE RETURNED STATUS CODE.
IT42203APIS WITH APPLICATION AUTHENTICATION MISSING PROPERTY AFTER MIGRATION FROM V2018 TO V10
IT42231SECURITY UPDATE TO NODE.JS
IT42234DATAPOWER CANNOT CHANGE ENCRYPTION KEY ALGORITHM FROM THE DEFAULT RSA1_5 TO RSA-OAEP IN THE B2B MODULE
IT42300POTENTIAL CSRF VULNERABILITY IN WEB UI (CVE-2022-31773)
IT42667APIC API PATH ALLOW DOLLAR SIGN IN PATH WITH PATH TEMPLATE

Back to top


10.0.1.9

Release date: 24 August 2022
Last modified: 24 August 2022
Status: Available

APAR
Description
IT38203DATAPOWER USES SNI HOSTNAME FOR HOSTNAME VALIDATION WHEN DISABLED FOR MQ CONNECTIONS
IT40045APIC-GW-SERVICE CAN LOSE CONFIG IN STARTUP CONFIG IF CONFIG SEQUENCE MODIFIES GWD AND USER LATER SAVES
IT40541DATAPOWER MIGHT RELOAD DUE TO API CONNECT ACTIVITY LOG GENERATION
IT40589API GATEWAY TAKING TRAFFIC WHILE CHANGING THE CONFIGURATION CAUSED RELOAD
IT40689OAUTH CONTROLLER DOES NOT CORRECTLY HANDLE HEADER FOR MTOM MESSAGES
IT40721DATAPOWER MIGHT RELOAD WHEN MODIFYING SNMP
IT40765API GATEWAY WEBSOCKET CALL DOES NOT USE PROXY POLICY CORRECTLY
IT40997DATAPOWER MEMORY-REPORT LOGS LIMITED BY 32-BIT REGISTERS AND CANNOT SHOW MEMORY SIZES BEYOND 4294967295
IT41008DATAPOWER API GATEWAY MIGHT RELOAD WHEN PARSE ASSEMBLY RUNS A POST WITH NO DATA
IT41031FOR API GATEWAY, REDACTED DATA IN ASSEMBLY LOG ARE NOT MASKED FOR THE ERROR FLOW WHEN NO ROOT PROPERTY IS DEFINED
IT41039RELOAD MIGHT OCCUR WHEN URLOPEN HAS INCORRECT ENDPOINT SYNTAX
IT41043THE PROBLEMATIC POPULATED PATH VALUE OF DATE AND DATE-TIME TYPES RESULTS IN THE WRONG RESOLVED TARGET URL IN INVOKE
IT41078DATAPOWER MIGHT RELOAD WHEN THE CONNECTIONS ARE TIMED OUT ON MQ V9+
IT41101ENHANCE SYSLOG-TCP LOG TARGETS TO IMPROVE CONCURRENCY THROUGHPUT AND PERFORMANCE
IT41112DATAPOWER FAILS TO PROCESS SQL DATA TYPE VARGRAPHIC INCLUDED IN THE DATABASE CURSOR.
IT41156FOR API GATEWAY WHEN A THIRD-PARTY OAUTH PROVIDER INTROSPECT URL CONTAIN QUERY PARAMETERS, THE QUERY PARAMETERS MIGHT BE TRUNCATED
IT41179SPACE ID IS NOT SET IN ANALYTICS DATA WHEN TWO API PLANS CONTAIN THE SAME API.
IT41246TENANT MEMORY DOES NOT MATCH THE ACTUAL MEMORY ALLOCATED TO A TENANT
IT41262DATAPOWER MIGHT RELOAD WHILE RUNNING API RULES AFTER DISABLING CERTAIN ACTION
IT41307IGNORE-EXPIRATION SETTING IS NOT HONORED TO QUOTA ENFORCEMENT SERVER TLS CONNECTION
IT41310DATAPOWER MIGHT LEAK MEMORY WHEN USING GATEWAYSCRIPT WITH DIFFERENT CONTEXT VALUES
IT41311THE EXTERNAL REVOCATION BASIC AUTH PASSWORD PROPERTY IS GENERATED WHEN ITS REFERENCED PASSWORD ALIAS DOES NOT EXIST
IT41350MTOM ROOT PART BODY TRUNCATED IF INVOKES CHUNKED-UPLOADS SET TO FALSE
IT41377MEMORY LEAK FOR TRANSACTIONS THAT USE MS:CALLRULE() TO CALL AN INVALID OR NONEXISTANT RULE
IT41385API GATEWAY MIGHT NOT BE DELETED DUE TO THE RELATED ANALYTICS ENDPOINT
IT41395IN API GATEWAY THE MECHANISM TO MASK THE CLIENT SECRET VALUE IN ANALYTICS DATA IS CASE SENSITIVE FOR HEADER NAME
IT41401APIC OAUTH TOGGLE AUTH HEADER PASSTHROUGH DELETES AUTHORIZATION HEADER
IT41414DATAPOWER WEB UI MEDIUM SECURITY VULNERABILITY CVE-2022-32750 CVE-2022-31774
IT41419BACKSLASHES REMOVED FROM API DEFINITION ON API GATEWAY BUT NOT WHEN IN V5C COMPATIBILITY MODE
IT41433SECURITY UPDATE TO JRE TO ADDRESS CVE-2021-35561, CVE-2022-21434, AND CVE-2022-21443
IT41442DATAPOWER AMQP CLIENT FAILS TO CONNECT TO EVENT HUB IN AZURE CLOUD ENVIRONMENT.
IT41446SECURITY UPDATE TO ITX TO ADDRESS CVE-2020-10531, CVE-2014-8147,CVE-2014-8146, AND CVE-2017-14952
IT41448V5 CUSTOM POLICIES REGEX CHECK HAS TYPO
IT41450DATAPOWER MIGHT RELOAD WHEN GENERATING ERROR REPORT WHILE FFDC PACKET CAPTURE IS ENABLED
IT41574DUPLICATE OAUTH OBJECTS IN CONFIGURATION CAUSES SLOW PROCESSING OF CATALOG EVENTS

Back to top


10.0.1.8

Release date: 21 June 2022
Last modified: 21 June 2022
Status: Available

APAR
Description
IT36680ENDPOINT REWRITE POLICY IS NOT SHOWN CORRECTLY IN WEBGUI AFTER WSP IMPORT
IT38064DATAPOWER WEBSPHERE JMS SOMETIMES GIVES ERROR 26 CONNECT_FAILED
IT39017RESULTS ACTION WITH "INPUT" AS INPUT CONTEXT AFTER PARSE ACTION WILL RESTART DATAPOWER
IT39614DATAPOWER MIGHT RELOAD WHEN EXECUTING API ASSEMBLY INVOKE
IT39825GATEWAYSCRIPT URLOPEN.OPEN() FOR HTTP/2 FAILS WITH TIMEOUT ERROR
IT40037DATAPOWER MIGHT RELOAD WHEN ROUTING APIC CALL USING SOAP BODY
IT40387APIC V5C: INVESTIGATE IMPROVING TLS DEPLOYMENT FOR CATALOGS
IT40583RAID DIRECTORY IS NOT CREATED FOR LOGSTORE FILES WHEN USING DATAPOWER ON DOCKER
IT40635FAILURE TO LOG TLS KEY DURING PACKET CAPTURE
IT40663FAILED TO SET RESPONSE STATUS CODE IN GATEWAYSCRIPT OF THE CALLED RULE
IT40664ADJUST VAR://SERVICE/MAX-ACTION-DEPTH TO BE A READ/WRITE VARIABLE
IT40753DATAPOWER WS-PROXY MIGHT LEAK QREF WHEN XML PARSING ERROR OCCURS
IT40760SET VARIABLE POLICY DOES NOT WORK FOR XML PAYLOADS
IT40767DATAPOWER MIGHT RELOAD WHEN RUNNING GATEWAYSCRIPT IF MQ QM IS NOT UP
IT40777DATAPOWER MIGHT RELOAD WHEN ADDING OR MODIFYING PASSWORD MAP USED BY B2B
IT40801MULTIPLE SECURITY ISSUES IN SECURE GATEWAY CLIENT
IT40823DP AS4 TRANSACTION COLLECTOR DATABASE ACCESS ERRORS/ AS4 TRANSACTIONS FAILING IN V10.0.1.4
IT40856REQUIRED FORM PARAMETER CHECK COULD FAIL WHEN PROCESSING REQUESTS OF MULTIPART/FORM-DATA TYPE WITH NON-TEXT PAYLOADS.
IT40934REMOTE ACCESS TO DATAPOWER HANGS AFTER INPUTTING COPY COMMAND WITH SCP TARGET
IT40935DATAPOWER DOCKER RAID VOLUME MOUNT POINT MODIFIED
IT40946APIGW CRASHES IN ROUTING WHEN HANDLING THE SOAP WITH ATTACHMENTS MESSAGE
IT40957THROTTLER DOES NOT TRIGGER WHEN MEMORY EXCEEDS CONFIGURED THRESHOLD ON TENANTS
IT40964ADDRESS CVE-2022-24736 & CVE-2022-24735 FOR GATEWAY PEERING AND QUOTA ENFORCEMENT
IT40969SECURITY VULNERABILITY - XML ENTITY EXPANSION IN WEBGUI
IT41091DATAPOWER MIGHT RELOAD WHEN LOGGING SSL ERROR MESSAGES UNDER HIGH LOAD
IT41106APIC GATEWAY SERVICE DOES NOT WORK ON DOCKER DESKTOP 4.X

Back to top


10.0.1.7

Release date: 28 April 2022
Last modified: 28 April 2022
Status: Available

APAR
Description
IT35779API GATEWAY REJECT GET REQUEST WHEN PARAMETER NAME CONTAINS A COLON
IT37659DATAPOWER RAID BATTERY HIGH TEMPERATURE WARNING CAN BE GIVEN INCORRECTLY AT 40 F IN 8441 X2 APPLIANCE
IT38066PING TEST SHOULD ALLOW USE OF HOST ALIAS
IT39549DATAPOWER MIGHT RESTART WHEN HANDLING MULTIPLE MQ SESSIONS
IT39604GATEWAYSCRIPT LOGGING JAVASCRIPT HEAP OUT OF MEMORY WHILE SESSION.OUTPUT.WRITE() CREATES CONSISTENT MEMORY GROWTH
IT39610DATAPOWER MIGHT RESTART WHEN ACTING AS SFTP CLIENT AND SFTP SERVER RETURNS INVALID UTF-8 IN THE FILENAME
IT39663DATAPOWER TENANT MISTAKENLY LOGS CPUS MISSING
IT39746API COUNT LIMIT MAY BE INCORRECT WITH AUTO-DECREMENT ENABLED
IT39795APIC - DELETING GATEWAY EXTENSION MIGHT NOT RESTORE PREVIOUS PARSE SETTINGS
IT39804SYSLOG COMMAND IN CLI DOES NOT FUNCTION AS CLI HELP OUTLINES.
IT39882CONTEXT.MESSAGE.STATUSCODE DO NOT SEND ERROR RESPONSE CODE TO ANALYTICS.
IT39912ERROR REPORT SECTION MEMSTATSBEFORERELOAD MAY NOT REPORT ACCURATE MEMTOTAL IN KUBERNETES ENVIRONMENTS.
IT39926DATAPOWER RMI INCORRECTLY REQUIRES JSON ORDERING FOR CERTAIN ACTIONS
IT39947API CONNECT GATEWAY PEERING OBJECTS CAN HAVE OPERATIONAL STATE UP EVEN WHEN 2 OBJECTS HAVE CONFLICTING PORTS
IT39948DATAPOWER MIGHT RESTART AFTER CORRECTING THE IP ADDRESS FOR GATEWAY PEERING
IT39989ZE APAR IT37691: DATAPOWER MIGHT RESTART WHEN AN API HAS LARGE NAMES FOR THE PATH, API, OR OTHER COMPONENT
IT40034APIC CONNECT GATEWAY SERVICE DOWN WHEN DOMAIN NAME IS LARGE
IT40038DATAPOWER FAILED TO BACKOUT MQ MESSAGE WITH INVALID CHARACTER.
IT40039LOGGED OUT FROM WEBGUI WHILE ATTACHING A POLICY SOURCE IN WS PROXY.
IT40073FAILURE PUBLISHING AN API OR CATALOG IF INCOMPLETE POLICY CONFIGURATION IS ENCOUNTERED
IT40078APIC GATEWAY PEERING OBJECT MAY BE UP EVEN IF AN INVALID IP ADDRESS IS SPECIFIED FOR A PEER OR CLUSTER NODE
IT40079APIC API DEFINITION NEW TOGGLE FOR ALLOW TRAILING SLASH
IT40097INVOKE_1.5.0 AND PROXY_1.5.0 POLICIES GENERATE A PARSE FAILURE FOR HTML RESPONSES
IT40132DATAPOWER MAY RESTART IF APIC REPUBLISHES WHILE API CALLS ARE BEING PROCESSED
IT40139DATAPOWER SOURCE MQ MFT FSH MAY HAVE ERROR WHEN PROCESSING MANY PARALLEL TRANSACTIONS
IT40152DATAPOWER SECURE GATEWAY OBJECT MIGHT GO INTO A PENDING STATE
IT40185DATAPOWER GATEWAY PEERING MAY LEAVE TCP CONNECTIONS IN CLOSE-WAIT STATE
IT40187APIC GATEWAY PROXY POLICY SHOULD APPLY TO ANALYTICS ENDPOINTS
IT40189APIC MEMORY GROWTH WHEN DISABLING MESSAGE BUFFERING AND USING PAYLOAD CONTENT TYPE
IT40264APIGW MIGHT RETURN INCORRECT CONTENT-ENCODING HEADER
IT40321DATAPOWER MIGHT RESTART WHEN CONFIGURING APIC PROBE DURING STARTUP
IT40341API GATEWAY RETURNS UNEXPECTED 404 NOT FOUND ERRORS WHEN REQUEST URL CONTAINS A PIPE CHARACTER IN THE PATH PARAMETER
IT40342GATEWAY PEERING PROCESSES MIGHT NOT BE TERMINATED PROPERLY WHEN CONFIGURATION CHANGES ARE APPLIED
IT40376ZE APAR IT32914: X-FORWARDED-FOR HEADER SHOULD BE SANITIZED FOR CORRECT ANALYTICS DATA
IT40377DATAPOWER RELOADS WHEN GATEWAYSCRIPT PROCESSING ERROR OCCURS DUE TO UNDEFINED VARIABLE
IT40395CLIENT-ID HEADER NOT SENT TO INVOKE_1.5.0 OR PROXY_1.5.0 POLICY BACKEND SERVER IN SOME INSTANCES
IT40420DATAPOWER MAY RESTART WHEN PREPARING TO COMPILE AFTER A CONFIGURATION CHANGE.
IT40500API CONNECT GATEWAY SERVICE MIGHT NOT BE USED SUCCESSFULLY FROM TENANTS
IT40510APIC CALLS ARE LOST OR RETURNED WITH A 404 ERROR MESSAGE AS READINESS OF GATEWAY IS SIGNALED TOO EARLY
IT40518API CONNECT RATELIMIT ASSEMBLY REPLENISH ACTION MIGHT NOT WORK CORRECTLY
IT40531B2B GATEWAY MAY FAIL TO DECOMPRESS RESPONSE WITH MULTIPLE ATTACHMENTS
IT40603PARSE SETTING VALUES ARE NOT WORKING IN APIC V10
IT40640DATAPOWER SQL-EXEC FAILED TO RETRIEVE STORED PROCEDURE RESPONSE
IT41909API CONNECT V10, VALIDATION FAILS DUE TO WHITESPACE IN TLS CLIENT CERTIFICATES

Back to top



10.0.1.6sr1

Release date: 30 March 2022
Last modified: 30 March 2022
Status: Available

APAR
Description
IT39994DATAPOWER GATEWAY POTENTIALLY VULNERABLE TO DOS (CVE-2022-22356, CVE-2022-22355)
IT40053IDG MEMORY GROWTH WHEN USING OAUTH AND API KEY FOR SECURITY
IT40215WHEN A DUPLICATE CATALOG SNAPSHOT IS RECEIVED FROM API MANAGER AFTER DRR IS INITIATED, API CONNECT GATEWAY SERVICE MIGHT NOT CREATE THE CATALOG
IT40243CLIENT SECURITY POLICY MAY NOT DETECT INVALID SUBSCRIPTION
IT40259DURING DRR, API CONNECT GATEWAY SERVICE MIGHT NOT PROPERLY REMOVE CATALOG SNAPSHOT DATA FROM GATEWAY PEERING DATABASE
IT40373POTENTIAL MODULE RESOLUTION ERROR IN GO IN DATAPOWER OPERATOR (CONTAINER ONLY)
IT40394POTENTIAL FLAWS IN NODE (CVE-2021-44532, CVE-2021-44531, CVE-2021-44533)
IT40487HEAP OVERFLOW IN ICU - DFDL (CVE-2020-10531, CVE-2014-8147, CVE-2014-8146, CVE-2017-14952)

Back to top


10.0.1.6

Release date: 21 February 2022
Last modified: 26 July 2022
Status: Available

APAR
Description
IT41431GUI ALLOWS USERS TO VIEW AND EDIT FILES THAT ARE NOT ALLOWED TO BE READ VIA RBM ACCESS RIGHTS
IT36154API CONNECT DATAPOWER GATEWAY MIGHT RELOAD IF THE GATEWAY DIRECTOR CANNOT INITIALIZE
IT36680ENDPOINT REWRITE POLICY IS NOT SHOWN CORRECTLY IN WEBGUI AFTER WSP IMPORT
IT37041V5 API CALLS WITH TRAILING SLASH NOT WORKING WITH V10
IT37575ADD SUPPORT OF MULTIPART/FORM-DATA CONTENT TYPE FOR REQUEST IN API GATEWAY
IT37657THE FIELD RESOURCE_ID INSIDE THE ANALYTICS COMPONENT IS NOT SAVING THE REAL RESOURCE, IT IS ONLY SAVING THE BASE PATH
IT37679MAKE THE DATA BUFFERED AUTOMATICALLY FOR ACTIVITY/ASSEMBLY LOGGING WITH PAYLOAD SETTINGS
IT37787DATAPOWER WEB APPLICATION FIREWALL ERROR POLICY OBJECT CONTAINS INCORRECT CHANGE/MODIFICATION ENTRIES
IT37925ADDRESS CVE-2021-32803 IN NODE-TAR
IT37997CANNOT SAVE THE DATA IN RAID ARRAY WHEN USING DOCKER ON LINUX CONTAINER IMAGE
IT38226API COLLECTION ROUTING PREFIXES NOT UPDATED AFTER V5 LEGACY ENDPOINT IS DISABLED
IT38228ERRORS IN THE INTERNAL CONFIGURATION CAN CAUSE DATAPOWER TO THROW 0X8100002E LOG MESSAGES AND ALERTS
IT38231MEMORY GROWTH WHEN USING GRAPHQL ASSEMBLY
IT38234IF VANITY HOSTNAME IS SAME AS GATEWAY HOSTNAME, /PROVIDER_ORGANIZATION/CATALOG/ SHOULD CONTINUE TO WORK
IT38252APIC API PLAN WITH SPACES IN NAME CANNOT BE PUBLISHED
IT38253DATAPOWER DPMON FILES ARE MISSING FROM ERROR REPORT
IT38254APIGW SHOULD MASK THE VALUE IN AUTHORIZATION HEADER BEFORE SEND TO THE ANALYTICS ENDPOINT
IT38263APIC V5 POLICY FAILS ON API GATEWAY WITH AN XML PARSE ERROR
IT38285DISABLING CSRF HEADER MIGHT IMPACT GUI ACTIONS
IT38301PRECONFIGURED V5 EMULATION POLICIES MIGHT BE REMOVED FROM CLUSTERED DATAPOWER AFTER RESTART
IT38309APIC HTTP/2 API CALL IS MARKED AS FAILED IN PORTAL ANALYTICS WHEN CALL WORKED
IT38368LOADING CERTIFICATES USING ANY ALGORITHM OTHER THAN RSA, DSA, OR ECDSA MIGHT RESTART DATAPOWER
IT38371APIGW RETURN 403 FORBIDDEN ERROR IF SECONDARY CLIENT_ID IS IN THE REQUEST BODY
IT38382WHEN OBJECT SUPPORT IS ENABLED FOR A DATA SOURCE, A DATABASE CALL MIGHT RESULT IN AN ERROR
IT38385APIC GATEWAY EXTENSION NOT APPLIED IMMEDIATELY AFTER DRR
IT38388V5E GATEWAY EXTENSION CLEANUP MIGHT FAIL TO COMPLETE
IT38392DATAPOWER - CANNOT SET CACHE-TIMEOUT TO NO TIMEOUT IN MQ QUEUE MANAGER FROM WEBGUI OR CLI
IT38401APIC API DEFINITION ALLOWS REQUESTS AFTER PUBLISH FAILS DUE TO DUE TO MISCONFIGURATION
IT38427DATAPOWER RESTART IN GATEWAY SCRIPT WHEN USING JWT GENERATOR
IT38480API CONNECT GATEWAY SERVICE MIGHT RELOAD AFTER ADDING TO CLUSTER
IT38550GET ?WSDL REQUESTS WITHOUT SECURITY CREDENTIAL WILL BE REJECTED BY API GATEWAY
IT38554APIC ROLE ASSIGN ACTION NOT TAKEN FOR GATEWAY PEERING AFTER REJOINING CLUSTER
IT38608DATAPOWER MIGHT RELOAD WHEN DOMAIN IS ENABLED AND RELOADED AT THE SAME TIME
IT38657DATAPOWER ISAM CLIENT DOES NOT HONOR DNS TIME TO LIVE (TTL) TIME AS ISAM HOSTNAME IS NOT CACHED.
IT38675DATAPOWER THROTTLE RESTART DUE TO LOW MEMORY AFTER APPLY FIX PACK 16
IT38685PKCS12 ARTIFACTS CONTAINING A CHAIN AND PRIVATE KEY MIGHT NOT BE PARSED CORRECTLY
IT38697APIC OAUTH PROVIDER DOES NOT RETURN CORRECT VALUE IN X-SELECTED-SCOPE
IT38713HTTP VERSION TO SERVER NOT WORKING CORRECTLY IN WEB APPLICATION FIREWALL
IT38715APIC API PLAN RATE LIMITS SORT ORDER ALGORITHM NOT IMPLEMENTED CORRECTLY
IT38717VALIDATE POLICY MIGHT EXPERIENCE LATENCY IN RETRIEVING THE SCHEMA TO USE IN THE VALIDATION
IT38737FOR APIGW UNABLE TO GET THE UDP PROPERTY VALUE BY USING APIM.GETPOLICYPROPERTY()
IT38751NEW APIC CONTEXT VARIABLE FOR THIRD-PARTY LDAP AUTHENTICATION
IT38759DATAPOWER - CANNOT CONNECT SSH CONNECTION FROM SSH CLIENT
IT38763CLIENT IDENTIFICATION CHECK COULD FAIL WHEN NEW VERSION OF API IS CREATED
IT38773DATAPOWER B2B GATEWAY SERVICE SENDS SIGNED AS2 REQUEST WITH S/MIME ENVELOPED DATA INCORRECTLY
IT38774APIC V5 AND V5C ENHANCEMENT TO KEEP PREVIOUS TLS PROFILES IN CONFIGURATION IF APIM CANNOT BE REACHED
IT38775SMALL MEMORY GROWTH WHEN CONFIGURING GRAPHQL SCHEMA OPTIONS IN API PLAN
IT38777APIC REDACT ASSEMBLY ACTION MIGHT RESTART DATAPOWER
IT38778API CONNECT ASSEMBLY MIGHT CAUSE SMALL MEMORY LEAK
IT38779REDACT_1.5.0 POLICY MIGHT CAUSE A 500 RESPONSE WHEN REDACTING LOGS
IT38780INVOKE_1.5.0 POLICY SUCCESSFUL WHEN THE SOURCE V5 POLICY FAILS
IT38781INVOKE_1.5.0 POLICY MIGHT FAIL WHEN THE SOURCE V5 POLICY SUCCEEDS
IT38782AMU MIGRATED APIS WITH AN INPUT PARSE IMPLICITLY WRAPPED WITHIN A SWITCH
IT38784API CONNECT V5C RESPONSE TO OAUTH AUTHENTICATION MIGHT BE INCORRECT
IT38838MAP POLICY MIGHT BE CASE SENSITIVE FOR HEADER NAMES WITH SOME USE CASES
IT38844RETURN THE PERCENTAGE MEMORY FREE FIELD TO USE MEMORY FREE IN THE THROTTLER USAGE LOG 0X804000A1 MESSAGES
IT38873APIC V5 COMPATIBILITY MODE RETURNS NULL FOR APIM.GETVARIABLE(REQUEST,BODY) FOR A GET REQUEST
IT38891DATAPOWER MIGHT RELOAD IF HTTP/2 CLIENT TIMES OUT BEFORE RESPONSE IS SENT
IT38917APIGW VALIDATE ACTION IS TAKING A LONG TIME TO COMPLETE
IT38919MITIGATE VULNERABILITY IN REDIS CVE-2021-32626, CVE-2021-32675
IT38922APIGW UNABLE TO GET UDP PROPERTIES THROUGH XSLT EXTENSION FUNCTION
IT38924APIC INVOKE POLICY DEFAULT PARAMETER CONTROL SHOULD BE AN EMPTY ALLOWLIST
IT38928DATAPOWER MIGHT RELOAD WHEN GATEWAY PEERING CLUSTER CREATE COMMAND IS USED
IT38936MAP OPTION TO CREATE REQUIRED SIBLING PROPERTIES OF OPTIONAL OBJECTS FAILS FOR LEAF PROPERTY MAPS
IT38937PROCESSING OF MALICIOUS REGEXP MIGHT CONSUME EXCESSIVE RESOURCES (CVE-2021-3807)
IT38954DATAPOWER MIGHT RELOAD WHEN PARSING A NULL INPUT DOCUMENT
IT38959LOAD BALANCER GROUP ALGORITHM WEIGHTED ROUND ROBIN MIGHT UNEXPECTEDLY RELOAD DATAPOWER
IT38962UNABLE TO SET HEADER WITH DOTS IN THE NAME WHEN USING APIM.SETVARIABLE()
IT39015DATAPOWER TENANTS ARE DISABLED WHEN DATAPOWER APPLIANCE IS RELOADED
IT39021IBM DATAPOWER GATEWAY MIGHT ALLOW JSON INJECTION (CVE-2021-38910)
IT39032DATAPOWER APIC GATEWAY RATE LIMIT COUNT OF CONCURRENT TRANSACTION NEVER DECREASES
IT39040IBM DATAPOWER GATEWAY MIGHT PERMIT HEADER INJECTION (CVE-2021-38944)
IT39044WITH PROBE ENABLED, INCORRECT 39 BYTE XML DECLARATION IS SHOWN INCORRECTLY FOR EMPTY CONTEXT FOR GATEWAYSCRIPT READASBUFFER()
IT39115DATAPOWER SSH CLIENT MIGHT CAUSE HIGH CPU WHEN ACTING AS AN SFTP CLIENT TO RETRIEVE A BIG FILE LIST
IT39117DATAPOWER ACCESS MANAGER CLIENT VERSION DEFAULT DOES NOT WORK CORRECTLY
IT39119FOR API CONNECT INTEGRATION, A DYNAMIC MQ URL OPEN CALL IN GATEWAYSCRIPT MIGHT RESTART DATAPOWER
IT39130MEMORY GROWTH OR RELOAD WHEN USING OAUTH FOR APIC SECURITY
IT39153DATAPOWER MIGHT RELOAD WHEN WS-PROXY CONFIGURATION IS CHANGED WHEN NOT QUIESCED
IT39154TRANSACTION MIGHT HANG AND NEVER COMPLETE IF CLIENT CLOSES TCP CONNECTION UNEXPECTEDLY TO THE APIGW
IT39155DATAPOWER MIGHT RESTART WHEN USING MULTISTEP PROBE
IT39157DATAPOWER JSON SCHEMA VALIDATION STRING FORMAT DATE AND DATE-TIME ALLOW FOR INVALID DAYS
IT39160DATAPOWER MAY UNEXPECTEDLY RESTART WHILE COLLECTING A PACKET CAPTURE
IT39161DATAPOWER MAY UNEXPECTEDLY RESTART, WHEN AN API IS BEING TESTED FROM APIC MANAGER TEST TOOL
IT39165SUPPORT NUMERIC TYPES OF OAI DEFINED DATA TYPES
IT39171DATAPOWER RELOAD WHEN USING API DEBUG PROBE WITH XSLT ASSEMBLY ACTION ERROR
IT39186USER REGISTRY FOR OAUTH CAN HAVE TLS PROFILE SET TO NONE ON DATAPOWER
IT39187JWE PRODUCED FROM THE EXAMPLE GATEWAYSCRIPT DOES NOT CONTAIN AN ENCRYPTED KEY PARAMETER
IT39203CONFIGURATION CHANGES IN API MANAGER MIGHT FAIL TO BE PROPAGATED ACROSS ALL GATEWAYS IN A CLUSTER
IT39232SAML ASSERTIONS ARE NOT PROCESSED WHEN SENT TO DATAPOWER IN AN HTTP URL QUERY STRING.
IT39289API GATEWAY - API COLLECTION MISSING AFTER RESTART OF THE GATEWAY
IT39299DATAPOWER WEBSOCKET UPGRADE MAY RESULT IN INCREASED FILE COUNT AND MEMORY GROWTH
IT39300DATAPOWER EXTENDED LATENCY LOG MAY HAVE EXTRA CHARACTERS WHICH MIGHT CAUSE ANALYTICS LOG ACTION TO FAIL
IT39342DATAPOWER MAY GROW IN MEMORY WHEN MQFTE URL OPENER FAILS TO PUT MESSAGES
IT39343GATEWAY MIGHT RESTART WHEN NO API COLLECTION OR API DEFINITION IS MATCHED
IT39384CLI COMMAND GATEWAY-PEERING-CLUSTER-REPLICATE SHOULD NOT ALLOW A DOWN PEER TO BE ASSIGNED AS THE PRIMARY
IT39436WHEN USING A APIC GATEWAY EXTENSIONS, ON RESTART THE GATEWAY MIGHT NOT PROPERLY CONFIGURE USER DEFINED POLICIES
IT39468DATAPOWER API GATEWAY MIGHT RESTART WHEN RUNNING AN ERROR RULE AFTER NO TARGET HAS BEEN MATCHED IN THE COLLECTION
IT39495MULTIPLE ISSUES IN SQL DRIVER
IT39504APIC GATEWAY ASSEMBLY RATE-LIMIT REJECTS REQUESTS WITH CODE 429 BEFORE REACHING THE CONFIGURED LIMIT
IT39513ASSEMBLY-OPERATION-SWITCH CAUSES MEMORY LEAK
IT39534DATAPOWER MIGHT RESTART WHEN REMOVING AN OBJECT FROM THE API RATELIMIT CACHE
IT39541SECURE GATEWAY CLIENT MIGHT HANG IN A UP OR PENDING STATE
IT39556DB2 ENDPOINT MAY CAUSE UNEXPECTED RELOAD OF DATAPOWER
IT39581WTX: XML NOT VALIDATING AGAINST DTD AS EXPECTED
IT39615MITIGATION FOR CVE-2021-22959 & CVE-2021-22960
IT39630DATAPOWER GATEWAY USING MQ V9+ OBJECTS MIGHT RESTART IN PERIODS OF HIGH TRAFFIC
IT39660WHEN PRIMARY GATEWAY GOES DOWN, GWD NODE.JS PROCESS ENCOUNTERS UNHANDLED REJECTION AND RESTARTS ON OTHER GATEWAYS
IT39661IF API CONNECT PRIMARY GATEWAY IS RESTARTED SOME CATALOGS ON A SECONDARY GATEWAY MIGHT BECOME UNUSABLE
IT39669APIGW - PEER CLEAN UP CAN CAUSE WEBAPI INIT CHECK TO FAIL AFTER A RELOAD
IT39700UPDATE DATAPOWER JRE TO ADDRESS CVE-2021-35578
IT39721WHEN API CATALOG CREATED AND IMMEDIATELY DELETED, GATEWAY PEERING DATA MIGHT REMAIN
IT39764SUPPORT API CLIENT ID THAT IS 37 CHARACTERS OR LONGER
IT39772REGRESSION OF IT36089 IN 10.0.1.4
IT40374ADDRESS PROTOTYPE POLLUTION FLAW IN DOJO (CVE-2021-23450)

Back to top


10.0.1.5

Release date: 1 October 2021
Last modified: 1 October 2021
Status: Available

APAR
Description
IT35948APIC GATEWAY DIRECTOR TLS CLIENT USING SNI WHEN NOT CONFIGURED TO USE SNI
IT36456DATAPOWER CAN CAUSE UNCOMMITTED MESSAGES IF MQ URLS WITH SYNC POINT TAGS ARE USED WITHOUT UNITS-OF-WORK SETTING IN MQ-QM OBJECT.
IT36675INVALID JSON SYNTAX ERROR MIGHT OCCUR WHEN DATAPOWER GATEWAY POD IS DELETED
IT36703DATAPOWER AMQP CONNECTIONS ARE NOT BEING TORN DOWN
IT36736DATAPOWER MIGHT RELOAD UNEXPECTEDLY WHEN MAKING AN MQGET CALL
IT36786DATAPOWER MAY WATCHDOG RELOAD WHILE STARTING UP AFTER A RELOAD
IT36859DATAPOWER MIGHT RESTART IF THE STYLEPOLICY CONFIGURATION IS CHANGED WHILE TRAFFIC IS USING THAT POLICY
IT37053DATAPOWER SQL TRACING FAILS TO CREATE ANY LOGS
IT37093DATAPOWER WTX INTERNAL ERROR. UNEXPECTED MAPPING ERROR. 200 AFTER UPGRADING TO 10.0.1.0
IT37200:PORT FORMAT FROM THE SSH CLIENT KNOWN HOST TABLES
IT37244RATELIMIT MODULE CONCURRENT POLICY WORKS UNEXPECTEDLY ON API GATEWAY
IT37281SESSION.APIGATEWAY IS NOT RETURNING THE GATEWAY NAME
IT37332MAP POLICY DOES NOT PROPERLY RESOLVE MAP VARIABLE REFERENCE WITH ESCAPED PERIODS.
IT37334GUI BANNER SHOWS UNSAVED CHANGES WHEN SHOW NTP-SERVICE COMMAND USED
IT37348DATAPOWER MAY RELOAD DUE TO A HANG ON AN MQ SESSION
IT37354DATAPOWER XML SCHEMA CANNOT VALIDATE ... TYPE="XS:DOUBLE" FIXED="NAN" ... CORRECTLY
IT37362APIC GATEWAY SERVICE CONFIG SEQUENCE HANGS DUE TO ASSEMBLY INVOKE ACTION
IT37388DATAPOWER MIGHT RESTART AFTER MIGRATION TO MQ V9+ OBJECTS
IT37474USING QUERY PARAM IN AUTHURL CAUSES ERROR
IT37506DATAPOWER MAY RESTART AFTER PROCESSING 4 BILLION LOG TARGET MESSAGES VIA SYSLOG-TCP OR NFS
IT37513CALLING THE XSLT EXTENSION FUNCTION DP:FREEZE-HEADERS IN AN ASYNCHRONOUS ACTION MIGHT RESTART THE DEVICE
IT37552EXTENSION DRR FLAG NOT CLEARED ON DRRS WHERE GATEWAYEXTENSIONDEPLOYER HAS ALREADY COMPLETED INIT
IT37601DATAPOWER RESTART WHEN RUNNING TLS-LOG-CLIENT-RANDOM
IT37603DATAPOWER UI GENERATED ERRONEOUS CLI ERRORS WHEN EDITING RATE LIMIT CONFIGURATION
IT37616GATEWAYSCRIPT MIGHT HAVE INCORRECT RESULT WITH THE BUFFER.SLICE() FUNCTION
IT37636THE DIAG FUNCTION, SET-GATEWAYSCRIPT-CACHE DISABLE/ENABLE, MIGHT CAUSE GATEWAYSCRIPT ERRORS
IT37653APIC PARAMETER INPUT CHECKING TO RESTRICT UNUSABLE CONFIGURATIONS
IT37666ADD OPTION TO SPECIFY XML MANAGER FOR API GATEWAY GATEWAYSCRIPT MULTISTEP CALLRULE FUNCTION
IT37691DATAPOWER MIGHT RESTART UNEXPECTEDLY WHEN AN API HAS UNUSUALLY LARGE NAMES FOR THE PATH, API, COMPONENT ETC.
IT37706SSL CONFIGURATION MAY NOT BE USED IF USING SNI PROFILE
IT37722APPLICATION.CERTIFICATE CONTEXT VARIABLE RETURNS NULL FOR KEYVALUE ATTRIBUTE
IT37750APIC ASSEMBLY RATE LIMIT ACTION SHOULD DETECT INVALID CONFIGURATION
IT37766API CONNECT OPENAPI V3.0 SUPPORT FOR API SYNTAX CHECKING
IT37770REQUESTS TIME OUT WHEN SENDING DATA LARGER THAN 1 MB BYTES
IT37779DATAPOWER POST-LOGIN BANNER DOES NOT WORK FOR WEBGUI
IT37782API CONNECT GATEWAY URLOPEN CALL IN GATEWAYSCRIPT DOES NOT RECOGNIZE THE DEFAULT TLS PROFILE NAME
IT37826API CONNECT GATEWAY SERVICE RETURNS DIFFERENT VALUE FOR THE CLIENT.APP.SECRET COMPARED TO APIM V5
IT37855APIC REDACT 1.5.0 POLICY ISSUES
IT37856UPDATE OPEN-VM-TOOLS TO ADDRESS SEVERAL CVE
IT37923ASSEMBLY CONTEXT VARIABLE PLAN.RATE.LIMIT FORMAT DOES NOT MATCH V5 OUTPUT
IT37924APIC GATEWAY CONTEXT.MESSAGE.BODY.READASBUFFER RETURNING INCORRECT DATA
IT37929ADDRESS CVE-2021-22918 IN NODE
IT37931FOR THE APIC GATEWAY SERVICE DOCUMENT CACHE FUNCTION WAS TURNED OFF BY DEFAULT
IT37935ADDRESS SEVERAL CVES IN KERBEROS
IT37936API INVOKE AND PROXY 1.5.0 POLICY FAILS WITH PARSE ERROR ON LARGE RESPONSES
IT37949ADDRESS FALSE-POSITIVE VULNERABILITY FINDINGS REPORTED BY SCAN UTILITIES
IT37950ADD HEADER TIMEOUT PARAMETER TO ADDRESS CVE-2020-4994
IT37962SQL DATA SOURCE GOES INTO PENDING STATE AFTER BEING DISABLED
IT37967IMPROVE GATEWAY EXTENSION CLEAN UP LOGIC
IT37975APIC GATEWAY SERVICE TRANSACTION TIMEOUT IS NOT ENFORCED CVE-2021-38872
IT37976APIC V5C PRODUCT AFTER REPLACE WILL NOT BE UPDATED CORRECTLY
IT37984APIC INVOKE ACTION REQUEST HEADERS IN THE API PROBE DATA MIGHT BE NOT CORRECT
IT37992USING MUTUAL TLS IN AN API DEFINITION RESULTS IN MEMORY LEAK
IT37993DATAPOWER MIGHT RESTART WHEN UPGRADING GATEWAY PEERING MEMBER UNDER LOAD
IT37994APIC GATEWAY SERVICE USING INVOKE ACTION MIGHT RESTART WITH HTTP/2 WHEN INJECT PROXY HEADERS IS SELECTED
IT38005RBM APPLY-CLI OPTION MAY CAUSE SCHEMA FAILURES SSH CLIENT PROFILES
IT38026APIC GATEWAY SERVICE SHOULD ALLOW SPACES IN PROPERTY NAMES
IT38071CUSTOMER MAY RECEIVE AN ERROR MESSAGE INDICATING THAT THE SWITCH_1.5.0-INTERNAL FUNCTION IS NOT VALID
IT38072TIMING ISSUE WITH CONCURRENT PROCESSING OF WEBHOOK REFRESH CAUSES DELETION OF ENTIRE CATALOG
IT38088UPDATE JRE TO ADDRESS CVE-2021-2341
IT38089MITIGATE CVE-2021-3712 FOR PROCESSING ASN.1 IN TLS
IT38095DATAPOWER TLS CAN FAIL WHEN NEGOTIATING ALPN
IT38096APIC OAUTH PROVIDER SETTINGS NOT DISPLAYING CORRECTLY
IT38112ERROR IN JWT AUTHENTICATION
IT38114MIGRATION POLICY IF BY OPERATION PATH
IT38151ADD XSLT EXTENSION FUNCTION APIM:GETTLSPROFILEOBJNAME TO THE API GATEWAY XSLT COMPATIBILITY MODULE
IT38154APIC GATEWAY PROXY POLICY NOT APPLIED CORRECTLY
IT38160AN XFORM ACTION ASYNCHRONOUS SETTING MIGHT CAUSE API GATEWAY TO RESTART.
IT38167AU CACHING IS FAILING, NO CACHE HIT, WITH FORMS BASED LOGIN.
IT38175APIC DATAPOWER GATEWAY MIGHT RESTART WHEN USING API PROBE ON A GET REQUEST
IT38176DATAPOWER TLS KEY LOG FILE MAY NOT DECODE TLS 1.3
IT38185UNABLE TO LOG INTO DATAPOWER CLI
IT38193XML PARSE ERROR IN APIC GATEWAY V5 POLICY WHEN PARSING MORE THAN 4 MB OF DATA
IT38220DELETING A CATALOG SHORTLY AFTER IT IS CREATED MIGHT CAUSE API CONNECT GATEWAY SERVICE INITIALIZATION FAILURE
IT38292DATAPOWER RESTARTS WHEN SENDING REQUEST WITH INVALID CHARACTERS IN URI
IT38387SCHEMA VALIDATION INCORRECTLY REJECTS BASE64 ELEMENT AS EMPTY

Back to top


10.0.1.4

Release date: 6 August 2021
Last modified: 6 August 2021
Status: Available

APAR
Description
IT21079POTENTIAL MEMORY GROWTH WITH AN XQUERY ACTION THAT USES JSON INPUT LANGUAGE
IT33993NEGOTIATION MODE OF LINK AGGREGATION INTERFACE IS UNKNOWN
IT35157DATAPOWER DELIMITS COALESCED COOKIES WITH COMMA INSTEAD OF SEMICOLON
IT35539FAILURE NOTIFICATION WITH SMTP FAILS TO TRANSITION TO UP WHEN ENDPOINT USES AN IPV6 ADDRESS
IT35554DATAPOWER ALLOWS DOTDOT IN URI WHEN USING PATCH METHOD EVEN IF DISALLOWED
IT35868INVALID SUBSCRIBER DATA NOT DELETED IN THE LOCAL CACHE
IT36001DATAPOWER MIGHT RESTART WHEN CLEANING UP AN IBM MQ MANAGEMENT STORE
IT36084IBM MQ HANDLER STOPS PROCESSING MESSAGES
IT36096DATAPOWER MIGHT NOT PROPERLY READ RESPONSE FROM THE BACK END
IT36143EXPIRATION TIME IN LOCAL RATE LIMIT CACHE WAS NOT UPDATED WHEN THE LIMIT IS EXCEEDED
IT36156PARALLEL UPDATES TO API GATEWAY CONFIGURATION FILES MIGHT CAUSE CORRUPTED FILES
IT36162DATAPOWER MIGHT RESTART WHEN PROCESSING RBM FOR THE GUI, XML MANAGEMENT, OR REST MANAGEMENT INTERFACES
IT36180DATAPOWER MIGHT RESTART WHILE UPLOADING A FILE WITH THE DATAPOWER GUI
IT36191RESTART WHEN QUERYING FOR A ?WSDL WHEN USING OAUTH SECURITY POLICY
IT36204DURING API PROCESSING WHEN RESPONSE CONTAINS NO BODY, REQUEST CONTENT-TYPE RETURNED TO CLIENT
IT36219HTTP/2 POST OR PUT REQUEST WITH NO BODY DATA WILL CAUSE TIME OUT ERROR
IT36332DUPLICATE CSR ENTRIES CREATED WITH THE DATAPOWER KEYGEN UTILITY
IT36407MITIGATION FOR TLS CVE-2021-3449
IT36417UPDATE SECURE GATEWAY CLIENT TO ADDRESS MULTIPLE CVES
IT36448DATAPOWER MIGHT PRINT EXTRA TEXT WHEN A LONG XML TEXT NODE IS LOGGED FROM AN XSLT ACTION
IT36463WSDL FAILS TO DEPLOY ON DATAPOWER FOR VMWARE
IT36479API CONNECT GATEWAY V5C POLICIES STOPPED WORKING AFTER FIRMWARE UPGRADE
IT36481DATAPOWER RESTARTS WHEN VIEWING GATEWAY PEERING STATUS
IT36517SPECIAL CASE THREADS MIGHT BE SUSCEPTIBLE TO LOGGING TO A TARGET THAT NO LONGER EXISTS CAUSING AN UNEXPECTED RESTART
IT36579DATAPOWER SNMP SHOULD NOT QUERY IBM MQ APPLIANCE STATUS PROVIDERS
IT36624API CONNECT GATEWAY EXTENSION FAILS TO IMPORT ALL OBJECTS
IT36625DATAPOWER MIGHT RESTART DUE TO API SUBSCRIBER CACHE MANAGEMENT
IT36627ADDRESS FALSE-POSITIVE VULNERABILITY FINDINGS REPORTED BY SCAN UTILITIES
IT36635DATAPOWER DOES NOT CONVERT ISO-8859-1 CHARACTERS TO UTF-8 CORRECTLY IN HTTP HEADER
IT36637DATAPOWER MIGHT RESTART WHEN MODIFYING WEB SERVICE PROXY WHILE REQUESTING WSDL
IT36655API CONNECT UNABLE TO INPUT INLINED PARAMETER FOR THE TLS PROFILE NAME OF THE ASSEMBLY INVOKE ACTION
IT36715ADDRESS CORS MISCONFIGURATION CVE-2020-4992
IT36726MEMORY GROWTH WHEN CALLING DP:GATEWAYSCRIPT XSLT FUNCTION
IT36727DATAPOWER DOES NOT CORRECTLY CALCULATE FREE MEMORY
IT36732ASSEMBLY VALIDATE ACTION MIGHT RESTART DATAPOWER
IT36779DATAPOWER TPS MIGHT BECOME LIMITED BY ASSEMBLY REDACT ACTION
IT36780API CONNECT GATEWAY SERVICE LOGS ERRORS AFTER THE PRIMARY GATEWAY RESTARTS AND RECONNECTS
IT36946API CONNECT REDACT STYLESHEETS ARE NOT RECOMPILED WHEN REPUBLISHED
IT36949MITIGATION FOR DOJO VULNERABILITIES CVE-2018-15494 AND CVE-2020-4051
IT37035API CONNECT GATEWAY SERVICE MIGHT RESTART UNEXPECTEDLY WHEN CLI SHOW CONNECTIONS IS RUN
IT37053DATAPOWER SQL TRACING FAILS TO CREATE LOGS
IT37082MITIGATION FOR CVE-2020-7774 UPDATE Y18N NODE MODULE
IT37175API GATEWAY V5C FAILS WITH SESSION AUTHENTICATION FAILURE
IT37214DATAPOWER TAM CLIENT GOES DOWN AFTER UPGRADING
IT37278MITIGATE NODE LIBRARY FOR CVE-2020-8287 AND CVE-2020-8265
IT37523UPDATE ICU LIBRARY TO ADDRESS SEVERAL CVES
IT37933UPDATE ANGULARJS TO ADDRESS MULTIPLE CVES

Back to top


10.0.1.3

Release date: 2 April 2021
Last modified: 2 April 2021
Status: Available

APAR
Description
IT33579ENSURE THE ORDER FOR THE LDAP OBJECTS ARE CORRECT AND DEFINED FOR CONFIGURATION.
IT34576ZE IT30835 FIX APAR: USE OF VAR://SERVICE/TLS-INFO VARIABLE MIGHT LEAD TO UNEXPECTED RESTART
IT34675DATAPOWER KAFKA OBJECT DOES NOT RETRIEVE ALL THE MESSAGES AFTER THE KAFKA OBJECT IS RESTARTED.
IT34680LIVE STREAM HANG TRIGGER DATAPOWER WATCHDOG RESTART
IT34742MEMORY GROWTH MIGHT OCCUR WHEN USING ASSEMBLY LOG ACTION
IT34767DATAPOWER MIGHT RESTART DUE TO A NETWORK ERROR IN THE MQ FTE HANDLER WHILE BACKOUT
IT35177INVOKE 1.5.0 DOES NOT CORRECTLY RESPECT STOP ON ERROR OPTIONS
IT35219DATAPOWER MIGHT RELOAD DUE TO AN INTERNAL DEFECT WITH MQ REFERENCE COUNTING
IT35248CLIENT SECRET IS NOT REDACTED ON API GATEWAY
IT35370ADDED HANDLING OF SPECIAL IMS IRM_TIMER VALUES 0 AND -1
IT35454ONLY FLUSH CACHE FOR MODIFIED FILES TO PREVENT INTERMITTENT ERRORS
IT35462DATAPOWER MIGHT RESTART WHILE PROCESSING A LARGE CONFIGURATION FILE OR MULTIPLE CONCURRENT CONFIGURATION FILES
IT35492DATAPOWER MIGHT RESTART WHILE CLOSING AN LDAP CONNECTION
IT35498ADD DOMAIN NAME TO ANALYTICS RECORDS
IT35529WHEN USING MQ HANDLER, DATAPOWER MIGHT RESTART IF CONNECTIONS CANNOT BE ESTABLISHED WITH THE MQ SERVER
IT35543THE LOCATION HEADER GETS REWRITTEN IN ANY CASE BY THE LOCATION HEADER REWRITE FEATURE WHEN THE HOST CANNOT BE RESOLVED
IT35677XML FIREWALL CANNOT SET DYNAMIC TLS PROFILE FOR A TLS CLIENT PROFILE
IT35724DATAPOWER MIGHT RESTART DUE TO A BAD MQRFH2 HEADER IN AN MQ MESSAGE
IT35729GATEWAYSCRIPT URLOPEN CALL MIGHT TIMEOUT WHEN READING DATA FROM THE NETWORK
IT35737DATAPOWER MIGHT LEAK MEMORY IF A WSDL BASED API IS INVOKED BY BASEPATH ONLY
IT35825DATAPOWER VALIDATION ERROR MESSAGES STATE ERROR REASON AT MESSAGE END, WHICH GETS TRUNCATED BY DATAPOWER LOG FOR LONG MESSAGES
IT35836API CONNECT GATEWAY SERVICE CAN GET STUCK IN A NON-RESPONSIVE STATE WHEN DRR FINISH NOT DETECTED
IT35863THE CRYPTO-BINARY ACTION GOES DOWN DUE TO NO DATAGLUE LICENSE.
IT35868INVALID SUBSCRIBER DATA NOT DELETED IN THE LOCAL CACHE
IT35869DATAPOWER MIGHT RESTART IF A STREAM IS READ WHILE THERE IS FATAL ERROR ON THAT STREAM
IT35870ADD AN OPTION TO THE ASSEMBLY INVOKE ACTION
IT35871ANALYTICS CERTIFICATES REMOVED WHEN API CONNECT GATEWAY SERVICE IS RESTARTED
IT35873ERROR POLICY PROPERTY OF ASSEMBLY VALIDATE ACTION COULD NOT BE SET BY APIC API MANAGER
IT35895DATAPOWER MIGHT RESTART WHILE ACCESSING A TLS SESSION
IT35909DATAPOWER MIGHT RESTART DUE TO LOCK ISSUE
IT35921API CALL FAILS WHEN REQUEST URL CONTAINS NEGATIVE VALUES FOR PATH PARAMETERS OF INTEGER TYPE
IT35924ANALYTICS CERTIFICATES ARE NOT RESTORED WHEN RE-ADDING ANALYTICS
IT35928DATAPOWER RELOADS WHILE MAKING AN OCSP CALL
IT35930CANNOT REFRESH API GATEWAY SERVICE IF OAUTH PROVIDER CONTAINS A USER REGISTRY USING TLS
IT35938API GATEWAY ONLY ALLOWS SECP256R1 CURVE ALGORITHM FOR TLS CONNECTIONS AS A CLIENT
IT35980API OPERATION STAYS UP EVEN IF PARAMETER REFERENCE IS MISSING
IT35988ADDRESS PROBLEMS WITH IBM MQ V9+ INTEGRATION
IT35990VALIDATION OF TOKENS WITH NON STRINGS IN THE JWT HEADER FAIL
IT35996MULTIPLE CVE FOR MCP AND UBI
IT36032ADD PASSWORD CONFIGURATION FOR INTRA-CLUSTER COMMUNICATIONS
IT36039THE SHARE RATE LIMIT COUNT PROPERTY IN API GATEWAY NOT HONORED WHEN API REPUBLISHED.
IT36078GUI ISSUE IN ADDING MESSAGE COUNT MONITOR IN WEB SERVICE PROXY
IT36089ZE IT34014 FIX APAR: COMPRESSION ON HTTPS RESULTS IN FAILING RESPONSES AFTER IT34014
IT36101DATAPOWER MIGHT RESTART DUE TO TLS TRANSACTIONS
IT36121FOR API CONNECT, TLS PROFILE CHANGES IN THE LDAP IS NOT PICKED UP
IT36129DATAPOWER MIGHT RESTART DUE TO AN INVALID POINTER TO AN LDAP USER REGISTRY
IT36325THE SECURITY ACCESS MANAGER CLIENT MIGHT FAIL TO START
IT36586JRE UPDATE TO ADDRESS CVE-2020-14779, CVE-2020-14782, CVE-2020-14803 AND CVE-2020-27221

Back to top


10.0.1.2

Release date: 29 January 2021
Last modified: 29 January 2021
Status: Available

APAR
Description
IT32643STYLESHEET WITH INPUT CONTEXT NULL AND COMPILE OPTIONS POLICY ATTEMPT-STREAMING-RULE MIGHT CAUSE A RESTART
IT32767DATAPOWER MIGHT RESTART IF A LOG TARGET CONFIGURATION IS MODIFIED
IT33795GATEWAYSCRIPT READASBUFFERS() CANNOT READ >2GB SIZE INPUT
IT33856QUIESCE STATE NOT PROPERLY SET IN SELF BALANCE RESULTS IN FAILED REQUESTS TO DOWN SERVICES
IT33927ERRORS FOR ISAM CLIENT
IT34586FREEZE GATEWAYSCRIPT GLOBAL OBJECT FOR SECURITY VULNERABILITY
IT34610ASSEMBLY INVOKE ACTION MIGHT CHANGE VERB FROM HEAD TO POST
IT34677APPLICATION METADATA CONTAINING COMMAS MIGHT CAUSE IBM DATAPOWER TO RESTART UNEXPECTEDLY
IT34798DATAPOWER SSH CLIENT MIGHT RESTART WHEN ACTING AS AN SFTP CLIENT FOR LARGE FILES
IT34843UNABLE TO GET CLIENT CERTIFICATE INFORMATION FROM THE ASSEMBLY CONTEXT IN API GATEWAY
IT34845CUSTOM DEFINED V5 POLICY IS INTERMITTENTLY MISSING ASSEMBLY REFERENCE
IT34847CANNOT DELETE PASSWORD ALIAS OBJECT WHEN THE SSH CLIENT PROFILE ASSOCIATED WITH IT IS DELETED
IT34848REQUEST.HEADERS.X-CLIENT-IP NEEDS TO BE POPULATED IN DATAPOWER API GATEWAY
IT34915INVOKE 1.5.0 POLICY DOES NOT EXECUTE WITH LONG API NAME
IT34923GATEWAYSCRIPT 1.0.0 POLICY NOT PROVIDED PARSED XML NODELIST IF CONTENT-TYPE HEADER IS NOT IN LOWER CASE
IT34971API CONNECT GATEWAY SERVICE WITH USER-DEFINED POLICIES MIGHT CAUSE DATAPOWER TO RESTART
IT34996PROCESSING OF LARGE NUMBER OF CATALOGS DURING DRR MIGHT CAUSE OUT OF MEMORY CONDITION
IT34999API CONNECT INTEGRATION IMPORT REJECT USER-POLICY TYPE IF NO POLICY YAML ARE PRESENT
IT35002RATE LIMIT REPLENISH OPERATION MIGHT REPLENISH AFTER INTERVAL ELAPSES
IT35003API CONNECT 1.0.0 POLICES THAT FAIL DO NOT RETURN CORRECT HTTP STATUSCODE AND REASON
IT35035IN API CONNECT INTEGRATION, ELIMINATE DUPLICATE TLS PROFILE CONFIGURATIONS IN CATALOGS.
IT35038FALLBACK TO CATALOG TITLE IF CATALOG NAME IS NOT FOUND
IT35044OAUTH ENDPOINTS REJECT REQUESTS WITH A ;CHARSET=XXX APPENDED TO THE CONTENT-TYPE HEADER
IT35051MAP POLICY FAILS WITH WRONG STATUS CODE WHEN OUTPUT SCHEMA IS INVALID
IT35079UNEXPECTED RESTART LOGGING RESULT OF DP:BINARYNODETOSTRING CHILD::NODE() FOR EMPTY OR STRING CHILD
IT35090IN POSTPROCESSING STEP OF AN AAA POLICY, USER CANT ADD ROLE INTO WS-SECURITY USERNAMETOKEN
IT35154GRAPHQL ASSEMBLY ACTION VALIDATION DOES NOT CHECK VALUE OF RETURNED DATA
IT35160COUNT LIMIT AUTO DECREMENT MIGHT NOT WORK CORRECTLY FOR CERTAIN EXPLICIT DECREMENT OPERATIONS
IT35172WHEN ASSEMBLY NAME CONTAINS SPACES, API GATEWAY CANNOT CATCH AN ERROR
IT35196GRAPHQL ASSEMBLY ACTION VALIDATION DOES NOT CHECK VISIBILITY LIST
IT35232REQUEST XML PARSING CHANGES CONTENT-TYPE
IT35239EXCEPTION THROWN WHEN DEPLOY-POLICIES NOT DEFINED
IT35242WEBSOCKET UPGRADE FAILS IF HTTP RESPONSE CODE IS MANUALLY SET
IT35251GRAPHQL ASSEMBLY ACTION DOES NOT CHECK CUSTOM DIRECTIVE ARGUMENTS
IT35253USE OF @COST DIRECTIVE INADVERTENTLY SUPPORTED IN INTERFACE FIELDS
IT35266ASSEMBLY VALIDATE ACTION CANNOT HANDLE ERROR RESPONSE WHEN DEFINED AS JSON INPUT AGAINST A GRAPHQL SCHEMA
IT35275API CONNECT 1.0.0 POLICIES CANNOT ACCESS VARIABLES SET BY A 2.0.0 POLICY
IT35288DATAPOWER MIGHT UNEXPECTEDLY RELOAD ACCESSING THE API SUBSCRIBER CACHE
IT35315API GATEWAY CANNOT ACCESS THE GATEWAYSCRIPT SESSION OBJECT
IT35316UNEXPECTED SYSTEM RESTART WHEN QUERYING SNMP (CVE-2020-4869)
IT35317NODE.JS SECURITY VULNERABILITES (CVE-2020-8174)
IT35324DEVICE MIGHT RESTART IF A CONTEXT VARIABLE REFERS TO AN UNKNOWN CONTEXT
IT35327IBM DATAPOWER GATEWAY POTENTIALLY VULNERABLE TO AN RCE ATTACK (CVE-2020-5014)
IT35364MEMORY GROWTH WHEN API DEFINITION LOGS PAYLOAD ON SUCCESS
IT35401HTTP CONNECT METHOD IS NOT USED FOR CALLS VIA USER AGENT PROXY
IT35441DYNAMIC ACTIONS FOR INVOKE POLICIES MIGHT BE CREATED INCORRECTLY
IT35447GATEWAY PEERING IN STANDALONE MODE CAN HANG WHEN PROCESSING HIGH VOLUME RATE LIMITING
IT35449UNDER CERTAIN CIRCUMSTANCES, ENCODING IS SET INCORRECTLY DURING VALIDATION OF JSON/GRAPHQL SCHEMA FILE
IT35451A FOREACH PROPERTY IN A MAP POLICY SET ACTION FAILS IF NOT SPECIFIED AS A STRING VALUE
IT35452DATAPOWER MIGHT RESTART UNEXPECTEDLY IN RARE CASES WHEN READING STREAM
IT35493DATAPOWER MIGHT FAIL TO COLLECT DPMON LOGS
IT35571DATAPOWER UPGRADE TO 10.X.X FAILS
IT35769ON ERROR, REDACT POLICY NOT HONORED BEFORE SENDING MESSAGE TO ANALYTICS ENDPOINT.

Back to top


10.0.1.1

Release date: 9 December 2020
Last modified: 9 December 2020
Status: Available

APAR
Description
IT31762EMPTY MESSAGES AS RESPONSE IN TIBCO EMS FOR SPECIFIC FLOWS
IT32057<XSL:MESSAGE> CALLED WITH NON-UTF8 CHARACTER WILL PREVENT JSON KEY AND XML NAME CLEANUP
IT32347SHOW MEMORY COMMAND RESULTS IN CANNOT FETCH STATUS DATA ERROR
IT32349KEYS STORED IN LUNA MIGHT FAIL TO LOAD
IT32577HSM PARTITION GIVES ERROR CANNOT LOAD KEY WHEN INCORRECT PASSWORD IS GIVEN
IT32876DATAPOWER WILL NOW RETURN PROPER GZIP CONTENT FOR A HTTP RESPONSE BODY OF LENGTH 0.
IT32937DATAPOWER DISREGARDS THE TTL VALUE IN THE DNS CNAME RECORD WHEN USING FIRST ALIVE ALGORITHM
IT33441WHEN CALLING OAUTH PROVIDER TOKEN ENDPOINT USING REFRESH TOKEN WITH DIFFERENT CLIENT ID, GATEWAY RETURN HTTP 401 INSTEAD OF 400
IT33495DATAPOWER RESTARTS DUE TO ODR OBJECTS
IT33551CREATE TOGGLE FOR LLDP ON THE INTERFACES
IT33588DELETED DOMAINS DO MAY NOT PROMPT FOR NEED SAVE, RESULTING IN RESURFACING ON DEVICE REBOOT/RESTART.
IT33673SUPPORT CATALOG PROPERTIES VIA A NEW CONTEXT VARIABLE IN DATAPOWER API GATEWAY
IT33679SESSION.CLIENTADDRESS API CONTEXT VARIABLE DOES NOT USE CLIENT IP ADDRESS IN X-FORWARDED-FOR OR X-CLIENT-IP HEADER
IT33727UPDATE ERROR MESSAGE RESPONSE CODE TO BE CORRECT FOR SECURITY.
IT33775ASSEMBLY RATE LIMIT CACHE STATUS IS INCORRECT
IT33778LUNA HA GROUP UP IF ONE MEMBER IS UP
IT33779WHEN A LUNA HA GROUP OR PARTITION OBJECT IS DOWN THE CERTIFICATE OBJECT SHOULD BE DOWN
IT33845CONTENT-TYPE HEADER SET TO UNKNOWN MIGHT CAUSE ISSUES WITH INVOKE POLICY TARGET SERVERS
IT33890ON IBM DPOD V1.0.10 DOES NOT DISPLAY API RESPONSE SIZE FOR V2018 APIC DOMAINS
IT33897MEMORY LEAK WHEN USING OAUTH AND RATE LIMITING
IT33898GATEWAY PEERING CACHE STATUS DOES NOT INCLUDE GATEWAY RATELIMIT DATA
IT33923MAXIMUM CONSENT TTL SETTING IN OAUTH PROVIDER SETTINGS DOES NOT WORK PROPERTY
IT33953UNEXPECTED RESTART OF DATAPOWER ON PASSWORD ALIAS WHICH ARE BLANK OR MALFORMED
IT33967FIX GRAPHQL SCHEMA PARSER TO PREVENT PARSE ERROR FOR CERTAIN SCHEMAS.
IT33975GRAPHQL PARSER WILL NOW DISALLOW CERTAIN SCHEMAS WHICH ARE NOT CONSISTENT WITH THE APIC MANAGER
IT33981COPY FILE AND MOVE FILE MAY ACT INCORRECTLY WITH SPECIFIC RBM ACCESS PROFILES.
IT33989EXPECTING JSON IN BADGERFISH FORMAT FOR NULL VALUES
IT34009_LINKS STANZA IN REST MANAGEMENT RESPONSE CONTAINS UNEXPECTED CONTENT
IT34014HTTP RESPONSE WHERE COMPRESSION REQUESTED AND NO DATA RETURNED CAUSES A DECOMPRESSION ERROR
IT34016DATAPOWER: LTPA MIGHT CAUSE APPLIANCE TO ENTER FAILSAFE MODE
IT34027PROVIDE PROTECTIVE CODING AGAINST MALFORMED XML IN REQUEST.CATALOGS AND REQUEST.SWAGGER
IT34034A CATALOG WITH NO SPACES AND THAT CATALOG IS PARTITIONED INTO SPACES WILL BRING DOWN ALL CATALOGS
IT34047SLM PEER MESSAGES COUNTS ARE INCORRECT AFTER RESTARTING THE PEER
IT34068CRYPTO-EXPORT CAUSES NON-HSM KEYS CANNOT BE EXPORTED IN THIS MANNER ERROR
IT34070THE V10 GATEWAY UNCONDITIONALLY OVERWRITES THE HOST HEADER
IT34075OAUTH IDENTITY EXTRACTION LOGS INCORRECT MESSAGE WHEN USING A CUSTOM HTML FORM
IT34084UNDER CERTAIN CIRCUMSTANCES, USER-DEFINED POLICIES ERRONEOUSLY DO NOT MEET AVAILABILITY CRITERIA DUE TO INVALID PEERING DATA
IT34142DATAPOWER GATEWAY MIGHT RESTART WHEN PROCESSING GATEWAY NAMED RATE-LIMIT POLICIES WITH ASSEMBLY-RATE-LIMIT ACTION
IT34144THIRD PARTY PROVIDER REQUIRES TOKEN MANAGER TO BE UP
IT34159DYNAMIC REREGISTRATION AND RECONFIGURATION (DRR) FAILS ON API GATEWAY SERVICES DEPLOYED WITH DEFERRED GATEWAY EXTENSIONS
IT34175UPDATES TO AN API GATEWAY CATALOG WITH A LARGE NUMBER OF PRODUCTS MIGHT CAUSE API CONNECT GATEWAY SERVICE RESTART
IT34176UPDATES TO AN API GATEWAY CATALOG WITH A LARGE NUMBER OF PRODUCTS MIGHT CAUSE DATAPOWER RESTART
IT34198DNS STATIC HOSTS MIGHT NOT WORK WHEN LOAD BALANCING ALGORITHM SET TO FIRST ALIVE
IT34236SSL CLIENT PROFILE NOT ACCESSIBLE BY WEBAPI GATEWAY
IT34256USER CANNOT SAVE A CHECKPOINT IN THE WEBGUI
IT34264SNMP POLLING TIMES OUT DUE TO DATAPOWER RESTART
IT34285MEMORY GROWTH SEEN WHEN DOMAIN IS RESTARTED IF GATEWAY PEERING IS USED IN THE DOMAIN OR GATEWAY PEERING IS MODIFIED
IT34286V5C GATEWAY IS INCORRECTLY SENDING API CONNECTS APP CLIENT ID
IT34287IN V5/V5C GATEWAY, WHEN REFRESH TOKEN IS USED TO GENERATE NEW ACCESS TOKEN THE NEW TOKEN STILL HAS THE OLD REVOCATION URL
IT34307TLS HANDSHAKE FAILURE WHEN USING NULL CIPHER ECDHE-RSA-NULL-SHA
IT34326THE <FLASHFILES> SECTION MIGHT UNEXPECTEDLY TRACK FILES ON NFS MOUNTS AND THUS POTENTIALLY DELAY GENERATING ERROR-REPORTS
IT34333AAA LDAP REQUIRES USERPASSWORD, EMPTY PASSWORD ERROR SHOULD BE THROWN ON FAILURE
IT34339WHEN YOU REPLACE A PRODUCT IN API MANAGER, INVOKING APIS IN THE PRODUCT MIGHT FAIL DURING THE REPLACEMENT
IT34349STRICT TRANSPORT SECURITY WILL BE ADDED TO OAUTH APIS IN ORDER TO IMPROVE SECURITY CONCERNS
IT34366GATEWAYSCRIPT CRYPTO.CREATESIGN() API FAILS WITH PSASSA-PSS ALGORITHM
IT34370API CONNECT INTEGRATION: DATAPOWER MIGHT RESTART AFTER ADDING IT AS A GATEWAY SERVICE
IT34376FIX AN ERRONEOUS ERROR MESSAGE ABOUT CLI ARGUMENTS.
IT34387REMOVE SQUARE BRACKETS FROM IPV6 ADDRESSES WHEN REPORTING ANALYTICS.
IT34388APIC V5 COMPATIBILITY FEATURES FOR MIGRATED APIS ARE NOW SUPPORTED
IT34405APIC V5 EMULATION MIGHT RETURN AN INCORRECT PAYLOAD CONTENT TYPE
IT34413MISCELLANEOUS FIXES FOR APIC V5 EMULATION AND MIGRATION
IT34420WHEN FILES ARE IN TEMPORARY: DIRECTORY, XSLT APIGW:SWAGGER-DOCUMENT EXTENSION DOES NOT WORK
IT34444THE CRYPTO PROFILE MIGHT INDICATE SSLV2 IS ENABLED WHILE MAKING CHANGES
IT34447APIC GATEWAY SERVICE MONITORS INCORRECT FILE LOCATIONS
IT34462ROUTING TABLES MIGHT HAVE MISSING BROADCAST ENTRIES FOR INTERFACES
IT34467GATEWAYSCRIPT ERROR MIGHT OUTPUT NAN INSTEAD OF MULTIPLE PERCENT CHARACTERS
IT34481DATAPOWER IS VULNERABLE TO ROBOT VULNERABILITY ON V10
IT34492DATAPOWER COULD NOT LOAD HOST KEY
IT34530DATAPOWER MIGHT LEAK MEMORY IN API GATEWAY SERVICE SCENARIO
IT34598$NUMBER() FUNCTION IN JSONATA DOES NOT ACCEPT BOOLEAN VALUES AS INPUT
IT34611API CONNECT GATEWAY SERVICE MIGHT FAIL TO PROCESS SOME API GATEWAY CONFIGURATION UPDATES
IT34616LOGS SENT BY SEND-ONLY AND GATHER-AND-SEND OF ASSEMBLY LOG ACTION CAN CAUSE AN IMPACT TO CPU USAGE.
IT34621DATAPOWER - THE SEND AS A MESSAGE TOOL ON THE PROBE FEATURE DOES NOT WORK
IT34627APP ID IS INVALID OR NOT WELL-FORMED ERROR WHEN UPDATING AN API SUBSCRIPTION WITH THE WEBGUI
IT34635API GATEWAY, MISSING EXPIRES_IN ATTRIBUTE IN THE POST REQUEST TO THE EXTERNAL TOKEN MANAGEMENT SERVER
IT34652SECURE GATEWAY CLIENT RESTART AT HIGH LOAD
IT34657CATALOG SNAPSHOT PAYLOADS WAS MISSING FROM DATAPOWER GATEWAY
IT34706PEERING ASSEMBLY BURST LIMIT DOES NOT SYNCHRONIZE ALL COUNTERS CORRECTLY
IT34724GATEWAY EXTENSION NOT REAPPLIED TO CONFIGURATION THAT WAS NOT ALREADY CREATED.
IT34760ADDRESSED CVE-2020-4831 IN DATAPOWER V10
IT34769V5 POLICY EMULATION: ERROR WITH TLS PROFILE VERSION OBFUSCATION
IT34805DATAPOWER MAY RELOAD UNEXPECTEDLY WHILE CHANGING OR SAVING DOMAIN CONFIGURATIONS.
IT34809UDP NOT INSTALLED ON DATAPOWER V5C IF REQUEST CAME IN AS SNAPSHOT
IT34858SECURITY VULNERABILITIES IN LODASH AND MINIMIST PACKAGES (API CONNECT GATEWAY SERVICE)
IT34870UNDER HEAVY PROCESSING LOAD, API CONNECT GATEWAY SERVICE MIGHT ENCOUNTER ERRORS ACCESSING GATEWAY PEERING DATABASE
IT34888API CONNECT GATEWAY SERVICE MIGHT NOT HONOR THE LOGGING TARGET LOG LEVEL
IT34894API CONNECT GATEWAY SERVICE VERIFICATION OF GATEWAY SERVICE URL DURING REGISTRATION IS TOO RESTRICTIVE
IT34914CONFIG-SEQUENCE FILE WATCHER MIGHT BE ACTIVATED AFTER MAIN CONFIGURATION FILE IS WRITTEN
IT34922API CONNECT GATEWAY SERVICE DOES NOT PROPERLY LOG ERROR MESSAGE FOR MISSING CATALOG DURING MANUAL DRR
IT34930DRR WITH LARGE NUMBER OF CATALOGS MIGHT GET STUCK IN A FAILURE LOOP
IT34948V5 USER POLICIES WILL NOT BE DEPLOYED ON API GATEWAY WHEN DESCRIPTION YAML DOES NOT HAVE PROPERTIES SECTION
IT34954ADDRESS MULTIPLE JRE SECURITY VULNERABILITIES
IT35000POST REQUEST BODY FORM PARAMETERS WHEN ADDED TO A GET REQUEST AS QUERY PARAMETERS ARE NOT REJECTED BY THE WEBGUI
IT35179USAGE OF A LARGE AMOUNT OF CUSTOM RATE LIMIT KEYS UNDER HIGH LOAD MAY RESULT IN A SYSTEM HANG
IT35203IN DATAPOWER 10.0.1.0, ILMT IS NONFUNCTIONAL

Back to top


10.0.1.0

Release date: 30 September 2020
Last modified: 30 September 2020
Status: Available

10.0.1.0 is a manufacturing refresh that includes no new APARs. 10.0.1.0 is equivalent to 10.0.0.1.

Back to top


10.0.0.1

Release date: 17 August 2020
Last modified: 17 August 2020
Status: Available

10.0.0.1 is the last fix pack against the 10.0.0.x stream. Future fix packs are against the 10.0.1.x stream.

APAR
Description
IT32051SSH KNOWN HOSTS FILE DOES NOT ACCEPT KEYS >1K BYTES
IT32283LOCAL-SERVICE-VARIABLE IS NOT POPULATED FOR HTTP/2 REQUESTS
IT32296SNMP POLLING MQ CONNECTION STATUS PROVIDER LEAKS MEMORY
IT32522THE "LOGTEMP:///XACT-LOG" AND ASSOCIATED STANZA IN THE ERROR REPORT WOULD REPORT A RANDOM OBJECT NAME FOR ACCEPTED CONNECTIONS
IT32758DATAPOWER MIGHT RELOAD AFTER INVOKING THE "SAVE INTERNAL-STATE" COMMAND
IT32782API CONNECT GATEWAY SERVICE MIGHT RESTART DATAPOWER WHILE CREATING CONFIGURATION FROM YAML FILE
IT32931DATAPOWER MIGHT NOT PARSE UTF16 XML IF BOM IS SPLIT ON DIFFERENT TCP PACKETS
IT32934DATAPOWER UNQUIESCE LEAVES API GATEWAY SERVICE IN DOWN STATE
IT32964DATAPOWER ODR INTEGRATION COULD GENERATE INVALID PEER CERTIFICATE ERRORS ON WEBSPHERE APPLICATION SERVER
IT32966MULTIPLE CVE FOR MCP AND UBI
IT33003DOMAIN SETTINGS PASSWORD TREATMENT INCORRECTLY IMPACTS PASSPHRASE DECRYPTION.
IT33036THE "VAR://SERVICE/AAA-ERROR-LOGS" VARIABLE IS NOT POPULATED WHEN LOG LEVEL IS ERROR
IT33116DATAPOWER USES AN OBSOLETE AAA HEADER
IT33129MULTIPLE SECURE BACKUPS MIGHT CAUSE A RELOAD
IT33142IN API GATEWAY, THE "X-GLOBAL-TRANSACTION-ID" HEADER IS NOT GENERATED FOR SOME API CALLS
IT33166SUBSCRIPTION ERROR IF MULTIPLE PRODUCTS WITH SAME API PATH
IT33185A TRANSACTION MIGHT HANG UNTIL A RELOAD IF THERE IS AN ERROR IN ITS HANDLER
IT33203DATAPOWER MIGHT RESTART CAUSED BY POST-HOOK GATEWAYSCRIPT
IT33215KAFKA CLUSTER FAILS TO COME UP WITH BROKER CONFIGURATION ERROR
IT33220RBM PASSWORD AGING INTERFERES WITH CONFIGURATION SEQUENCES THAT USE AN ACCESS PROFILE
IT33232INVALID DOMAIN NAME IS LOGGED IF AUTHENTICATION FAILS AND AN INVALID DOMAIN NAME IS USED.
IT33233"CONTENT ENCODING" HEADER SET WITH EMPTY BODY RESPONSE THROWS A READ ERROR
IT33247SUPPRESS AUTOMATIC GENERATION OF SSH DSA KEYS
IT33251QUEUE MANAGER CONNECTION FAILURE WHEN USING "MQ://" PROTOCOL IDENTIFIER IN API GATEWAY GATEWAYSCRIPT
IT33327CONSUMER APPLICATION GETS 401 UNAUTHORIZED AFTER INTRODUCING A NEW VERSION OF AN API WITH DIFFERENT SECURITY CONFIGURATION
IT33351XSS AND HTML INJECTION VULNERABILITY
IT33374ADDING AN ASSEMBLY FUNCTION WITH THE RATE LIMIT ACTION TO API CONNECT GATEWAY SERVICE THROWS ERROR
IT33375MEMORY GROWTH MIGHT OCCUR DURING PAYLOAD LOGGING
IT33401ENABLE ALLOW COMPRESSION BY DEFAULT FOR THE HANDLERS CREATED BY API CONNECT INTEGRATION
IT33450THE DATAPOWER WEBGUI MIGHT BE SLOW LOADING A MULTI-PROTOCOL GATEWAY
IT33455UNEXPECTED RELOAD DUE TO MEMORY CORRUPTION IN TLS
IT33460JSON SCHEMA THAT FAILS COMPILATION WITH INVALID REFERENCE OR INVALID JSON SYNTAX DOES NOT LOG SPECIFIC ERROR
IT33536DATAPOWER "DYN:EVALUATE()" XSLT COMPILED CODE CACHE ALLOWS FOR ONLY 32 ENTRIES
IT33543DATAPOWER MIGHT WATCHDOG RELOAD WHILE READING AND SAVING A CONFIGURATION AT THE SAME TIME
IT33551ENABLE LLDP ON THE ETHERNET INTERFACES
IT33597WHEN USING API GATEWAY, A PAYLOAD WITH THE "OPTIONS" CALL ECHOES THE RESPONSE
IT33741DATAPOWER CAN RESTART ON A RARE WEBGUI ACTIVITY RACE CONDITION
IT33747REINITALIZING WITH 10.0.0.0 FIRMWARE LOSES THE IBM MQ FEATURE
IT34050X-IBM-CLIENT-ID HEADER EXTRA VALUES IS IGNORED IN OAUTH AUTHENTICATION

Back to top


10.0.0.0

Release date: 17 June 2020
Last modified: 17 June 2020
Status: Available

APAR
Description
IT19885DATAPOWER XMI SCHEMA FOR B2B-QUERY-METADATA RESPONSE IS MISSING IN XML-MGMT-OPS.XSD
IT31897CUSTOM POLICIES DIRECTORIES WILL GET REMOVED ON DRR
IT32293GWS CLI DEBUGGER PRINT COMMAND FAILS IF THE VALUE HAS A SPACE INIT
IT32372CANNOT MODIFY VARIABLES USING THE SCOPE PANEL WHEN DEBUGGING GATEWAYSCRIPT REMOTELY
IT32380REFRESH TOKEN SCOPE IS IGNORED IN API CONNECT GATEWAY SERVICE
IT32445SSL CLIENT PROFILE FAILS TO WORK IN GATEWAYSCRIPT URLOPEN
IT32486GWS ACTION CAN LEAK MEMORY WHEN THE TRANSACTION ENCOUNTERS A FATAL ERROR
IT32565SNMP USER ACCOUNTS MAY ENCOUNTER AN ERROR WHEN ASSIGNING A KEY GENERATED FROM PLAINTEXT.
IT32585API CONNECT GATEWAY SERVICE CAN RESTART THE DEVICE IF MISCONFIGURED.
IT32617EXPIRED SUBSCRIBER DATA INCORRECTLY MANAGED BY API SUBSCRIPTION GATEWAY PEERING
IT32620USER DEFINED POLICIES CANNOT HAVE THE NAME AS AN OUT-OF-BOX POLICY EVEN IF THE VERSIONS DO NOT MATCH
IT32626PREPARING SCHEMA VALIDATION ACTION CAUSES RELOAD
IT32642CONTINUOUS ERROR MESSAGES EVEN AFTER POLICY HAS REACHED CONSENSUS
IT32697SET PASSWORD ALIAS MAP TO DOWN WHEN IMPORT FAILS DUE TO LACK OF MASKED SETTING
IT32770SECURITY VULNERABILITY IN "MINIMIST" PACKAGE (API CONNECT GATEWAY SERVICE)
IT32781A CATALOG HAVING MORE THAN ONE USER DEFINED POLICY, ONLY ONE OF THE POLICIES IS RESTORED BY DRR
IT32798USER DEFINED POLICIES ARE NOT ADVERTISED TO API MANAGER ALTHOUGH GATEWAY REGISTRATION DATA IS AVAILABLE
IT32800ILLEGAL CATALOG METADATA CAN LEAD TO A CATALOG OUTAGE
IT32839UPDATE FOR LOW LEVEL CODE ON 4 PORT 10 GB MODULE
IT32914X-FORWARDED-FOR HEADER SHOULD BE SANITIZED FOR CORRECT ANALYTICS DATA
IT32982IF INVOKE PASSWORD CONTAINS THE = CHARACTER, IT IS CONVERTED TO &#X3D
IT33002NATIVE DATAPOWER SERVICE VARIABLES ARE NOT AVAILABLE IN API GATEWAY
IT32942WHEN FIRST RULE IN A POLICY CONTAINS ONLY ONE PROCESSING ACTION, EDITOR SHOWS ONLY THE MATCHING ACTION
IT33271UDP WITH FILES OUTSIDE OF 'LOCAL:POLICY/' ACROSS MULTIPLE CATALOGS MIGHT NOT BE IMPORTED

Back to top


Change history
Last modified: 24 April 2024

  • 24 April 2024: Added fix list for the 10.0.1.19 fix pack.
  • 1 March 2024: Added fix list for the 10.0.1.18 fix pack.
  • 8 December 2023: Added fix list for the 10.0.1.17 fix pack.
  • 25 October 2023: Added fix list for the 10.0.1.16 fix pack.
  • 30 August 2023: Added fix list for the 10.0.1.15 fix pack.
  • 28 June 2023: Added fix list for the 10.0.1.14 fix pack.
  • 26 April 2023: Added fix list for the 10.0.1.13 fix pack.
  • 22 February 2023: Added fix list for the 10.0.1.12 fix pack.
  • 18 January 2023: Added IT42171 to 10.0.1.10 fix list.
  • 5 January 2023: Added IT42667 to 10.0.1.10 fix list.
  • 14 December 2022: Added fix list for 10.0.1.11 fix pack.
  • 26 October 2022: Added fix list for 10.0.1.10 fix pack.
  • 24 August 2022: Added fix list for 10.0.1.9 fix pack.
  • 21 June 2022: Added fix list for 10.0.1.8 fix pack.
  • 28 April 2022: Added fix list for 10.0.1.7 fix pack.
  • 30 March 2022: Added fix list for 10.0.1.6sr1 security refresh.
  • 21 February 2022: Added fix list for 10.0.1.6 fix pack.
  • 1 October 2021: Added fix list for 10.0.1.5 fix pack.
  • 6 August 2021: Added fix list for 10.0.1.4 fix pack.
  • 2 April 2021: Added fix list for 10.0.1.3 fix pack.
  • 29 January 2021: Added fix list for 10.0.1.2 fix pack.
  • 9 December 2020: Added fix list for 10.0.1.1 fix pack.
  • 30 September 2020: Added fix list for 10.0.1.0 fix pack.
  • 17 August 2020: Added fix list for 10.0.0.1 fix pack.
  • 17 June 2020: Created fix list for 10.0.0.0 fix pack.

Off

Document Location

Worldwide

[{"Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateway"},"ARM Category":[{"code":"a8m50000000L0rqAAC","label":"DataPower"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"10.0.1"}]

Problems (APARS) fixed
IT19885; IT31897; IT32293; IT32372; IT32380; IT32445; IT32486; IT32565; IT32585; IT32617; IT32620; IT32626; IT32642; IT32697; IT32770; IT32781; IT32798; IT32800; IT32839; IT32914; IT32982; IT33002; IT32942, IT33271; IT32051; IT32283; IT32296; IT32522; IT32758; IT32782; IT32931; IT32934; IT32964; IT32966; IT33003; IT33036; IT33116; IT33129; IT33142; IT33166; IT33185; IT33203; IT33215; IT33220; IT33232; IT33233; IT33247; IT33251; IT33327; IT33351; IT33374; IT33375; IT33401; IT33450; IT33455; IT33460; IT33536; IT33543; IT33551; IT33597; IT33747; IT34050; IT31762; IT32057; IT32347; IT32349; IT32577; IT32876; IT32937; IT33441; IT33495; IT33551; IT33588; IT33673; IT33679; IT33727; IT33741; IT33775; IT33778; IT33779; IT33845; IT33890; IT33897; IT33898; IT33923; IT33953; IT33967; IT33975; IT33981; IT33989; IT34009; IT34014; IT34016; IT34027; IT34034; IT34047; IT34068; IT34070; IT34075; IT34084; IT34142; IT34144; IT34159; IT34175; IT34176; IT34198; IT34236; IT34256; IT34264; IT34285; IT34286; IT34287; IT34307; IT34326; IT34333; IT34339; IT34349; IT34366; IT34370; IT34376; IT34387; IT34388; IT34405; IT34413; IT34420; IT34444; IT34447; IT34462; IT34467; IT34481; IT34492; IT34530; IT34598; IT34611; IT34616; IT34621; IT34627; IT34635; IT34652; IT34657; IT34706; IT34724; IT34760; IT34769; IT34805; IT34809; IT34858; IT34870; IT34888; IT34894; IT34914; IT34922; IT34930; IT34948; IT34954; IT35000; IT35179; IT35203; IT32643; IT32767; IT33795; IT33856; IT33927; IT34586; IT34610; IT34677; IT34798; IT34843; IT34845; IT34847; IT34848; IT34915; IT34923; IT34971; IT34996; IT34999; IT35002; IT35003; IT35035; IT35038; IT35044; IT35051; IT35079; IT35090; IT35154; IT35160; IT35172; IT35196; IT35232; IT35239; IT35242; IT35251; IT35253; IT35266; IT35275; IT35288; IT35315; IT35316; IT35317; IT35324; IT35327; IT35364; IT35401; IT35441; IT35447; IT35449; IT35451; IT35452; IT35493; IT35571; IT35769; IT33579; IT34576; IT34675; IT34680; IT34742; IT34767; IT35177; IT35219; IT35248; IT35370; IT35454; IT35462; IT35492; IT35498; IT35529; IT35543; IT35677; IT35724; IT35729; IT35737; IT35825; IT35836; IT35863; IT35868; IT35869; IT35870; IT35871; IT35873; IT35895; IT35909; IT35921; IT35924; IT35928; IT35930; IT35938; IT35980; IT35988; IT35990; IT35996; IT36032; IT36039; IT36078; IT36089; IT36101; IT36121; IT36129; IT36325; IT36586; IT21079; IT32464; IT33993; IT35157; IT35539; IT35554; IT36001; IT36084; IT36096; IT36109; IT36120; IT36143; IT36156; IT36162; IT36180; IT36191; IT36204; IT36219; IT36268; IT36332; IT36346; IT36407; IT36415; IT36417; IT36448; IT36463; IT36471; IT36479; IT36481; IT36517; IT36579; IT36585; IT36597; IT36624; IT36625; IT36627; IT36635; IT36637; IT36655; IT36705; IT36714; IT36723; IT36726; IT36727; IT36732; IT36779; IT36780; IT36822; IT36838; IT36843; IT36946; IT36949; IT36963; IT36988; IT37018; IT37035; IT37053; IT37082; IT37131; IT37152; IT37175; IT37214; IT37331; IT37464; IT37523; IT37577; IT37278; IT37933; IT35948; IT36456; IT36675; IT36703; IT36736; IT36786; IT36859; IT37053; IT37093; IT37200; IT37244; IT37281; IT37332; IT37334; IT37348; IT37354; IT37362; IT37388; IT37474; IT37506; IT37513; IT37552; IT37601; IT37603; IT37616; IT37636; IT37653; IT37666; IT37691; IT37706; IT37722; IT37750; IT37766; IT37770; IT37779; IT37782; IT37826; IT37855; IT37856; IT37923; IT37924; IT37929; IT37931; IT37935; IT37936; IT37949; IT37950; IT37962; IT37967; IT37975; IT37976; IT37984; IT37992; IT37993; IT37994; IT38005; IT38026; IT38071; IT38072; IT38088; IT38089; IT38095; IT38096; IT38112; IT38114; IT38151; IT38154; IT38160; IT38167; IT38175; IT38176; IT38185; IT38193; IT38220; IT38292; IT38387; IT39994; IT40053; IT40215; IT40243; IT40259; IT40373; IT40394; IT40487; IT35779; IT37659; IT38066; IT39549; IT39604; IT39610; IT39663; IT39746; IT39795; IT39804; IT39882; IT39912; IT39926; IT39947; IT39948; IT39989; IT40034; IT40038; IT40039; IT40073; IT40078; IT40079; IT40097; IT40132; IT40139; IT40152; IT40185; IT40187; IT40189; IT40264; IT40321; IT40341; IT40342; IT40376; IT40377; IT40395; IT40420; IT40500; IT40510; IT40518; IT40531; IT40603; IT40640; IT40374; IT36680; IT38064; IT39017; IT39614; IT39825; IT40037; IT40387; IT40583; IT40635; IT40663; IT40664; IT40753; IT40760; IT40767; IT40777; IT40801; IT40823; IT40856; IT40934; IT40935; IT40946; IT40957; IT40964; IT40969; IT41091; IT41106; IT41431; IT38203; IT40045; IT40541; IT40589; IT40689; IT40721; IT40765; IT40997; IT41008; IT41031; IT41039; IT41043; IT41078; IT41101; IT41112; IT41156; IT41179; IT41246; IT41262; IT41307; IT41310; IT41311; IT41350; IT41377; IT41385; IT41395; IT41401; IT41414; IT41419; IT41433; IT41442; IT41446; IT41448; IT41450; IT41909; IT41574; IT31382; IT36173; IT38762; IT39395; IT41159; IT41163; IT41319; IT41352; IT41394; IT41459; IT41521; IT41551; IT41552; IT41558; IT41600; IT41601; IT41632; IT41657; IT41677; IT41678; IT41685; IT41699; IT41737; IT41741; IT41776; IT41786; IT41794; IT41801; IT41802; IT41817; IT41896; IT41908; IT41936; IT41963; IT42005; IT42051; IT42095; IT42101; IT42104; IT42141; IT42165; IT42203; IT42234; IT42060; IT42166; IT42231; IT42300; IT40689; IT41601; IT41642; IT41910; IT42076; IT42089; IT42162; IT42249; IT42255; IT42263; IT42293; IT42299; IT42336; IT42356; IT42364; IT42372; IT42375; IT42400; IT42406; IT42478; IT42479; IT42483; IT42493; IT42510; IT42520; IT42528; IT42543; IT42667; IT42171; IT42063; IT42064; IT42421; IT42488; IT42521; IT42524; IT42538; IT42571; IT42616; IT42655; IT42729; IT42733; IT42734; IT42735; IT42742; IT42755; IT42804; IT42849; IT42955; IT42978; IT42982; IT42983; IT42984; IT42987; IT42996; IT39416; IT41761; IT42607; IT42681; IT42988; IT43070; IT43083; IT43095; IT43121; IT43122; IT43137; IT43155; IT43156; IT43157; IT43161; IT43168; IT43202; IT43223; IT43232; IT43234; IT43245; IT43246; IT43253; IT43254; IT43257; IT43288; IT43292; IT43298; IT43318; IT43331; IT43332; IT43340; IT43359; IT43360; IT43363; IT43379; IT43389; IT43390; IT43393; IT43402; IT43421; IT43430; IT43431; IT43432; IT43434; IT43441; IT43474; IT43475; IT43487; IT43500; IT43519; IT43551; IT43572; IT43640; IT43160; IT42057; IT41417; IT42480; IT43264; IT43358; IT43661; IT39216; IT41799; IT43107; IT43125; IT43150; IT43251; IT43409; IT43445; IT43506; IT43513; IT43524; IT43593; IT43595; IT43640; IT43681; IT43703; IT43730; IT43755; IT43769; IT43773; IT43813; IT43814; IT43839; IT43850; IT43852; IT43853; IT43871; IT43873; IT43890; IT43891; IT43899; IT43900; IT43907; IT43915; IT43917; IT43919; IT43924; IT43931; IT43933; IT43935; IT43980; IT44028; IT44112; IT44114; IT43729; IT42195; IT42964; IT43003; IT43809; IT43870; IT43925; IT43927; IT43943; IT43995; IT44115; IT44126; IT44143; IT44145; IT44165; IT44208; IT44231; IT44237; IT44240; IT44255; IT44257; IT44262; IT44280; IT44281; IT44293; IT44338; IT44339; IT44340; IT44341; IT44351; IT44381; IT44383; IT43641; IT44630; IT44654; IT44026; IT44141; IT44196; IT44360; IT44427; IT44438; IT44453; IT44461; IT44470; IT44481; IT44487; IT44507; IT44509; IT44515; IT44543; IT44557; IT44558; IT44580; IT44588; IT44591; IT44605; IT44650; IT44665; IT44716; IT44720; IT44748; IT45049; IT43302; IT43425; IT44179; IT44212; IT44514; IT44538; IT44544; IT44732; IT44752; IT44766; IT44768; IT44788; IT44799; IT44803; IT44822; IT44826; IT44843; IT44844; IT44845; IT44846; IT44861; IT44874; IT44877; IT44903; IT44916; IT44923; IT44962; IT44963; IT44969; IT44976; IT44978; IT44987; IT44988; IT44991; IT44992; IT45033; IT45034; IT45065; IT45068; IT45493; IT44150; IT44405; IT44823; IT44917; IT44959; IT44975; IT45008; IT45032; IT45057; IT45086; IT45129; IT45132; IT45133; IT45134; IT45144; IT45159; IT45180; IT45214; IT45227; IT45254; IT45321; IT45323; IT45337; IT45340; IT45341; IT45347; IT45359; IT45367; IT45368; IT45387; IT45393; IT45402; IT45404; IT45406; IT45441; IT45455; IT45495; IT45576; IT44537; IT45245; IT45298; IT45308; IT45330; IT45355; IT45357; IT45514; IT45542; IT45570; IT45582; IT45664; IT45666; IT45668; IT45669; IT45699; IT45742; IT45743; IT45764; IT45769; IT45773; IT45774; IT45777; IT45787; IT45820; IT45829; IT45830; IT45833; IT45853; IT45866; IT45869; IT45899; IT45930; IT45944; IT45515;

Document Information

Modified date:
05 January 2026

UID

ibm16205303