IBM Support

Fix List for Sterling B2B Integrator V6.1.0.0

Fix Readme


Abstract

This page contains comprehensive fix information for all Fix Packs released for Sterling B2B Integrator and Sterling File Gateway V6.1.0.0 and later versions.

Content

  IBM periodically releases fix packs for download to resolve issues in Sterling B2B Integrator. All Sterling B2B Integrator customers should download the most recently available fix pack and apply it to their environments.
Follow these steps to update your system:

  1. Download the fix pack from Fix Central.
  2. Install the fix pack on each node in your environment. Remember that a node outage is required. You should apply the fix pack to your test environment first and run regression tests against it before applying it to production.

Mod Pack (v6.1.0.0)
LinkDate ReleasedStatus
Download
Note: This Fix Pack also contains APAR security and regular fixes from 5263_155.2.6.4_45.2.6.5_2, 6.0.2.2, and 6.0.3.2 releases.
 

Security Fixes

 
APARDescription
IT33331REST API CREDENTIALS ARE SHOWN IN THE LIBERTY LOGS
IT33520PERMISSION CONTROL SECURITY VULNERABILITY EXISTS IN DASHBOARD UI
IT33724    GLOG COOKIE DOES NOT HAVE SECURE OR HTTPONLY FLAG ON
IT33753FTP SERVER LOGS STORE USER PASSWORDS WHEN PASS COMMAND USED VIA TELNET
IT33882 A USER CAN VIEW THE DIRECTORY STRUCTURE OF STERLING B2B INTEGRATOR HOST WITHOUT PERMISSION
IT33991 XSS SECURITY VULNERABILITY IN IMPORT MANAGER OF DASHBOARD UI
IT33523PERMISSION CONTROL SECURITY VULNERABILITY EXISTS IN ACCOUNT MANAGEMENT DASHBOARD UI             
IT32838SPE REMOTE MAP TEST SSL ERROR VERSION OF JAVA RUNTIME DOES NOT SUPPORT THE TLS VERSION ON THE SERVER

Regular Fixes

APARDescription
IT32280ERROR IN USEREXIT LOG FOR ANY USER AUTHENTICATED WITH THE REST API
IT32339CREATESCHEDULE XAPI UNABLE TO PASS NAME OR VALUE PAIRS TO SCHEDULE IN DATAXML
IT32786SPLASH PAGE LOADED FOR FILE GATEWAY AFTER UPGRADING TO 6.0.3
IT33034MAILBOXAS2SENDSYNCMDN IS NOT NOTIFYING A FAILURE ON THE AS2 TRANSMISSION AND THE MESSAGE SENT REMAINS LOCKED
IT33301SOFTSTOP.SH DOES NOT WORK IN 6.0.3
IT32812AFTER UPGRADE TO 6.0.1, AND DEPLOYMENT OF WAR FILES THE HTTP SERVER ADAPTER SESSION INFORMATION IS NOT DISPLAYED
IT32704THE REST API CLIENT SERVICE GET FAILS WHEN URL INCLUDES COMMA
IT33624   AIX B2B INTEGRATOR CLUSTER NOAPP PROCESSES STILL RUN AFTER RUNNING SOFTSTOP.SH ALL AND HARDSTOP
IT33465JAVA.LANG.NULLPOINTEREXCEPTION IN UI.LOG WHEN CHANGING SYSTEM CERTIFICATE NAME
IT29000IF X12 EDI DATA IS 00402 OR GREATER, ENVELOPE SERVICE DOES NOT USE THE ISA 11 CHARACTER TO SEPERATE ELEMENTS MARKED REPETITIVE
IT32350UNABLE TO IMPORT THE EXPORT OF USER ACCOUNTS WITH PASSWORD POLICY INTO ANOTHER INSTANCE
IT33182MAILBOX DOES NOT THROW AN ERROR WHEN USING THE COMMAND SFTP     
CLIENT TO LIST FILES IN GLOBAL MAILBOX                          
IT34153ERROR WHEN UPGRADING IBM STERLING B2B INTEGRATOR FROM V5.2 to
V6.0.x AS PART OF BTI INTEGRATION SERVICE                    
IT33958XML JSON TRANSFORMER SERVICE STAYS ACTIVE INDEFINITELY WHEN     
TRANSFORMING AN XML FILE TO JSON                                
 

Fix Pack (V6.1.0.1)
 
LinkDate ReleasedStatus
 No Longer Available
Note: This Fix Pack also contains APAR security and regular fixes from 6.0.3.3 and 6.0.2.3 releases.
 

Security Fixes

 
APARDescription
IT35207CDSA SECURE+ SESSIONS CONFIGURED WITH ECDSA-BASED CIPHERS FAIL AFTER UPGRADING FROM 6.0.3.0 TO 6.0.3.3  
IT35348SECURITY VULNERABILITY: PERMISSION CONTROL SECURITY VULNERABILITIES AFFECT THE DASHBOARD UI

Regular Fixes

APARDescription
IT34636SFTP USER EXIT FAILS WHEN GLOBAL MAILBOX IS TURNED ON FOR THE SFG ACCOUNT AND A NULL POINTER EXCEPTION IS SEEN IN SFTPSERVER.LOG    
IT32906CROSS-SITE SCRIPTING VULNERABILITY - /FILEGATEWAY/SMARTCLIENTRPC.DO    
IT34961UNABLE TO LOG IN TO STERLING FILEGATEWAY WITH SPANISH LOCALIZATION: REFERENCE ERROR: FG_I18N IS NOT DEFINED    
IT33335FILE ROUTING AND SFTP UPLOADS VIA GLOBAL MAILBOX TAKES MORE TIME THAN TRADITIONAL MAILBOX    
IT34577AWSS3 CLIENT GET ACTION, NEITHER KEEPS THE DOCUMENT IN PROCESS-DATA NOR IN DOWNLOADED-FILE-NAME    
IT34917POST INSTALLATION OF DOCKER AND THE STANDARDS JAR AS MENTIONED IN DOCUMENTATION STRLING FILE GATEWAY GETS ENABLED   
IT34599GB18030 CHARACTERS ARE INCORRECTLY DISPLAYED   
IT35032GENCON GARBAGE COLLECTION POLICY IS OUTDATED AND DOESN'T WORK WELL WITH NEWER ENVIRONMENTS
IT35031CHANGING DEFAULT VISIBILITY OF QUEUES TO 6 
IT34569GB18030 CHARACTERS DON'T DISPLAY CORRECTLY   
IT34935IMPLEMENTATION OF CONNECTION POOLING FOR WSMQ SUITE  
IT34898STERLING B2B INTEGRATOR 6.1 IIM INSTALL PACKAGE UI DISPLAYS UNREADABLE JAPANESE CHARACTER    
 

Fix Pack (V6.1.0.2)
 
LinkDate ReleasedStatus
 No Longer Available
Note: This Fix Pack also contains APAR security and regular fixes from 6.0.3.4 release.
 

Security Fixes

 
APARDescription
IT35181THE FILEGATEWAY AND MYFILEGATEWAY USER INTERFACES LACK SUFFICIENT PERMISSION CONTROL 
IT35605ACCESS CONTROL VULNERABILITY AFFECTS IBM STERLNG FILE GATEWAY (CVE-2021-20372)
IT35654ACCESS SECURITY CONTROL VULNERABILITY AFFECTS IBM STERLING FILE GATEWAY (CVE-2021-20375)
IT35660SECURITY VULNERABILITY: USER ENUMERATION VULNERABILITY IN MYFILEGATEWAY USER INTERFACE                                     
IT35837SECURITY VULNERABILITY: SESSION FIXATION SECURITY VULNERABILITY IN FILEGATEWAY
IT35845CROSS SITE SCRIPTING VULNERABILITY 6.1 (PERSISTENT XSS)       
IT37912IBM WEBSPHERE MQ (PUBLICLY DISCLOSED VULNERABILITY)

Regular Fixes

APARDescription
IT31929IBM STERLING B2B INTEGRATOR HAS SLOW FILE TRANSFER DOWNLOAD     
VIA THE SFTP CLIENT GET SERVICE
IT35721IBM STERLING B2B INTEGRATOR USES THE AFFECTED FUNCTIONALITY WITHIN XSTREAM LIBRARIES FOR CVE-2020-26217    
IT35738EMAIL ADDRESS IS INCLUDED IN HTTP RESPONSE AFTER USER LOGIN 
IT35845CROSS SITE SCRIPTING VULNERABILITY 6.1 (PERSISTENT XSS)       
IT35920TEMP COOKIE FROM DASHBOARD UI DOES NOT HAVE HTTPONLY OR SECURE SET                      
 

Fix Pack (V6.1.0.3)
 
LinkDate ReleasedStatus
Download
Note: This Fix Pack also contains APAR security and regular fixes from 5.2.6.5_4, 6.0.3.4, and 6.0.0.6 release.
 

Security Fixes

 
APARDescription
IT35458SECURITY VULNERABILITY: [ALL] ECLIPSE JETTY (PUBLICLY DISCLOSED VULNERABILITY)
IT36390SECURITY VULNERABILITY: MYFILEGATEWAY USER CAN UPLOAD THE FILE EVEN THOUGH THE UPLOAD TAB IS DISABLED
IT36447SECURITY VULNERABILITY: 3RD PARTY STORED CROSS SITE SCRIPTING IN IBM STERLING B2B INTEGRATOR
IT36570SECURITY VULNERABILITY: INFORMATION DISCLOSURE SECURITY VULNERABILITY IN THE DASHBOARD USER INTERFACE
IT36609SECURITY VULNERABILITY: PERSISTENT XSS SECURITY VULNERABILITY EXISTS IN THE WEB SERVICE MANAGEMENT USER INTERFACE
IT36300SECURITY VULNERABILITY - MYFILEGATEWAY FILE-NAME COULD BE INTERCEPTED TO INJECT DISALLOWED CHARACTERS IN FILENAME
IT36280SECURITY VULNERABILITY: MYFILEGATEWAY UI DISPLAYS SENSITIVE INFORMATION AFTER LOGOUT
IT38515APACHE KAFKA VULNERABILITIES AFFECT THE B2B API OF IBM STERLING B2B INTEGRATOR (CVE-2017-12610, CVE-2018-1288)
IT37914UPGRADE NETTY JAR (CVSS 9.1)
IT37682UPDATE APACHE TOMCAT JARS (CVSS 9.8)
IT37681UPGRADE XML BEAN (CVSS 9.1)
IT38512UPDATE JACKSON-DATABIND JAR (CVSS 9.8)
IT37913UPDATE BOUNCY CASTLE JAR IN GATEWAY.WAR (CVSS 9.8)
IT36552UPDATE JASPERREPORTS (CVSS 8.8)
IT36688SECURITY VULNERABILITY: CSRF TOKEN APPEARS IN THE URLS FOR FILEGATEWAY USER INTERFACE (AFT)

Regular Fixes

APARDescription
IT34735AWS S3 CLIENT SERVICE GET OPERATION UNABLE TO GET THE DOCUMENTS AND LIST THEM AS PRIMARY DOCUMENTS
IT35379AWS S3 CLIENT SERVICE DOES NOT DELETE THE TEMPORARY FILES CREATED WHEN DOCUMENTS OR FILES ARE SENT FROM MAILBOX TO AWS S3 STORAGE
IT36079RCT CREATION USING SPECIAL CHARACTERS DOES NOT WORK IN THE SWAGGER UI
IT36097INCORRECT PATH SPECIFIED IN DECRYPT_STRING.CMD SCRIPT
IT36217UNABLE TO UPDATE THE USER ACCOUNT API WITH CUSTOM PASSWORD POLICY
IT36272V6.1 NODE2 CHECKBOX IS HIDDEN IN THE IIM INSTALLATION PANEL
IT36286THE CHECKBOX FOR DATABASE SCHEMA INFORMATION IS HIDDEN IN THE IIM INSTALLATION PANEL
IT36335FILE SYSTEM ADAPTER FAILS TO COLLECT FILENAMES WITH LATIN CHARACTERS SPECIFIC TO AIX
IT36649UNABLE TO SET THE "REVIEWED" TICK ON FILEGATEWAY IN V6.1.0.2 ON AN ARRIVED FILE
IT36687WITH NATIVE PGP, PGP PACKAGE SERVICE RESULTS IN BLANK ENCRYPTED DOCUMENT WHEN A SMALL FILE IS ENCRYPTED AND DOCUMENT STORAGE IS FILE SYSTEM
IT36696NATIVE PGP DOES NOT WORK WHEN DOCUMENT ENCRYPTION IS  ENABLED
IT36710DUMPINFO OUTPUT FILE SHOWS REPETITION OF LICENSE, DBINFO, AND JVMINFO IN A WINDOWS SETUP
IT37063CONSUMER PROTOCOL IN ROUTING CHANNEL TEMPLATE IS UPDATED FROM "MAILBOX ONLY" TO "PROTOCOL OR MAILBOX" WHEN THE ROUTING CHANNEL TEMPLATE IS IMPORTED FROM V5.6.6.3 TO V6.1
 

Fix Pack (V6.1.0.4)
 
LinkDate ReleasedStatus
Download
Note: This Fix Pack also contains APAR security and regular fixes from 6.0.3.5 release.
 

Security Fixes

 
APARDescription
IT37848UPGRADE LOG4J (CVSS 7.8)
IT37693UPDATE APACHE COMMONS BEANUTILS (CVSS 7.5)
IT37615UPDATE APACHE XCERCES2 J (CVSS 7.5)
IT38514UPDATE APACHE TAGLIBS (CVSS 7.5)
IT37678UPGRADE DATA MAPPER FOR JACKSON (CVSS 7.5)
IT38149UPDATE JBOSS DROOLS (CVSS 7.5)
IT36447SECURITY VULNERABILITY: 3RD PARTY STORED CROSS SITE SCRIPTING IN IBM STERLING B2B INTEGRATOR
IT37677UPGRADE JACKSON DATAFORMATS JAR (CVSS 7.5)
IT38515APACHE KAFKA VULNERABILITIES AFFECT THE B2B API OF IBM STERLING B2B INTEGRATOR (CVE-2017-12610, CVE-2018-1288)
IT38674IBM STERLING B2B INTEGRATOR IS VULNERABLE TO CROSS-SITE REQUEST FORGERY (CVE-2020-4668)

Regular Fixes

APARDescription
IT38047EBICS PARTNERS WITH ENTRIES IN STERLING FILE GATEWAY - PARTNERS ARE LEFT WHEN ENTRIES IN PROFILE MANAGER - PARTNER CONFIGURATION ARE DELETED
IT37875STERLING B2BI-RESTAPI-GETPAYLOADDATA FAILS IN V6.1.0.2
IT37845USER HAVING PROBLEM LOGGING INTO MYFG2.0 AFTER CLOSING BROWSER
IT37843FILTERS MYFG2.0
IT37343ERROR WHEN USING JMS 1,1 ACQUIRE CONNECTION AND SESSION SERVICE WITH SSL AND DESTINATION TYPE AS TOPIC
IT37631USING JDBCSERVICE.LWJDBC.WRITEDOCFORNONSELECT FUNCTION CREATES ERROR IN SYSTEM.LOG
IT37688USER RESTRICTION IN SFTP SERVER ADAPTER IS ONLY WORKING WITH PASSWORD AUTHENTICATION BUT NOT WITH PUBLIC KEY AUTHENTICATION
IT37718MISSING TRANSLATION IN THE POP-UP MESSAGE PT-BR MYFG2.0
IT36708ROUTING CHANNELS WITH A GLOBAL MAILBOX PRODUCER CANNOT BE IMPORTED VIA THE IMPORT SERVICE IN A BP
IT37692EBICS SERVER GENERATES DUPLICATE ORDER IDS
IT38235CUSTOMIZATION LINK IS NOT ACCESSIBLE
IT38442EBICS BANK - GERMAN ORDER TYPES - TEST PARAMETER HANDLING
IT36996FILEGATEWAY RE-DLIVER USING REST API TRIGGERS TWO FILES INSTEAD OF ONE FILE CREATING DUPLICATES ON CONSUMER SIDE
IT38579MANY ENTRIES LIKE THE INSIDE SSHKEYDBINFOBASE SETTING RAW KEY AFTER UPGRADE
IT37296SBI NATIVE PGP ERROR WHEN DECRYPTING FILE FROM SYMANTEC COMMAND LINE PGP
IT37771ERROR "JAVAX.NAMING.COMMUNICATIONEXCEPTION [ROOT EXCEPTION IS JAVA.RMI.NOSUCHOBJECTEXCEPTION: NO SUCH OBJECT IN TABLE]" IN OPS.LOG AFTER UPGRADING TO 6.1.0.2
IT36929CASE SENSITIVE ISSUE OF FILENAME FILTER IN SFTP CLIENT SERVICES 2.0 IN BP FOR ".PDF" / ".PDF" IN 6.1 VERSION
IT37921EBICS CLIENT SERVICES DOES NOT REPORT PROPERLY FAILURE STATUS
IT36405INCORRECT MQ POOLING BEHAVIOR FOR TLS CHANNELS, CONNECTIONS ARE NOT BEING RE-USED
IT36406WEBSPHERE MQ SUITE ASYNC RECEIVE ADAPTER RECONNECT FAILURE
IT37288CANNOT CREATE A CERTIFICATE CONTAINING SPACES USING REST API ALTHOUGH FROM THE DASHBOARD THEY ARE ALLOWED
IT38067AFTER UPGRADE TO 61,WSMQ ASYNCH RECEIVE ADAPTER DOESNT PULL MESSAGES WHEN QM IS LEFT BLANK
IT32183REVERT FIX FOR IT32183 - AS2INBOUND WORKFLOW PROCESSES OUTBOUND MDN INSTEAD OF ACTUAL PAYLOAD WHENEVER EDIINTPIPELINEPARSE FAILS
IT38091USERACCOUNTS LIST API ALONG WITH QUERY PARAMETERS IS THROWING AN ERROR
IT37208EDIT OF PARTNERS IN SFG NOT POSSIBLE ANYMORE WITH ITALIAN LANGUAGE SET IN BROWSER
IT38454CACHE REFRESH SERVICE NOT REFRESHING PROPERTIES DELETED VIA THE CUSTOMIZATION UI
IT37558ISSUE WITH THE DEFAULT PASSWORD POLICY ON FIRST LOGIN IN B2BI V6.1.0.1 DASHBOARD
IT38036NULLPOINTEREXCEPTION RAISED WHEN TRYING TO VIEW DATA FLOW DETAILS
IT38132COMMUNICATION SESSIONS ARE NOT CLOSED WHEN SFTP SERVER IS USED WITH GLOBAL MAILBOX
IT36968HPB ORDER TYPE EBICS CLIENT DOES RECEIVE AN INVALID XML CHARACTER (UNICODE: 0X5) WHEN SECURITY.ENC_DECR_DOCS=ENC_ALL IS SET ON EBICS SERVER SIDE
IT38628CLEAN UP THE OLD JGROUPS-3.4.0.ALPHA2.JAR
IT38251HTTP GET SERVICE SETTING INVALID CONTENT TYPE, CAUSES ERRORS WITH GLOBAL MAILBOX
IT38630IF YOU CLICK FINISH MULTIPLE TIMES IN CREATE SSH HOST KEY, MULTIPLE DUPLICATE KEYS CREATED
 
iFix Pack (V6.1.0.4_1)
 
LinkDate ReleasedStatus
DownloadAvailable

Security Fixes

 
APARDescription
IT39380UPGRADE LOG4J TO 2.17.0

iFix Pack (V6.1.0.4_2)
 
LinkDate ReleasedStatus
DownloadCurrent

Regular Fixes

 
APARDescription
IT39649UNABLE TO CREATE A ROUTE ON A SUB-MAILBOX IN GLOBAL MAILBOX IF A ROUTE ALREADY EXISTS ON ANOTHER SUB-MAILBOX UNDER THE SAME PARENT MAILBOX
IT39935FILES ARE NOT BEING REMOVED FROM FILE SHARE EVEN THOUGH THEY ARE DELETING ALL MAILBOX MESSAGES AFTER 14 DAYS WITH A BUSINESS PROCESS
IT39936NULLPOINTEREXCEPTION OCCURRED IN DELETING MESSAGE WITH MAILBOX DELETE SERVICE FOR GLOBAL MAILBOX

Fix Pack (V6.1.0.5)
 
LinkDate ReleasedStatus
DownloadAvailable

Note: This Fix Pack also contains APAR security and regular fixes from 6.0.3.6 release.

Security Fixes

 
APARDescription
IT39737UPGRADE LOG4J TO 2.17.1
IT38878SECURITY VULNERABILITIES IN APACHE SANTURARIO AFFECT IBM STERLING B2B INTEGRATOR (CVE-2013-4517, CVE-2013-2172 CVSS 5.0)
IT40546DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT40945DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT40552IBM STERLING B2B INTEGRATOR VULNERABLE TO DENIAL OF SERVICE DUE TO XSTREAM (CVE-2021-43859)
IT38705INFORMATION DISCLOSURE SECURITY VULNERABILITY EXISTS IN THE REST B2B API IN IBM STERLING B2B INTEGRATOR
IT40669IBM STERLING FILE GATEWAY IS VULNERABLE TO MULTIPLE ISSUES DUE TO BOUNCY CASTLE
IT39545SECURITY VULNERABILITY IN APACHE COMMON IO AFFECTS IBM STERLING B2B INTEGRATOR (CVE-2021-29425 CVSS 7.5)

 

Regular Fixes

 
APARDescription
IT39649UNABLE TO CREATE A ROUTE ON A SUB-MAILBOX IN GLOBAL MAILBOX IF A ROUTE ALREADY EXISTS ON ANOTHER SUB-MAILBOX UNDER THE SAME PARENT MAILBOX
IT38915TEMPLATE SEARCH FROM SFG ROUTES > CHANNELS PAGE IS BROKEN
IT39689CAN EXTERNAL PURGE PROPERTIES BY MODIFIED IN THE CUSTOMIZATION UI?
IT38789WHEN OVERRIDING A PROPERTY VALUE IN CUSTOMER_OVERRIDES IN DB / CUSTOMIZATION UI. SHOULD THE NEW VALUE BE REFLECTED ON QUEUEWATCHER / VIEW PROPERTIES?
IT39642DBVERIFY.SH FOR REGRESSION-FORCE DBVERIFY.SH RUN DIRECTLY FROM COMMAND LINE PLACE RESULTING FILES IN <INSTALL_DIR>/BIN. REGARDLESS OF USE_CONNECTION_SERVICE_FOR_DBVERIFY PARAMETER VALUE
IT39308FG FILE SHOWN AS FAILED, BUT FILE SUCCESSFULLY DELIVERED TO PARTNER
IT38956BROKEN DOCUMENT FILE ICON ON EDI CORRELATION SCREEN AFTER UPGRADE TO 6102, FROM 5263
IT39987SI 6104_1 OFFSET ISSUE ON SI UI DASHBOARD WHILE USING CHROME BROWSER
IT38721CANNOT ACCESS CERTIFICATE CAPTURE UTILITY WITHOUT SYSTEM CERTIFICATES PERMISSION
IT38454QUEUE WATCHER NOT INCLUDING THE CUSTOMIZATION UI PROPERTIES
IT40230GET FUNCTIONALITY NOT WORKING FOR AWS S3 CLIENT ADAPTER IN WINDOWS
IT39664CANNOT USE FOLDERNAME ALONG WITH FILEPATTERN FOR AWS S3 GET ADAPTER
IT38947STERLING CONNECT DIRECT NETMAP SERVICES UPDATE AND DELETE FUNCTION SELECT THE WRONG NETMAP WHEN THE NETMAP NAMES ARE CASE SENSITIVE
IT39574THE CHINESE DASHBOARD IS GARBLED IN 6.1.0.4
IT39816REST API ALWAYS DELETES ALL VERSIONS OF A BP EVEN WHEN YOU SELECT A SPECIFIC VERSION TO BE DELETED
IT38702TRADING PARTNER API FAILING TO UPDATE PARTNER PASSWORD
IT38771BLANK PAGE WHEN TRYING TO CREATE SFG TRADING PARTNER
IT38904BLANK PAGE WHEN EDITING A SFG TRADING PARTNER
IT39453REST API MAX. FIELD LENGTH MISMATCH
IT40368IN SBI 6010001, THE SFTP CLIENT CONNECTION USING SFTP2.0 IS SUCESSFUL EVEN IF THE KNOWN HOST KEY IS INCORRECT IN THE SSH REMOTE PROFILE
IT40498MYFG 2.0: UPLOADED FILENAME IS DISPLAYED WRONG IF THE FILE NAME CONTAINS GB18030 CHARACTERS
IT39445INTERRUPTED FILE TRANSFER BEHAVES DIFFERENTLY FOR GLOBAL MAILBOX
IT39236STERLING B2B INTEGRATOR WEBSPHEREMQ ASYNC RECEIVE ADAPTER HANGING AFTER FAILOVER
IT39650"WAITING FOR FILE TO PROCESS" POPUP KEEP SPINNING IN MYFILEGATEWAY FOR GLOBAL MAILBOX
IT38747SFTP SERVER ADAPTER (MAVERICK) REPORTING CIPHER NOT FOUND IN SERVER CIPHER LIST
IT38698UPDATE OF JAR FILE IN CUSTOM SERVICE DOES NOT WORK
IT38977UNABLE TO CHANGE FONT COLOR OF SELECTED LINK AND HOVER LINK IN B2B DASHBOARD
IT39974MULTIPLE SECURITY ISSUES FOR SAME MYFILEGATEWAY URL
IT39732SPE SERVICE IS NOT RETURNING DATA TO THE MESSAGE FROM SERVICE INSTEAD RETURNING TO THE PROCESS DATA WHEN LOAD IS HIGH
IT40056EBICS SERVER UI VERY SLOW WHEN MANY ORDER TYPES AND FILE FORMATS ARE CONFIGURED
IT40136SWIFTNET7: UPGRADE PATH FOR MEFG - LOST ABILITY TO PERFORM IN PLACE UPGRADE
IT40944PAGE NOT FOUND ERROR ON RETURNING FROM PARTNER LIST VIEW UI
IT39827MYFG2.0 ERRORS POST LOGIN
IT39505FILEGATEWAY PARTNER LIST UI IS BROKEN IN 6.1.0.3
IT39992JVM MONITOR THREAD DUMP UTILITY WILL ONLY USE CLA2AUTH
IT39106CONTROLLERWORKFLOW SHOWN MESSAGE WORKFLOW STATE (<STATUS>) UNEXPECTED, IGNORING THIS REQUEST."
IT40661FAILS TO DOWNLOAD MESSAGES FROM DISTRIBUTED MAILBOX THROUGH B2B'S SFTP SERVER ADAPTER 2.0 CONNECTION
IT40684AWSS3EXCEPTION: ACCESS DENIED (SERVICE: AMAZON S3; STATUS CODE: 403;
IT37341NOTIFICATION ISSUE AFTER ENABLING REDELIVER AND REPLAY IN UI FOR TPS
IT40766[SFTP 2.0] INTERRUPTED FILE TRANSFER BEHAVES DIFFERENTLY FOR GLOBAL MAILBOX
IT40810PGP KEYS OF TYPE NATIVE ARE LISTED UNDER PGP PUBLIC KEYS WHEN ACCESSED USING APIS
iFix Pack (V6.1.0.5_1)
 
LinkDate ReleasedStatus
DownloadAvailable

Regular Fixes

 
APARDescription
IT41631ENHANCE B2B MAIL CLIENT ADAPTER FOR ACCESSING MICROSOFT EXCHANGE WITH OAUTH 2.0

iFix Pack (V6.1.0.5_2)
 
LinkDate ReleasedStatus
DownloadAvailable

Security Fixes

 
APARDescription
IT41648SECURITY VULNERABILITY EXISTS IN SFTP SERVER ADAPTER 2.0 IN IBM STERLING B2B INTEGRATOR

 

Regular Fixes

 
APARDescription
IT40662FOR SFG ARRIVEDFILE EVENTS THE DATA FLOW HYPERLINK IS NOT AVAILABLE IN FILEGATEWAY WHEN CLICKING ON THE DATA FLOW LINK IN THE ARRIVED FILE SEARCH SCREEN
IT41706GLOBAL MAILBOX - FILES UPLOADED TO ONE DC ARE NOT REPLICATED TO THE OTHER DC

Fix Pack (V6.1.0.6)
 
LinkDate ReleasedStatus
DownloadAvailable

Note: This Fix Pack also contains APAR security and regular fixes from 6.0.3.7 release.

Security Fixes

 
APARDescription
IT40312XSS SECURITY VULNERABILITIES EXISTS IN DASHBOARD UI OF IBM STERLING B2B INTEGRATOR (DBS)
IT39958XSS SECURITY VULNERABILITIES EXISTS IN DASHBOARD UI OF IBM STERLING B2B INTEGRATOR (DBS)
IT38888DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT38884INVESTIGATE THE SECURITY VULNERABILITY OF APACHE COMPRESS (CVSS 7.5)
IT39547SECURITY VULNERABILITY IN HTTP CLIENT AFFECTS IBM STERLING B2B INTEGRATOR (CVE-2020-13956 CVSS 5.3)
IT38879IBM STERLING B2B INTEGRATOR IS VULNERABLE TO INFORMATION DISCLOSURE DUE TO JUNIT4 (CVE-2020-15250)
IT41291UPDATE SPRING FRAMEWORK (CVSS 5.4)
IT42094SECURITY VULNERABILITIES IN JACKSON-DATABIND EXISTS IN B2B API OF IBM STERLING B2B INTEGRATOR FROM CORE-IO JAR (CVE-2019-12384 AND OTHERS CVSS 9.8)
IT42188DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT42189DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT38890SECURITY VULNERABILITIES IN ECLIPSE JETTY AFFECT IBM STERLING B2B INTEGRATOR (CVE-2021-34428, CVE-2021-28169, CVE-2021 CVSS 5.3)
IT42222DENIAL OF SERVICE SECURITY VULNERABILITY IN SPRING FRAMEWORK AFFECTS B2B API OF IBM STERLING B2B INTEGRATOR (CVE-2022-22970 CVSS 6.5)
IT41672[DAS] SQL INJECTION SECURITY VULNERABILITY EXISTS IN EBICS UI OF IBM STERLING B2B INTEGRATOR (CVE-2022-22338 CVSS 6.3)
IT41689DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)

 

Regular Fixes

 
APARDescription
IT36929CASE SENSITIVE ISSUE OF FILENAME FILTER IN SFTP CLIENT SERVICES 2.0 IN BP FOR ".PDF" / ".PDF" IN 6.1 VERSION
IT41771CHANGING ENCRYPTION STRENGTH SHOW ILLEGAL CHARACTERS WHEN BROWSER PREFERRED LANGUAGE IS CHINESE
IT39574FILE GATEWAY IS GARBLED WHEN BROWSER PREFERRED LANGUAGE IS CHINESE
IT41493XMLJSONTRANSFORMER DOCUMENTATION DOES NOT STATE IF XML DATA OF ONLY NUMERICS WILL BE OUTPUT AS STRING (IN QUOTES) OR NUMERIC (NO QUOTES)
IT40810PGP KEYS OF TYPE NATIVE ARE LISTED UNDER PGP PUBLIC KEYS WHEN ACCESSED USING APIS
IT41500UI NOT DISPLAYING ALL THE ENTRIES IN A CODE LIST IF THE COMBINATION OF SENDER AND RECEIVER RESULT IN THE SAME VALUE
IT40961ERRORS IN OPS.LOG : JAVAX.NAMING.COMMUNICATIONEXCEPTION
IT40746IF YOU CLICK FINISH MULTIPLE TIMES IN CREATE SSH USER IDENTITY KEY, MULTIPLE DUPLICATES ARE CREATED
IT40733SWIFTNET7 AIX RA 7.4 : DEPENDENT MODULE LIBSWLNK.A COULD NOT BE LOADED
IT41814CANNOT UPDATE B2B MAIL CLIENT ADAPTER INSTANCE VIA REST API IF SSL IS ENABLED AND MULTIPLE CA CERTIFICATES ARE ASSIGNED
IT41945NO MQ REASON CODES FOR MQGET EXCEPTIONS IF DEBUG DISABLED IN WEBSPHEREMQ ASYNC RECEIVE ADAPTER
IT41034REMOTE FAILS TO EXTRACT REAL FILENAME FROM B2B ENCRYPTED DOCUMENT BY NATIVEPGP PUBLIC KEY
IT41591ISSUE WHILE ENABLING AND DISABLING ADAPTERS THROUGH UI
IT42048ZIP FILE GETS CORRUPTED WHEN DOWNLOADED WITH THE REST API CLIENT SERVICE
IT41585CUSTOMER IS SOMEHOW CREATING DUPLICATE NAMED SSH USER IDENTITY KEYS AND THEN IS UNABLE TO DELETE THEM IN THE DASHBOARD GUI
IT41763FSA DOES NOT CLEAR THE LOCK. INTERMITTENT ISSUE
IT39445INTERRUPTED FILE TRANSFER BEHAVES DIFFERENTLY FOR GLOBAL MAILBOX
IT42192INSTALLING JARS OF LARGE SIZE - AWS S3 - OPENSHIFT
IT42183SMIME/CMS SIGNATURE FAILURE FOR CUSTOMER "M GROUP" WITH "CANNOT FIND CLASS NAME FOR OID: OID 1.2.840.113549.1.9.52"
IT42200AKS K8S 19.X USING HELM CHART IBM-SFG-PROD-2.0.5 TO CHANGE THE REST API POD TO USE MSSQL TLSV1.2 INSTEAD OF V1
IT42245HELM CHART IBM-SFG-PROD-2.0.5 NOT COMPATIBLE WITH K8S 1.17.11

Fix Pack (V6.1.0.7)
 
LinkDate ReleasedStatus
DownloadAvailable

Note: This Fix Pack also contains APAR security and regular fixes from 6.0.3.8 release.

Security Fixes

 
APARDescription
IT43073[ALL] IBM WEBSPHERE MQ - CVE-2022-42436 (PUBLICLY DISCLOSED VULNERABILITY) (CVSS 4.0)
IT43310[ALL] JACKSON-DATABIND - CVE-2022-42004 (PUBLICLY DISCLOSED VULNERABILITY) (CVE-2022-42004 CVSS 6.2)
IT42431IBM WEBSPHERE APPLICATION SERVER LIBERTY IS VULNERABLE TO HTTP HEADER INJECTION (CVE-2022-34165 CVSS 5.4)
IT43312DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43311DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT42890SECURITY VULNERABILITIES IN JQUERY.JS AFFECTS EBICS CLIENT UI OF IBM STERLING B2B INTEGRATOR (CVS 7.2)
IT41109THE SECURITY VULNERABILITIES IN APACHE SANTUARIO XML SECURITY AFFECT IBM STERLING B2B INTEGRATOR (CVE-2021-40690, CVE-2014-8152 CVSS 5.3)
IT41111XXE SECURITY VULNERABILITY IN APACHE POI AFFECTS IBM STERLING B2B INTEGRATOR (CVE-2019-12415 CVSS 5.3)
IT40617SECURITY VULNERABILITY IN JDOM AFFECTS IBM STERLING B2B INTEGRATOR (CVE-2021-33813 CVSS 5.3)
IT43308SECURITY VULNERABILITIES IN XSTREAM AFFECT IBM STERLING B2B INTEGRATOR (CVEID: CVE-2022-40151, 40152, 40153, 40154, 40155, 40156 CVSS 6.5)
IT43309DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT42806DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)

 

Regular Fixes

 
APARDescription
IT42844SEARCHING AS2 PARTNER PROFILE DOES NOT DISPLAY THE PARTNER WHILE TYPING IT IF THE PROFILE WAS CREATED VIA REST API
IT41206SFTP SERVER ADAPTER 2.0 ENHANCEMENT
IT43147WORKDAY WSDL IMPORT FAILS IN SI DUE TO SIZE
IT39574FILE GATEWAY IS GARBLED WHEN BROWSER PREFERRED LANGUAGE IS CHINESE
IT39445INTERRUPTED FILE TRANSFER BEHAVES DIFFERENTLY FOR GLOBAL MAILBOX
IT42530NATIVEPGP ENCRYPTION FAILS FOR LARGER FILES WHEN COMPRESSION IS TURNED OFF
IT43152SWAGGER-UI ERROR 500: JAVAX.SERVLET.SERVLETEXCEPTION: FILTER [SPRINGSECURITYFILTERCHAIN]: COULD NOT BE INITIALIZED
IT43071CUSTOM PROTOCOLS ARE ONLY SEEN AS ENABLED FROM FILEGATEWAY UI WHEN A STANDARD PROTOCOL IS ENABLED
IT42689RESOURCE TAG CONSISTS OF DELETED FILEGATEWAY PARTNERS WHEN EXPORTING
IT42453SFGDBCHECK TOOL CREATES A MISSING MAILBOX WITH PRODUCERCODE INSTEAD OF PRODUCERNAME
IT43188THE READ USER ACCOUNT REST API IS RETURNING THE WRONG AUTHENTICATION HOST OF EXTERNAL USERS
IT43300FEW FILES ARE NOT PROCESSED AND BLOCKED ON CLA2 STEP. ENCRYPTION THREADS ARE RUNNING AND BLOCKING THE QUEUE WHEN TOO MUCH THREADS ARE IN THE QUEUE
IT42859UNABLE TO CREATE SSH PROFILE IN V6.1.0.6 DUE TO ERROR - THE NAME IS DUPLICATE
IT43322GLOBAL MAILBOX EVENT RULE ADAPTER DOES NOT SEND A USER ID PASSWORD TO IBM MQ GREATER THAN 12 CHARACTERS
IT42726PGP PACKAGE SERVICE SIGNS DOCUMENT ALSO IF "SIGNED BY THE PARTNER" SET TO NO
IT42929SFGDBCHECK TOOL IS REPORTING COMMUNITIES IN THE INCONSISTENT PARTNERS LIST
IT43103MAILBOX MESSAGES IN MYFG2.0 UI DO NOT HONOR EXTRACTABILITY POLICIES
IT42619TP_IMPORT/EXPORT.SH ALWAYS SHOWS "ERROR '1' DURING EXPORT FOR CD_NETMAPS
IT42237LIBERTY LOGGING - STRANGE FOLDER NAME ${LOG-PATH} WITH ANALYTICS-%D{YYYY-MM-DD}.LOG
IT43181UPDATION OF CODELIST ENTRIES UPON SORTING BY RECEIVERCODE/SENDERCODE REPORTS UI ERROR
IT42676UNABLE TO IMPORT A PARTNER CONTAINING & IN THE PARTNER NAME
IT42746SFTP CLIENT BEGIN SESSION STATUS REPORT VERY GENERIC
IT42490NATIVE PGP UNPACKAGE SERVICE HAS INCORRECT "ACTION" IN PROCESS DATA FOR DECRYPT AND VERIFY
IT42461SFTP CLIENT MOVE SERVICE FAILS WITH NO SUCH FILE
IT43468EBICS SERVER AND EBICS CLIENT VERSIONS ARE NOT UPDATED ON THE SUPPORT PAGE IN OCP
IT43250REST API UPDATE TRADING PARTNER API000411 ERROR FOR GLOBAL MAILBOX LISTENING PRODUCER
IT41142WHEN CREATING ROUTING CHANNELS (VIA RESTAPI) FOR A PRODUCER PARTNER WITH SUBMAILBOXES, THE EVENT RULE IS GETTING CREATED FOR THE FIRST SUBMAILBOX ONLY AND NOT FOR THE SUBSEQUENT SUBMAILBOXES, AND THE EVENT RULE LIST ONLY ONE MAILBOX
IT42019GLOBAL MAILBOX EVENTS WHICH ARE OLD ARE NOT BEING CLEARED FROM CASSANDRA TABLES

Fix Pack (V6.1.0.8)
 
LinkDate ReleasedStatus
DownloadCurrent

Security Fixes

 
APARDescription
IT43138DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43549DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43090DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43508DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43522DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44091DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44092DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44078ECLIPSE JETTY (PUBLICLY DISCLOSED VULNERABILITY) (CVSS 5.3)
IT44300DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43649SECURITY VULNERABILITIES IN JETTISON AFFECT EBICs CLIENT OF IBM STERLING B2B INTEGRATOR (CVE-2023-1436, CVSS 5.3)
IT43908[ALL] APACHE COMMONS FILEUPLOAD (PUBLICLY DISCLOSED VULNERABILITY) (CVE-2023-24998 CVS 7.5)
IT44182UPDATE SNAPPY-JAVA IN B2B API (CVSS 7.5)
IT44198[ALL] IBM WEBSPHERE MQ - CVE-2023-32342 (PUBLICLY DISCLOSED VULNERABILITY) (CVSS 5.9)
IT44322SECURITY VULNERABILITY IN COMMONS-BCEL AFFECT IBM STERLING B2B INTEGRATOR (CVE-2022-42920 CVSS 9.8)

 

Regular Fixes

 
APARDescription
IT43645GM IMPORT UTILITY FAILS WITH JAVA.LANG.NOCLASSDEFFOUNDERROR: ORG.APACHE.COMMONS.COLLECTIONS.ARRAYSTACK
IT43762EXTERNAL PURGE INSTALLED ON OPENSHIFT PLATFORM CLEARS ALL THE LOCKS WHEN IT STARTS
IT43734RESTAPI - WHEN USING THE RESTAPI UI HTTP://IP:BASEPORT+74/B2BAPIS/SVC TO CREATE MAILBOXES THE FOLLOWING ERROR MESSAGE IS RAISED IN LOGFILE (SYSTEM.LOG)
IT43643STERLING INTEGRATOR IB 997 PROCESS DATA SHOWS SUCCESSFUL BUT THE 997 RECONCILIATION REPORT HAS AN ERROR
IT41328QUERY ON FG_ROUTE TABLE DOES NOT USE BIND VARIABLES
IT43785NOT ABLE TO SEND EMAIL FROM STERLING INTEGRATOR / SBI / B2BI TO MS EXCHANGE ONLINE USING SMTP SEND ADAPTER
IT43301DIRECT TRANSFERS ARE SLOW WHEN USING GLOBAL MAILBOX
IT42183SMIME/CMS SIGNATURE FAILURE FOR CUSTOMER "M GROUP" WITH "CANNOT FIND CLASS NAME FOR OID"

Mod Pack (V6.1.1.0)

 
Date ReleasedStatus
Important: You can download the fix from Passport Advantage.
 
Note: This Mod Pack also contains APAR security and regular fixes from 6.0.0.7 and 6.1.0.3 releases.
 

Security Fixes

 
APARDescription
IT35823INFORMATION DISCLOSURE VULNERABILITIES AFFECT IBM STERLING B2B FILE GATEWAY USER INTERFACE (CVE-2021-20485, CVE-2021-20563)
IT36688SECURITY VULNERABILITY: CSRF TOKEN APPEARS IN THE URLS FOR FILEGATEWAY USER INTERFACE (AFT)
IT37682UPDATE APACHE TOMCAT JARS (CVSS 9.8)
IT36354SECURITY VULNERABILITY: REFLECTED CROSS-SITE SCRIPTING VULNERABILITY IN IBM STERLING B2B INTEGRATOR​ DISCOVERED BY THIRD PARTY
IT37597CROSS-SITE SCRIPTING VULNERABILITY AFFECTS THE MAILBOX USER INTERFACE OF IBM STERLING B2B INTEGRATOR (CVE-2021-29855)
IT33759IBM STERLING B2B INTEGRATOR VULNERABLE TO CROSS-SITE AJAX REQUEST VULNERABILITY DUE TO PROTOTYPE JAVASCRIPT (CVE-2008-7220)
IT36390SECURITY VULNERABILITY: MYFILEGATEWAY USER CAN UPLOAD THE FILE EVEN THOUGH THE UPLOAD TAB IS DISABLED
IT36280SECURITY VULNERABILITY: MYFILEGATEWAY UI DISPLAYS SENSITIVE INFORMATION AFTER LOGOUT
IT36300SECURITY VULNERABILITY - MYFILEGATEWAY FILE-NAME COULD BE INTERCEPTED TO INJECT DISALLOWED CHARACTERS IN FILENAME
IT37862B2BIAPIS --> SECOND_ORDER_SQL_INJECTION [1]
IT36900SECURITY VULNERABILITY: PERMISSION CONTROL SECURITY VULNERABILITY EXISTS IN CREATING USER NEWS IN THE DASHBOARD USER INTERFACE
IT36914SECURITY VULNERABILITY: PERMISSION CONTROL SECURITY VULNERABILITIES EXISTS WHILE DOWNLOADING WAR FILE FROM WEB EXTENSION UTILITY
IT36930SECURITY VULNERABILITY: ACCESS CONTROL SECURITY VULNERABILITY EXISTS WHILE VIEWING THE ROSETTA NET ACTIVITIES
IT36609SECURITY VULNERABILITY: PERSISTENT XSS SECURITY VULNERABILITY EXISTS IN THE WEB SERVICE MANAGEMENT USER INTERFACE
IT36447SECURITY VULNERABILITY: 3RD PARTY STORED CROSS SITE SCRIPTING IN IBM STERLING B2B INTEGRATOR
IT37031SECURITY VULNERABILITY: STORED XSS SECURITY VULNERABILITY EXISTS IN DASHBOARD USER INTERFACE CAUSED BY NOT CHECKING SERVER NAME IN CREATING A PERIMETER SERVER
IT37777UNABLE TO DISABLE SPECIFIC TLS VERSION (TLS 1.0) ON HTTP SERVER ADAPTER USING SSLHELLOPROTOCOL
IT37848UPGRADE LOG4J (CVSS 7.8)
IT37914UPGRADE NETTY JAR (CVSS 9.1)
IT37678UPGRADE DATA MAPPER FOR JACKSON (CVSS 7.5)
IT37859UPGRADE XSTREAM TO 1.4.17 (CVSS 8.8)
IT37693UPDATE APACHE COMMONS BEANUTILS (CVSS 7.5)
IT37613B2BI_DOCKER CLUMP --> SECOND_ORDER_SQL_INJECTION [2]
IT37612CROSS-SITE REQUEST FORGERY [3]
IT35458SECURITY VULNERABILITY: [ALL] ECLIPSE JETTY (PUBLICLY DISCLOSED VULNERABILITY)
IT37681UPGRADE XML BEAN (CVSS 9.1)
IT37858DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT37642CROSS-SITE SCRIPTING VULNERABLITY AFFECTS THE DASHBOAD UI OF IBM STERLING B2B INTEGRATOR (CVE-2021-29836)
IT38514UPDATE APACHE TAGLIBS (CVSS 7.5)
IT37677UPGRADE JACKSON DATAFORMATS JAR (CVSS 7.5)
IT37615UPDATE APACHE XCERCES2 J (CVSS 7.5)
IT38149UPDATE JBOSS DROOLS (CVSS 7.5)
IT37913UPDATE BOUNCY CASTLE JAR IN GATEWAY.WAR (CVSS 9.8)
IT36552UPDATE JASPERREPORTS (CVSS 8.8)
IT36570SECURITY VULNERABILITY: INFORMATION DISCLOSURE SECURITY VULNERABILITY IN THE DASHBOARD USER INTERFACE
IT35845CROSS SITE SCRIPTING VULNERABILITY 6.1 (PERSISTENT XSS)       
IT37912IBM WEBSPHERE MQ (PUBLICLY DISCLOSED VULNERABILITY)
IT35837SECURITY VULNERABILITY: SESSION FIXATION SECURITY VULNERABILITY IN FILEGATEWAY
IT35660SECURITY VULNERABILITY: USER ENUMERATION VULNERABILITY IN MYFILEGATEWAY USER INTERFACE                              
IT35654ACCESS SECURITY CONTROL VULNERABILITY AFFECTS IBM STERLING FILE GATEWAY (CVE-2021-20375)
IT35605ACCESS CONTROL VULNERABILITY AFFECTS IBM STERLNG FILE GATEWAY (CVE-2021-20372)
IT35181THE FILEGATEWAY AND MYFILEGATEWAY USER INTERFACES LACK SUFFICIENT PERMISSION CONTROL
IT38515APACHE KAFKA VULNERABILITIES AFFECT THE B2B API OF IBM STERLING B2B INTEGRATOR (CVE-2017-12610, CVE-2018-1288)
IT38512UPDATE JACKSON-DATABIND JAR (CVSS 9.8)

 

Regular Fixes

APARDescription
IT35859ROSETTANET ISSUE AFTER REACHING INT LIMIT FOR WFID
IT36453ERROR DECRYPTING DB PASSWORD AFTER UPGRADING TO B2BI 6.1.0.1 WITH FIPS
IT37796IGNORELATEINBOUND LOG SHOWS INCORRECT DELIVERY TIME AND AS A RESULT REQUEST IS HANDLED AS TIMEOUT
IT37462THE NEW QUERY.CALCDOCUMENTLIFESPANSQL1.MSSQL QUERY IS TRYING TO INSERT DUPLICATE WORKFLOW_ID IN THE BPMV_LS_WRK TABLE
IT37692EBICS SERVER GENERATES DUPLICATE ORDER IDS
IT38106SILENTINSTALLATIONFILECONVERTER UTILITY IS CREATING DUPLICATE PARAMETERS WITH OPPOSITE VALUES
IT38091USERACCOUNTS LIST API ALONG WITH QUERY PARAMETERS IS THROWING AN ERROR
IT37875STERLING B2BI-RESTAPI-GETPAYLOADDATA FAILS IN V6.1.0.2
IT37921EBICS CLIENT SERVICES DOES NOT REPORT PROPERLY FAILURE STATUS
IT38047EBICS PARTNERS WITH ENTRIES IN STERLING FILE GATEWAY - PARTNERS ARE LEFT WHEN ENTRIES IN PROFILE MANAGER - PARTNER CONFIGURATION ARE DELETED

 

 


Fix Pack (V6.1.1.0_1)
 
LinkDate ReleasedStatus
DownloadSuperseded

Security Fixes

 
APARDescription
IT39380UPGRADE LOG4J TO 2.17.0

Fix Pack (V6.1.1.0_2)
 
LinkDate ReleasedStatus
DownloadAvailable

Security Fixes

 
APARDescription
IT39737UPGRADE LOG4J TO 2.17.1

Regular Fixes

APARDescription
IT38166AFTER APPLYING 6.0.3.4 IFIX APAR IT37392, SFTP CLIENT GET FAILS WITH ERROR MESSAGE = [NO SUCH FILE: THE MESSAGE [XXX/ABC] IS NOT EXTRACTABLE!
IT40130AFTER UPGRADING FROM B2BI 6.1.0.0 TO 6.1.1.0, MANY OF THE HTTPS SERVER ADAPTERS FAIL TO START AFTER THE NODE STARTS UP

Fix Pack (V6.1.1.1)
 
LinkDate ReleasedStatus
Download
Note: This Fix Pack also contains APAR security and regular fixes from 6.1.0.4 release.
 

Security Fixes

 
APARDescription
IT37287INFORMATION DISCLOSURE SECURITY VULNERABILITY EXISTS IN IBM STERLING B2B INTEGRATOR WEB USER INTERFACE (JETTY 404) (CVE-2021-39033 4.3)
IT38888DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT38877SECURITY VULNERABILITIES IN XSTREAM AFFECT THE B2B API OF IBM STERLING B2B INTEGRATOR
IT38878SECURITY VULNERABILITIES IN APACHE SANTURARIO AFFECT IBM STERLING B2B INTEGRATOR (CVE-2013-4517, CVE-2013-2172 CVSS 5.0)
IT38879IBM STERLING B2B INTEGRATOR IS VULNERABLE TO INFORMATION DISCLOSURE DUE TO JUNIT4 (CVE-2020-15250)
IT38884INVESTIGATE THE SECURITY VULNERABILITY OF APACHE COMPRESS (CVSS 7.5)
IT39126DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39125DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39090DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT38412PERMISSION CONTROL SECURITY VULNERABILITY EXITS IN THE MAILBOX USER INTERFACE OF IBM STERLING B2B INTEGRATOR
IT33759IBM STERLING B2B INTEGRATOR VULNERABLE TO CROSS-SITE AJAX REQUEST VULNERABILITY DUE TO PROTOTYPE JAVASCRIPT (CVE-2008-7220)
IT38705INFORMATION DISCLOSURE SECURITY VULNERABILITY EXISTS IN THE REST B2B API IN IBM STERLING B2B INTEGRATOR
IT39737UPGRADE LOG4J TO 2.17.1

 

Regular Fixes

APARDescription
IT39094ERROR WHILE CREATING EBICS BTF SERVICE
IT39226S3 CLIENT ADAPTER STOPS AFTER UPGRADE TO SI 6.1.1
IT39228EBICS: DUPLICATE ORDER FAILURES NOT LOGGED IN FILEGATEWAY
IT39229ERRORCODE = "CONNECTION LEAK" IN JETTY.LOG AND SCI.LOG
IT39281ENHANCE CDSA TO PASS SACCOUNT AND PACCOUNT INFORMATION TO A B2BI BUSINESSES PROCESS
IT39445INTERRUPTED FILE TRANSFER BEHAVES DIFFERENTLY FOR GLOBAL MAILBOX
IT39494UNABLE TO VIEW A SWIFTNETROUTING RULE IN B2BI 6.1.1
IT39649UNABLE TO CREATE A ROUTE ON A SUB-MAILBOX IN GLOBAL MAILBOX IF A ROUTE ALREADY EXISTS ON ANOTHER SUB-MAILBOX UNDER THE SAME PARENT MAILBOX
IT35379AWSS3CLIENT / PUT SERVICE GENERATES FILES INTO THE SI INSTALL/TMP DIRECTORY WHICH ARE NOT DELETED
IT39528WINDOWS XCOPY COMMANDS CAUSING UPGRADEJDK.CMD SCRIPT TO FAIL
IT39855FILE UPLOAD TO S3 BUCKET USING MAILBOX OPTION DOESN’T WORK
IT39681B2BI TAGLIBS (JSLT) UPGRADE FROM 1.1.2 TO 1.2.5 IN EBICS CLIENT AND SERVER REST APIS
IT39163DUPLICATE HAC REQUEST SENT BY THE EBICS HAC SCHEDULER
IT39774SFTP CLIENT 2.0 PWD SERVICE DIDN'T RETURN THE SAME RESULT COMPARED TO SFTP CLIENT 1.0 PWD SERVICE
IT34982REMOTE HOST IS INVALID. PLEASE ENTER A VALID DOMAIN NAME OR IPV4 OR IPV6 ADDRESS


Fix Pack (V6.1.1.2)
 
LinkDate ReleasedStatus
Download
Note: This Mod Pack also contains APAR security and regular fixes from releases:

Security Fixes

 
APARDescription
IT38890SECURITY VULNERABILITIES IN ECLIPSE JETTY AFFECT IBM STERLING B2B INTEGRATOR (CVE-2021-34428, CVE-2021-28169, CVE-2021 CVSS 5.3)
IT40312XSS SECURITY VULNERABILITIES EXISTS IN DASHBOARD UI OF IBM STERLING B2B INTEGRATOR (DBS)
IT39442DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39357DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39422IBM STERLING B2B INTEGRATOR DASHBOARD UI IS VULNERABLE TO SENSITIVE INFORMATION EXPOSURE (CVE-2021-39087)
IT39433DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39434DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39424DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39440SQL INJECTION SECURITY VULNERABILITY EXISTS IN THE DASHBOARD UI OF IBM STERLING B2B INTEGRATOR (CVE-2021-39085, CVSS 6.3)
IT39438DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39547SECURITY VULNERABILITY IN HTTPCLIENT AFFECTS IBM STERLING B2B INTEGRATOR (CVE-2020-13956 CVSS 5.3)
IT41026HTTP SESSION DOES NOT EXPIRE AFTER PASSWORD CHANGE
IT40552IBM STERLING B2B INTEGRATOR VULNERABLE TO DENIAL OF SERVICE DUE TO XSTREAM (CVE-2021-43859)
IT39958XSS SECURITY VULNERABILITIES EXISTS IN DASHBOARD UI OF IBM STERLING B2B INTEGRATOR (DBS)
IT38888DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT41002SECURITY VULNERABILITIES IN CKEDITOR EXISTS IN B2B API OF IBM STERLING B2B INTEGRATOR (CVSS 7.6)
IT41085WILDCARD IS SPECIFIED FOR HTTP CORS HEADER IN THE B2BI API FOR IBM STERLING B2B INTEGRATOR
IT41370DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT41292JACKSON-DATABIND BEFORE 2.13.0 ALLOWS A JAVA STACKOVERFLOW EXCEPTION AND DENIAL OF SERVICE (CVE-2020-36518 CVSS 7.5)
IT41369DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT41250DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT41291UPDATE SPRING FRAMEWORK (CVSS 5.4)
IT39105DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT40617SECURITY VULNERABILITY IN JDOM AFFECTS IBM STERLING B2B INTEGRATOR (CVE-2021-33813 CVSS 5.3)
IT39360INFORMATION DISCLOSURE SECURITY VULNERABILITY EXISTS IN THE USER INTERFACE OF IBM STERLING FILE GATEWAY (DBS VERBOSE ERROR MESSAGE)  (CVE-2021-39086 CVSS 4.3)
IT41490DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT40669IBM STERLING FILE GATEWAY IS VULNERABLE TO MULTIPLE ISSUES DUE TO BOUNCY CASTLE
IT41648SECURITY VULNERABILITY EXISTS IN SFTP SERVER ADAPTER 2.0 IN IBM STERLING B2B INTEGRATOR
IT39104DBS HAS REPORTED STORED CROSS SITE SCRIPTING VULNERABILITY ON 6.0.3.3
IT39235DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)

 

Regular Fixes

APARDescription
IT40068SSHKEYGRABBER - ORG.APACHE.SSHD.COMMON.RUNTIMESSHEXCEPTION: FAILED TO GET THE SESSION
IT40444SWIFTNET7: REQUEST FAILING DURING START OF ADAPTER
IT38279CUSTOM IFIX REQUEST FOR APAR IT38279 AND IT36968
IT41153SFG PARTNER CREATION ROUTINE HAS LONG DELAYS FOR SOME SCREENS TO POPULATE
IT40821SWIFTNET7: HANDLING OF MESSAGEEXPIRED
IT40778SFTP SERVER ADAPTER IN READ-ONLY VIEW SHOWS "CIPHER NOT FOUND IN SERVER CIPHER LIST" NEXT TO PREFERREDCIPHER
IT39881EBICS A/B SIGNATURES NOT WORKING
IT39445INTERRUPTED FILE TRANSFER BEHAVES DIFFERENTLY FOR GLOBAL MAILBOX
IT40236CHANGING DASHBOARD_TOPBAR_SUB_INTEGRATOR.GIF WITH API CUSTOMIZATION UI IS NOT PERMANENT / DEPLOYER RESETS
IT40988CDSA - STERLING CONNECT:DIRECT SERVER PRIMITIVE COPYTO SERVICE STATUS REPORT MISSING INFORMATION
IT40057DATE PICKER IN DOWNLOAD TAB OF MYFILEGATEWAY UI IS DISABLED
IT41090OLD VERSION OF CDJAI.JAR COMPILED WITH OLD JAVA VERSION
IT41372SQL INJECTION EXISTS IN EBICSCLIENT UI
IT41089UNABLE TO UPLOAD ZERO BYTE FILE VIA MYFILEGATEWAY IN B2BI 6010101
IT39867ERROR WHEN SEARCHING OR LISTING FILE FORMATS IN THE EBICS CLIENT UI SET FOR FRENCH LANGUAGE
IT40972STERLING INTEGRATOR NATIVE PGP DISABLE COMPRESS
IT40141NATIVE PGP DECRYPTION OF FILE WITH .ASC FILE EXTENSION ADDS PERIOD TO END OF DECRYPTED FILE NAME
IT40263ACCENTED CHARACTERS DISPLAY INCORRECTLY IN THE EBICS CLIENT UI SET FOR FRENCH LANGUAGE
IT40130AFTER UPGRADING FROM B2BI 6.1.0.0 TO 6.1.1.0, MANY OF THE HTTPS SERVER ADAPTERS FAIL TO START AFTER THE NODE STARTS UP
IT41271EBICS COF FOR CDB - H003 WITH FILEFORMAT PAIN.008.00X.02.SBB.CDB FAILING
IT39970EBICS SERVER COF CONFIGURATION ERROR DURING CREATION
IT40056EBICS - VEU/EDS ORDER FAILED FOR HVE ON 6.1.1.0 EBICS SERVER / CLIENT USING H003
IT39964SOA OUTBOUND SERVICE - CANNOT FIND DOM MECHANISM TYPE
IT41150RESTAPICLIENT: STRINGINDEXOUTOFBOUNDSEXCEPTION IN BP
IT40633UNIQUE CONSTRAINT (PKOS09.SCI_PK_215) VIOLATED ON REST API POST
IT40252GETARRIVEDFILEDETAILS API DOES NOT RETURN RESPONSE IN SWAGGER UI
IT40348PGP DECRYPT FAILING AFTER MIGRATING FROM SYMANTEC TO NATIVE PGP
IT40346BULK IMPORT OF PGP KEYS INTO NATIVE PGP THROWS ERROR AFTER IMPORTING AROUND 100 PGP KEYS
IT41411EDIT SERVICE ADAPTOR CONFIG FAILS WITH "PROCESSING ERROR"
IT36929SFTP CLIENT LIST SERVICE FAILS TO LIST FILES BY CASE-INSENSITIVE SEARCH
IT41631ENHANCE B2B MAIL CLIENT ADAPTER FOR ACCESSING MICROSOFT EXCHANGE WITH OAUTH 2.0

Fix Pack (V6.1.1.3)
 
LinkDate ReleasedStatus
Download
 
Note: This Fix Pack also contains APAR security and regular fixes from 6.1.0.6 release.
 

Security Fixes

 
APARDescription
IT41109THE SECURITY VULNERABILITIES IN APACHE SANTUARIO XML SECURITY AFFECT IBM STERLING B2B INTEGRATOR (CVE-2021-40690, CVE-2014-8152 CVSS 5.3)
IT42431
IBM WEBSPHERE APPLICATION SERVER LIBERTY IS VULNERABLE TO HTTP HEADER INJECTION (CVE- 2022-34165 CVSS 5.4)
IT42505DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT41715SPECIAL CHARACTERS CAN BE ENTERED TO A LOG FILE WITH UNSUCCESSFUL LOGIN TO DASHBOARD UI OF IBM STERLING B2B INTEGRATOR
IT41689DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT42295DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT42440DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT41362DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)

 

Regular Fixes

APARDescription
IT42211UNABLE TO EXPORT OFTP PARTNERS IN SI 6.1.1
IT42353SFTP CLIENT ADAPTER SESSIONS ARE NOT DISTRIBUTED ACROSS CLUSTER NODES
IT41102CD REQUESTER SUBMIT SERVICE IS FAILING
IT41838EXCEPTION WHEN GNUPG 8BIT KEY IS MIGRATED VIA PGPPARTNERKEYSMIGRATION.SH
IT41833ERROR WHILE SYSTEM CERT CHECKIN IN TXT FORMAT - OBJECTIDENTIFIER() -- DATA ISN'T AN OBJECT ID (TAG = 48)
IT41739PARTNER USER NOT ADDED TO MAILBOX PERMISSIONS WHEN CREATING ROUTING CHANNEL USING B2B API
IT40821HANDLING OF MESSAGEEXPIRED
IT42419MONTHLY SCHEDULE NOT WORKING PROPERLY ON V6.1.1.1
IT36929SFTP CLIENT LIST SERVICE FAILS TO LIST FILES BY CASE-INSENSITIVE SEARCH
IT409186.1.1 HAVING ISSUES WITH SCP (LINUX) TO SSH 2.0 SERVER ADAPTER
IT42144EBICS CLIENT UI NOT SHOWING X509 CERTIFICATE NAMES WHILE CREATING NEW EBICS USER
IT41974COF CREATION IS CAUSING ISSUE IF CONFIGURED ON EBICS CLIENT AND SERVER IN THE SAME ENVIRONMENT
IT41790IBM STERLING & ADP SSH SPECIAL CHARACTER ENHANCEMENT REQUEST
IT42186REST API FOR FETCHING SCHEDULE DETAILS, IT'S GIVING WRONG INFORMATION WHEN IT COMES TO SCHEDULE TYPE “SERVICE CONFIGURATION”
IT41912ON RESTART HTTP SERVER ADAPTERS CREATES NEW BLOB ENTRIES IN HSM AND DELETES THE OLDER ONE
IT42286EXTERNAL PURGE LOG ERROR DB2 SQL ERROR: SQLCODE=-805, SQLSTATE=51002 (PROD)
IT42241INCORRECT ITEMS SELECTED ON PGP MANAGER WHILE USING CHROME OR EDGE BROWSER
IT42508DEFAULTSFTP IN SFTP.PROPERTIES HAS BEEN SET TO 1.0. IT SHOULD BE 2.0
IT42547UPGRADE FROM V6.1.1.0 TO V6.1.1.1 FAILS WITH ERROR COM.IBM.STERLING.AFC.INSTALL.LAUNCH.BACKENDLAUNCHER.RUN(BACKENDLAUNCHER.JAVA:354)
IT41814CANNOT UPDATE B2B MAIL CLIENT ADAPTER INSTANCE VIA REST API IF SSL IS ENABLED AND MULTIPLE CA CERTIFICATES ARE ASSIGNED
IT42496CREATE A NEW PARTNER ON FILEGATEWAY 6.1.1.1 --> UI WINDOW REMAINS WHITE WITH SPANISH LANGUAGE SETTINGS
IT42622CONNECT:DIRECT SERVER ADAPTER NOT HONOR DOCUMENT STORAGE TYPE OF SYSTEM DEFAULT WITH DEFAULTSTORAGETYPE=FS
IT40662FOR SFG ARRIVEDFILE EVENTS THE DATA FLOW HYPERLINK IS NOT AVAILABLE IN FILEGATEWAY WHEN CLICKING ON THE DATA FLOW LINK IN THE ARRIVED FILE SEARCH SCREEN
IT42019GLOBAL MAILBOX EVENTS WHICH ARE OLD ARE NOT BEING CLEARED FROM CASSANDRA TABLES
IT42549DOCUMENT NOT FOUND DURING ROUTING AFTER UPGRADING TO 6112 + CUSTOM FIX
IT41706GLOBAL MAILBOX - FILES UPLOADED TO ONE DC ARE NOT REPLICATED TO THE OTHER DC
IT41065GLOBAL MAILBOX EVENT RULE ADAPTER DOES NOT RESPECT BATCH MODE AND INVOKES AS IMMEDIATE MODE LEADING TO SAME FILES TO BE PROCESSED TWICE

Fix Pack (V6.1.1.4)
 
LinkDate ReleasedStatus
Download
 
Note: This Fix Pack also contains APAR security and regular fixes from 6107 release.
 

Security Fixes

 
APARDescription
IT42896SECURITY VULNERABILITIES IN SPRING SECURITY AFFECTS IBM STERLING B2B INTEGRATOR (CVE-2022-31692, CVE-2022-22978 CVSS 8.2)
IT43557DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43555VULNERABILITY IN THE APACHE JAMES MIME4J LIBRARY USED BY IBM WEBSPHERE APPLICATION SERVER LIBERTY WHEN THE FEATURE RESTFULWS-3.0 IS ENABLED (CVE-2022-45787 CVSS 5.5)
IT43625DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43624DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43473DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43508DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43110DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43073[ALL] IBM WEBSPHERE MQ - CVE-2022-42436 (PUBLICLY DISCLOSED VULNERABILITY) (CVSS 4.0)
IT43308SECURITY VULNERABILITIES IN XSTREAM AFFECT IBM STERLING B2B INTEGRATOR (CVEID: CVE-2022-40151, 40152, 40153, 40154, 40155, 40156 CVSS 6.5)
IT42890SECURITY VULNERABILITIES IN JQUERY.JS AFFECTS EBICS CLIENT UI OF IBM STERLING B2B INTEGRATOR (CVS 7.2)
IT41109THE SECURITY VULNERABILITIES IN APACHE SANTUARIO XML SECURITY AFFECT IBM STERLING B2B INTEGRATOR (CVE-2021-40690, CVE-2014-8152 CVSS 5.3)
IT43312DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43678SECURITY VULNERABILITIES IN SNAKEYAML AFFECT B2B API OF IBM STERLING B2B INTEGRATOR (CVE-2017-18640, CVE-2022-25857, CVE-2022-38749, CVE-2022-38750, CVE-2022-38751, CVE-2022-38752, CVE-2022-41854, CVE-2022-1471 CVSS CVSS 8.3)
IT43720DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43649SECURITY VULNERABILITIES IN JETTISON AFFECT EBLICS CLIENT OF IBM STERLING B2B INTEGRATOR (CVE-2023-1436, CVSS 5.3)
IT43310
[ALL] JACKSON-DATABIND - CVE-2022-42004 (PUBLICLY DISCLOSED VULNERABILITY) (CVE-2022-42004 CVSS 6.2)
IT43051CSRF SECURITY VULNERABILITY EXISTS IN ROSETTANET SEARCH IN DASHBOARD UI OF IBM STERLING B2B INTEGRATOR (CVE-2022-35638)
IT43090DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)

 

Regular Fixes

APARDescription
IT43547INSTALLATION LEAVES JAR FILE IN <INSTALL-DIR> - WASTE OF SPACE OR NEEDED
IT42719EBICS SERVER - FDL FROM CLIENT INTERMITTENTLY FAILING
IT43244/B2BAPIS/SVC/USERACCOUNTS DOES NOT ALLOW UPPERCASE FOR EMAIL FIELD
IT43149PROPERTY STRONGTLS1.2ONLYCIPHERSUITE NOT HONORED
IT42745ITEMS RELATED TO THE "SOCKET.TCPKEEPALIVE" PROPERTY CONFLICT WITH EACH OTHER
IT43400WHEN SQL BATCHING IS ENABLED THE INSERTS IN DB ON THE OUTPUT SIDE ARE EXECUTED IN AN UNPREDICTABLE ORDER
IT43321DELETE ROUTINGCHANNEL API RETURNS 400 RESPONSE, ROUTING CHANNEL IS DELETED
IT43601ERROR JAVAX.XML.TRANSFORM.TRANSFORMERFACTORYCONFIGURATIONERROR: PROVIDER COM.STERLINGCOMMERCE.WOODSTOCK.XML.XSLT.TRANSFORMERFACTORYIMPL NOT FOUND
IT43047SFTP2.0 USER EXIT ISFTPSERVERUSEREXIT_ONPUTBEFOREEXECUTE USING OUTPUT PARAMETER KEY_CONTINUE_CMD_EXECUTION DOESN'T WORK AS DOCUMENTED
IT42747XMLJSONTRANSFORMER SERVICE FAILS WHEN INPUT JSON IS ARRAY OF ELEMENTS WITHOUT ROOT ELEMENT
IT43059SFTP2.0 USER EXIT ISFTPSERVERUSEREXIT_ONLSCDBEFOREEXECUTE DOESN'T WORK AS DOCUMENTED
IT43027CIPHERS DEFINED IN SECURITY.STRONG/WEAK/ALLCIPHERSUITE THROUGH CUSTOMIZATION UI ARE NOT PICKED UP BY ADAPTER PORT
IT43026CIPHERS DEFINED IN SECURITY.JDKCIPHERSUITE THROUGH CUSTOMIZATION UI ARE NOT PICKED UP BY SECURE BASE PORT
IT43651FILGATEWAY FLICKERING ISSUE IN B2BI 6.1.1.0
IT42183EDIINTPIPELINEPARSE HITS AN ERROR MESSAGE: COM.TRUSTPOINT.ASN.ASNEXCEPTION: CANNOT FIND CLASS NAME FOR OID: OID 1.2.840.113549.1.9.52
IT43301DIRECT TRANSFERS ARE SLOW WHEN USING GLOBAL MAILBOX
IT43054PRIVATE CERTIFICATES FOR AN EBICS USER ARE NOT DISPLAYED IN EBICS CLIENT UI
IT43250REST API UPDATE TRADING PARTNER API000411 ERROR FOR GLOBAL MAILBOX LISTENING PRODUCER
IT41142WHEN CREATING ROUTING CHANNELS (VIA RESTAPI) FOR A PRODUCER PARTNER WITH SUBMAILBOXES THE EVENT RULE IS GETTING CREATED FOR THE FIRST SUBMAILBOX ONLY AND NOT THE SUBSEQUENT SUBMAILBOXES, AND THE EVENT RULE LIST ONLY 1 MAILBOX
IT43747EBICS SERVER - COF CANNOT BE CONFIGURED FOR CERTAIN FILE FORMATS
IT42502EBICS SERVER INI AND HIA IS FAILING
IT43878HTD ORDER IS FAILING FOR H003
IT43874FUL ORDER SUBMISSION IS FAILING

Mod Pack (V6.1.2.0)
LinkDate ReleasedStatus
Download
Important: Download the Mod Pack from Passport Advantage.
 
Note: This Mod Pack also contains APAR security and regular fixes from releases:

Security Fixes

 
APARDescription
IT39380UPGRADE LOG4J TO 2.17.1
IT38884INVESTIGATE THE SECURITY VULNERABILITY OF APACHE COMPRESS (CVSS 7.5)
IT38888DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT38879IBM STERLING B2B INTEGRATOR IS VULNERABLE TO INFORMATION DISCLOSURE DUE TO JUNIT4 (CVE-2020-15250)
IT38878SECURITY VULNERABILITIES IN APACHE SANTURARIO AFFECT IBM STERLING B2B INTEGRATOR (CVE-2013-4517, CVE-2013-2172 CVSS 5.0)
IT38877SECURITY VULNERABILITIES IN XSTREAM AFFECT THE B2B API OF IBM STERLING B2B INTEGRATOR
IT33759IBM STERLING B2B INTEGRATOR VULNERABLE TO CROSS-SITE AJAX REQUEST VULNERABILITY DUE TO PROTOTYPE JAVASCRIPT (CVE-2008-7220)
IT38705INFORMATION DISCLOSURE SECURITY VULNERABILITY EXISTS IN THE REST B2B API IN IBM STERLING B2B INTEGRATOR
IT39126DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT38890SECURITY VULNERABILITIES IN ECLIPSE JETTY AFFECT IBM STERLING B2B INTEGRATOR (CVE-2021-34428, CVE-2021-28169, CVE-2021 CVSS 5.3)
IT40669IBM STERLING FILE GATEWAY IS VULNERABLE TO MULTIPLE ISSUES DUE TO BOUNCY CASTLE
IT39125DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39545SECURITY VULNERABILITY IN APACHE COMMON IO AFFECTS IBM STERLING B2B INTEGRATOR (CVE-2021-29425 CVSS 7.5)

 

Regular Fixes

APARDescription
IT39936NULLPOINTEREXCEPTION OCCURRED IN DELETING MESSAGE WITH MAILBOX DELETE SERVICE FOR GLOBAL MAILBOX
IT39935FILES ARE NOT BEING REMOVED FROM FILE SHARE EVEN THOUGH THEY ARE DELETING ALL MAILBOX MESSAGES AFTER 14 DAYS WITH A BUSINESS PROCESS
IT41631ENHANCE B2B MAIL CLIENT ADAPTER FOR ACCESSING MICROSOFT EXCHANGE WITH OAUTH 2.0

Fix Pack (V6.1.2.1)
 
LinkDate ReleasedStatus
Download
 
Note: This Fix Pack also contains APAR security and regular fixes from 6.1.0.6 release.
 

Security Fixes

 
APARDescription
IT42094
SECURITY VULNERABILITIES IN JACKSON-DATABIND EXISTS IN B2B API OF IBM STERLING B2B INTEGRATOR FROM CORE-IO JAR (CVE-2019-12384 AND OTHERS CVSS 9.8)
IT39422DBS HAS REPORTED SECURITY VULNERABILITY, INSUFFICIENT AUTHORIZATION CONTROLS ON 6.0.3.3
IT39547SECURITY VULNERABILITY IN HTTPCLIENT AFFECTS IBM STERLING B2B INTEGRATOR (CVE-2020-13956  CVSS 5.3)
IT39357DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39360INFORMATION DISCLOSURE SECURITY VULNERABILITY EXISTS IN THE USER INTERFACE OF IBM STERLING FILE GATEWAY (DBS VERBOSE ERROR MESSAGE)  (CVE-2021-39086 CVSS 4.3)
IT39562SECURITY VULNERABILITY IN APACHE COMMON COMPRESS 1.20 AFFECTS B2B API OF IBM STERLING B2B INTEGRATOR (CVSS 5.5)
IT39105DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT41648SECURITY VULNERABILITY EXISTS IN SFTP SERVER ADAPTER 2.0 IN IBM STERLING B2B INTEGRATOR
IT39958XSS SECURITY VULNERABILITIES EXISTS IN DASHBOARD UI OF IBM STERLING B2B INTEGRATOR (DBS)
IT40312XSS SECURITY VULNERABILITIES EXISTS IN DASHBOARD UI OF IBM STERLING B2B INTEGRATOR (DBS)
IT39438DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39434DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39433DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39424DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39442DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39440DBS HAS REPORTED SQL INJECTION VULNERABILITY ON 6.0.3.3
IT42395DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT42393DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT42394XSS SECURITY VULNERABILITY EXISTS IN THE MAILBOX UI OF IBM STERLING B2B INTEGRATOR (CHECKMARX)
IT42443DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT40617SECURITY VULNERABILITY IN JDOM AFFECTS IBM STERLING B2B INTEGRATOR (CVE-2021-33813 CVSS 5.3)
IT41715SPECIAL CHARACTERS CAN BE ENTERED TO A LOG FILE WITH UNSUCCESSFUL LOGIN TO DASHBOARD UI OF IBM STERLING B2B INTEGRATOR
IT41002
SECURITY VULNERABILITIES IN CKEDITOR EXISTS IN B2B API OF IBM STERLING B2B INTEGRATOR (CVSS 7.6)
IT39104DBS HAS REPORTED STORED CROSS SITE SCRIPTING VULNERABILITY ON 6.0.3.3
IT39235DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT40841ACCESS CONTROL VULNERABILITY EXISTS IN SFTP SERVER ADAPTER IN IBM STERLING B2B INTEGRATOR
IT41672[DAS] SQL INJECTION SECURITY VULNERABILITY EXISTS IN EBICS UI OF IBM STERLING B2B INTEGRATOR (CVE-2022-22338 CVSS 6.3)
IT41689DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT41362DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT42828SECURITY VULNERABILITY IN GOOGLE GSON AFFECTS IBM STERLING B2B INTEGRATOR (CVE-2022-25647 CVSS 7.7)
IT39127DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT41371IBM STERLING B2B INTEGRATOR IS VULNERABLE TO DENIAL OF SERVICE DUE TO NETTY (CVE-2021-37136, CVE-2021-37137)

 

Regular Fixes

APARDescription
IT42216OAUTH2_1.CLASS_NAME PROPERTY IN OAUTH2.PROPETIES GOT INCORRECT ABSOLUTE CLASS NAME
IT42353SFTP CLIENT ADAPTER SESSIONS ARE NOT DISTRIBUTED ACROSS CLUSTER NODES
IT41822REST API STILL DISPLAYS DELETED PERMISSIONS IF LISTED DIRECTLY VIA THE URL
IT41893OAUTH2 ERROR - B2BMAIL ADAPTER FAILED TO GET AN ACCESS TOKEN JAVA.IO.IOEXCEPTION: SERVER RETURNED HTTP RESPONSE CODE: 401
IT42317ORACLEPOOL.URL NOT READ FROM FROM THE CUSTOMER_OVERRIDES.PROPERTIES
IT39392VALUE TOO LARGE FOR COLUMN ON ACT_SESSION.PRINCIPAL
IT39574FILE GATEWAY IS GARBLED WHEN BROWSER PREFERRED LANGUAGE IS CHINESE
IT37315CREATE PROPERTY API DOESN'T CREATE PROPERTY IN CUSTOM_PROPERTY TABLE
IT37845BROWSER CACHE ISSUE WHILE LOGIN TO MYFG 2.0 UI
IT39345EDIINTPARSE BP FAILS WITH FAILURE UNPACKAGING MESSAGE ERROR - CLASS: 0; SUBCLASS: 0; CODE: 0;
IT41706GLOBAL MAILBOX - FILES UPLOADED TO ONE DC ARE NOT REPLICATED TO THE OTHER DC
IT41065GLOBAL MAILBOX EVENT RULE ADAPTER DOES NOT RESPECT BATCH MODE AND INVOKES AS IMMEDIATE MODE LEADING TO SAME FILES TO BE PROCESSED TWICE
IT40662FOR SFG ARRIVEDFILE EVENTS THE DATA FLOW HYPERLINK IS NOT AVAILABLE IN FILEGATEWAY WHEN CLICKING ON THE DATA FLOW LINK IN THE ARRIVED FILE SEARCH SCREEN

Fix Pack (V6.1.2.2)
 
LinkDate ReleasedStatus
Download
 
Note: This Fix Pack also contains APAR security and regular fixes from releases:
 

Security Fixes

 
APARDescription
IT42936DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT42935DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43058DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT42505DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT41109
THE SECURITY VULNERABILITIES IN APACHE SANTUARIO XML SECURITY AFFECT IBM STERLING B2B INTEGRATOR (CVE-2021-40690, CVE-2014-8152 CVSS 5.3)
IT42985INFORMATION DISCLOSURE SECURITY VULNERABILITY EXISTS IN RESOURCE IMPORTER OF IBM STERLING B2B INTEGRATOR (CVE-2023-25682 CVSS 6.2)
IT43099
SECURITY VULNERABILITY IN DOJO TOOLKIT AFFECTS EBICS CLIENT UI OF IBM STERLING B2B INTEGRATOR (CVE-2020-23450 CVSS 9.8)
IT43055DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39312SECURITY VULNERABILITY IN APACHE XML SECURITY AFFECTS IBM STERLING B2B INTEGRATOR (CVE-2021-40690 CVSS 5.3)
IT43051CSRF SECURITY VULNERABILITY EXISTS IN ROSETTANET SEARCH IN DASHBOARD UI OF IBM STERLING B2B INTEGRATOR (CVE-2022-35638)
IT43057SECURITY VULNERABILITY IN XSTREAM AFFECTS IBM STERLING B2B INTEGRATOR (CVE-2022-41966 CVSS 8.2)
IT42806DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT42896
SECURITY VULNERABILITIES IN SPRING SECURITY AFFECTS IBM STERLING B2B INTEGRATOR (CVE-2022-31692, CVE-2022-22978 CVSS 8.2)

 

Regular Fixes

APARDescription
IT42781IN SI 6.1.2 AWS S3 GET SERVICE DOES NOT WORK FOR GETTING FILES MATCHING A PATTERN
IT42807EVENT SCREEN ON MYFG2.0 DOESN'T FINISH LOADING
IT43081XML DIGITAL SIGNATURE SERVICE HAS BEEN ENHANCED TO SUPPORT STAX DOCUMENT STREAMING IN SIGNING AND VERIFICATION OPERATIONS
IT43041WSDL SERVICE IS FAILING AND UNABLE TO REDIRECTING TO HTTPS PORT
IT42383DEVELOP MSSQL FRIENDLY DATASWEEPER TO CLEAN UP *_GUID TABLES
IT42827OLD JARS IN THE <INSTALL_DIR>/PACKAGES DIRECTORY ARE NOT REMOVED
IT43030UNABLE TO CATCH THE EXCEPTION FROM PGPUNPACKAGESERVICE IN ONFAULT
IT42726PGP PACKAGE SERVICE SIGNS DOCUMENT ALSO IF "SIGNED BY THE PARTNER" SET TO NO

Fix Pack (V6.1.2.3)
 
LinkDate ReleasedStatus
Download
 
Note: This Fix Pack also contains APAR security and regular fixes from 6.1.1.4 release.
 

Security Fixes

 
APARDescription
IT43555
VULNERABILITY IN THE APACHE JAMES MIME4J LIBRARY USED BY IBM WEBSPHERE APPLICATION SERVER LIBERTY WHEN THE FEATURE RESTFULWS-3.0 IS ENABLED (CVE-2022-45787 CVSS 5.5)
IT43678SECURITY VULNERABILITIES IN SNAKEYAML AFFECT B2B API OF IBM STERLING B2B INTEGRATOR (CVE-2017-18640, CVE-2022-25857, CVE-2022-38749, CVE-2022-38750, CVE-2022-38751, CVE-2022-38752, CVE-2022-41854, CVE-2022-1471 CVSS 8.3)
IT43937DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43308SECURITY VULNERABILITIES IN XSTREAM AFFECT IBM STERLING B2B INTEGRATOR (CVEID: CVE-2022-40151, 40152, 40153, 40154, 40155, 40156 CVSS 6.5)
IT43649SECURITY VULNERABILITIES IN JETTISON AFFECT EBLICS CLIENT OF IBM STERLING B2B INTEGRATOR (CVE-2023-1436, CVSS 5.3)
IT43908[ALL] APACHE COMMONS FILEUPLOAD (PUBLICLY DISCLOSED VULNERABILITY) (CVE-2023-24998 CVS 7.5)
IT43976DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT42806DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43090DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43549DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43522DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43941DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43508DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43138DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43972DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT43848DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)

 

Regular Fixes

APARDescription
IT43905MORE CHINESE DASHBOARD UI IS GARBLED IN 6.1.2.1
IT39345OBSERVED SLOWNESS IN AS2 WITH LARGE FILE
IT43438CURRENT PROCESSES AND CENTRAL SEARCH PAGE IS NOT WORKING
IT43693WITH NIST TRANSITION OR STRICT MODE ENABLED, SSH KNOWN HOST KEY ECDSA-SHA2-NISTP256 KEYS CANNOT BE ENABLED WITH DEFAULTSFTP=1.0
IT43692WITH NIST TRANSITION OR STRICT MODE ENABLED, SSH KNOWN HOST KEY ECDSA-SHA2-NISTP256 FAILS TO BE CHECKED IN OR IMPORTED
IT43321DELETE ROUTINGCHANNEL API RETURNS 400 RESPONSE, ROUTING CHANNEL IS DELETED
IT41328QUERY ON FG_ROUTE TABLE DOES NOT USE BIND VARIABLES
IT43401UTF-8 ENCODING FAILS WHILE RUNNING JSON TO XML TRANSFORMER SERVICE
IT43734ERROR EXCEPTION DECRYPTING PASSPHRASE
IT43785NOT ABLE TO SEND EMAIL FROM STERLING INTEGRATOR TO MS EXCHANGE ONLINE USING SMTP SEND ADAPTER
IT43735SI 6.1.1 KEEP GETTING EXCEPTION DECRYPTING PASSPHRASE -JAVAX.CRYPTO.BADPADDINGEXCEPTION: GIVEN FINAL BLOCK NOT PROPERLY PADDED
IT43761SCP OPTIONS DO NOT SHOW IN SFTP SERVER ADAPTER OF V6.1.2.2
IT43554INTERMITTENT SSH HANDSHAKE FAILURES WITH B2BI AS CLIENT <MAVERICK JAR UPGRADE 1.7.51>
IT43689EXTERNAL PURGE DB2 SQL ERROR: SQLCODE=-805, SQLSTATE=51002, SQLERRMC=NULLID.SYSLH203
IT44027UNABLE TO EXPORT/IMPORT OFTP PROFILE IN A SYSTEM USING A DIFFERENT SYSTEM PASSPHRASE
IT42218ROUTING CHANNEL FOR A GLOBAL MAILBOX PARTNER VIA THE ROUTING CHANNEL REST API WHEN A DC IS DOWN
IT41142WHEN CREATING ROUTING CHANNELS (VIA RESTAPI) FOR A PRODUCER PARTNER WITH SUBMAILBOXES THE EVENT RULE IS GETTING CREATED FOR THE FIRST SUBMAILBOX ONLY AND NOT THE SUBSEQUENT SUBMAILBOXES, AND THE EVENT RULE LIST ONLY 1 MAILBOX
IT43250REST API UPDATE TRADING PARTNER API000411 ERROR FOR GLOBAL MAILBOX LISTENING PRODUCER
IT43645GM IMPORT UTILITY FAILS WITH JAVA.LANG.NOCLASSDEFFOUNDERROR: ORG.APACHE.COMMONS.COLLECTIONS.ARRAYSTACK
IT44610IDOC META DATA BUILlDER IS LOOPING IN+C84 VERSION 6010201

Fix Pack (V6.1.2.5)
 
LinkDate ReleasedStatus
Download
 
Note: This Fix Pack also contains APAR security and regular fixes from releases:

Security Fixes

 
APARDescription
IT44322SECURITY VULNERABILITY IN COMMONS-BCEL AFFECT IBM STERLING B2B INTEGRATOR (CVE-2022-42920 CVSS 9.8)
IT45063DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44862SECURITY VULNERABILITY IN NETTY AFFECTS IBM STERLING B2B INTERGRATOR (CVE-2023-34462 CVSS 6.5)
IT44329DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT45062DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44198
[ALL] IBM WEBSPHERE MQ - CVE-2023-32342 (PUBLICLY DISCLOSED VULNERABILITY) ( CVSS 5.9)
IT40443MISSING SAMESITE ATTRIBUTE IN THE COOKIE GENERATED BY DASHBOARD PAGES
IT43976DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44222DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44223ADD BOUND TO THE LOOP CONDITION IN BASEUIGLOBALS.ESCAPESPECIFICCHARS FOR THE FINDINGS FROM CHECKMARX
IT44899XSS SECURITY VULNERABILITY EXISTS IN THE UI OF IBM STERLING FILE GATEWAY (FROM DBS (CVE-2023-47714 CVSS 4.8)
IT44144XSS SECURITY VULNERABILITY EXISTS IN THE DASHBOARD UI OF IBM STERLING B2B INTEGRATOR FROM DBS 
IT44091DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44092DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44415DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44287DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44317DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44304DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44312DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44284DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44311DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44283DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44078ECLIPSE JETTY (PUBLICLY DISCLOSED VULNERABILITY) (CVSS 5.3)
IT43591UPDATE ESAPI-JAR-LEGACY (CVSS 7.5)
IT44559XSS SECURITY VULNERABILITY EXISTS IN THE DASHBOARD UI OF IBM STERLING B2B INTEGRATOR FROM DBS 
IT44182UPDATE SNAPPY-JAVA IN B2B API (CVSS 7.5)
IT44452NO WEB SECURITY HTTP RESPONSE HEADERS ARE RETURNED IN THE WEBAPP ON HTTP SERVER ADAPTER IN IBM STERLING B2B INTEGRATOR (CVE-2024-22355)
IT44185UPDATE STRUTS FOR SECURITY VULNERABILITIES (CVSS 7.5)
IT45140UPDATE JACKSON-DATABIND (CVSS 5.5)
IT43508DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)

 

Regular Fixes

APARDescription
IT44536EXCESSIVE TX.LOG INFORMATION AFTER UPGRADING TO STERLING INTEGRATOR 6.1.2.3
IT44524DISCEPERANCY IN LISTING USERS IN USER LISTS WHILE SELECTING USER FOR ROUTING RULE/BUSINESS PROCESS
IT44651OFTP PHYSICAL PARTNER WHILE EDITING, AUTO-CONFIGURE PREVIOUSLY MANUALLY CHOSE CONFIGURATION BY CUSTOMER
IT44758ROOT DOC SIZE SHOWS 0 BYTES FOR THE FILES UPLOADED FROM MYFILEGATEWAY IN SI VERSION 6.1.2.2
IT44593GENERIC EDIFACT OUTBOUND UNH ENVELOPE REGRESSION
IT44446GETTING "UNDEFINED" MESSAGES WHILE DELETING GROUP WHEN THAT GROUP IS USED IN RCT
IT44847RETRIEVEERRORSETSUCCESS PARAMETER IN SFTP CLIENT GET SERVICE IS NOT TAKEN INTO ACCOUNT WITH SFTP2.0
IT44213SFTP CLIENT GET NOT RETURNING THE DOCUMENT DOWNLOADED TO PRIMARYDOCUMENT WHEN TRANSFER MODE IS SET TO ASCII
IT44361404 WHEN ACCESSING MYFILEGATEWAY WITH REBRANDING AFTER UPGRADING TO 6122
IT44443NETMAP CORRUPTION WHEN SYNCING
IT44023EBICS SERVER COF ORDERS ARE NOT VEU ENABLED
IT44939EC / SERVICES INVESTIGATION - CDSA DB FAILUREOVER "OPTIMIZATION"
IT38789CUSTOMER_OVERRIDES PROPERTIES IN CUSTOMIZATION-UI / DB ARE NOT DISPLAYED IN QUEUEWATCHER
IT44894INCORRECT FILENAME WHILE DECRYPTING NATIVE PGP ENCRYPTED FILE
IT45025EBICS SERVER - COF CANNOT BE CONFIGURED FOR CERTAIN FILE FORMATS WITH HF6
IT45010EBICS CLIENT/SERVER - PROCESSING STILL CREATES 16BYTE FILE ON DISC AND LEFT OVER
IT44793CHANGES DONE USING UPDATE SERVICE INSTANCE REST API DO NOT REFLECT IN THE UI
IT44787EBICS SERVER - CANNOT VIEW EBICS REQUEST FROM SFG UI WHEN THE BROWSER IS CONFIGURED WITH SPANISH LANGUAGE
IT44626SAP RFC XML SCHEMA BUILDER DOESN'T WORK IN SI 6123
IT44974NOT ABLE TO INSTALL PS IN WIN 2K22
IT44619CHANGE URI IN DOCUMENTION FOR SFG FILEGATEWAY_UI.PROPERTIES
IT44618SFTP CLIENT ERROR IN SERVICE SFTPCLIENTENDSESSION (NULLPOINTEREXCEPTION) SINCE UPGRADE TO B2BI 6114
IT44753ROSSETTANET MESSAGE PARSER SERVICE ERROR OUT WITH "COM.TRUSTPOINT.ASN.ASNEXCEPTION: CANNOT FIND CLASS NAME FOR OID: OID 1.2.840.113549.1.9.52"
IT44830REWORK FIX TO REST API TO NOT GET PERMISSIONS DELETED THROUGH DASHBOARD
IT44755UNABLE TO DECRYPT SIGNED FILE THROUGH OFTP2 IN 6123
IT44754XMLJSONTRANSFORMER 6.1.2.3: UNABLE TO ACCESS OR VERIFY MANDATORY SERVICE PARAMETER
IT44247EBICS SERVER: OOM WHEN PROCESSING HVZ AND HVU EBICS REQUEST
IT44927INCORRECT FILENAME WHILE DECRYPTING NATIVE PGP ENCRYPTED FILE
IT44566ERROR IN CHECKOUT SSH USERIDENTITYKEY AFTER USING CHANGESYSTEMPASSPHRASE.SH IN SI 6120
IT44521APAR IT33167 IS NOT PRESENT IN 6.1.2.3 RELEASE
IT44356CANNOT EDIT CODES AFTER SORTING CODELIST BY SENDER CODE/RECEIVER CODE IN SI V6.1.2.3
IT45011EBICS SERVER - HAC PROCESS DOES NOT RETURN ANY EVENTS
IT44801AS2 PROTOCOL: CANNOT FIND A CLASS THAT CORRESPONDS TO OID 1.2.840.113549.1.1.10
IT45083EBICS SERVER - CASCADE DELETE NOT WORKING FOR COF ORDER
IT43985LOCAL_QUORUM ERROR AND FILE TRANSFERS ARE FAILING
IT44494PAYLOADPURGE NOT DELETING FILES ON FILESYSTEM ON HORIZON DC
IT44417HEALTHCHECK TAKES TOO LONG TO PERFORM SHUTTING DOWN CONNECTION TO DC'S
IT45164LIVENESS PROBE FAILED: STARTING LIVENESS PROBE FOR API - LIBERTY SERVER IS NOT UP
IT45162EBICS CLIENT LINDE CONNECTIVITY ISSUE FOR HEV
IT45234EBICS 3.0 NEW CUSTOM BTF SERVICE FAILS
IT45119GLOBAL MAILBOX HEALTHCHECK MESSAGE GETTING EXPIRED AFTER DEFAULT NUMBER OF DAYS AND LEADING TO HEALTHCHECK FAILURE
IT45118EBICS SERVER - HKD ORDER TYPE ERROR FOR H003 AND H004 NOT WORKING WITH HF6
IT44045EBICS SERVER - HPB FAILING FOR CLIENT IN PROD BECAUSE OF FILE FORMAT
IT45284UPGRADE TO 6.1.2.2 OR 6.1.2.3, OR INSTALL A FRESH COPY OF 6.1.2.X, THERE ARE 2 CDJAVA.JAR FILES IN DYNAMICCLASSPATH.CFG, THE OLDEST JAR SHOULD BE REMOVED

iFix Pack (V6.1.2.5_1)
 
LinkDate ReleasedStatus
Download
 
Security Fixes
 
APARDescription
IT46478DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)

Fix Pack (V6.1.2.6)
 
LinkDate ReleasedStatus
Download
Note: This Fix Pack also contains APAR security and regular fixes from 6.0.3.9 release.
 

Security Fixes

 
APARDescription
IT45059SECURITY VULNERABILITIES FOUND IN PENETRATION TESTING: TRACK SQL INJECTION
IT46388STORED XSS IN SSH REMOTE PROFILE CREATION UI
IT46193NAB FINDING 129290-3 - THE IBM STERLING INTEGRATOR ADMIN WEB APPLICATION IS VULNERABLE TO STORED CROSS-SITE SCRIPTING (XSS) IN THE CREATION OF A NEW PGP SECRET KEY
IT45045PERSISTENT XSS SECURITY VULNERABILITIES FOUND IN PENETRATION TESTING
IT46767DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46083STORED XSS SECURITY VULNERABILITY EXISTS IN STERLING INTEGRATOR IN DEPLOYEMENT -->MAILBOXES --> MESSAGES USING THE RENAME SFTP COMMAND - WITH MAVERICK SFTP SERVER
IT451973RD PARTY: H1-2283533: 'STORED CROSS-SITE SCRIPTING IN IBM STERLING FILE GATEWAY USING THE RENAME SFTP COMMAND'
IT46849UPGRADE APACHE AXIS (CVSS 9.8)
IT46567DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46832DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46707DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46464DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT45994DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46060DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46966UPDATE IBM LIBERTY SERVER (CVSS 5.3)
IT46967UPDATE LIBERTY (CVSS 7.5)
IT43937UPGRADE COMMONS NET JAR IN WMQFTE_CORE_BUNDLE_9_2_0_7.JAR (CVSS 6.5)
IT46103STORED XSS ON QUEUEWATCHER UI (VIEW STATELESS ADAPTERS) - FSA ADAPTER
IT46748DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44322SECURITY VULNERABILITY IN APACHE XALAN AFFECTS IBM STERLING B2B INTEGRATOR (CVSS 7.3)
IT46036UPDATE APACHE COMMONS COMPRESS (CVSS 5.5)
IT46268DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46478DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT45450UPDATE APACHE SANTUARIO (CVSS 6.5)
IT45485UPDATE JSON-JAVA (CVSS 7.5)
IT45690DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT45722DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46458DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46965DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46254UPDATE MQ (CVSS 7.5)
IT46964DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT45521UPDATE MAVERICK SERVER AND CLIENT FOR A HIGH-RISK SECURITY VULNERABILITY
IT45233UPDATE SPRING BOOT (CVSS 5.3)
IT46084STORED XSS SECURITY VULNERABILITY EXISTS IN STERLING INTEGRATOR IN DEPLOYEMENT -->MAILBOXES --> MESSAGES USING THE RENAME SFTP COMMAND - ISSUE WITH APACHE 20 SERVER
IT46100STORED XSS SECURITY VULNERABILITY EXISTS IN STERLING INTEGRATOR IN DEPLOYEMENT -->MAILBOXES --> MESSAGES USING THE RENAME FTP COMMAND
IT44109XSS SECURITY VULNERABILITY EXISTS IN DASHBOARD UI OF IBM STERLING B2B INTEGRATOR FROM CHECKMARX SCAN (CVSS 4.6)
IT44314DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44081DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44440DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44303DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT45596USERID (CLEAR TEXT) AND DLSSO TOKEN (BASE64 ENCODED) BEING VISIBLE AND UNENCRYPTED IN THE URL OF BROWSER ADDRESS LINE WHEN CLICKING "LAUNCH CUSTOMIZATION ADMINISTRATION UI" IN DASHBOARD
IT46252NAB F129290-12-CROSS-SITE SCRIPTING (XSS)"TRADING PARTNER – SSH – AUTHORIZED USER KEY"
IT46739DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT45244DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46955DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46396DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46931DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT45620UPDATE JSON-JAVA IN MEG JARS (CVSS 7.5)
IT46798DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46353UPDATE BOUNCY CASTLE (CVSS 7.5)
IT45204DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47147DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT45140UPDATE JACKSON-DATABIND (CVSS 5.5)
IT46045SECURITY VULNERABILITY IN APACHE MINA SSHD AFFECTS IBM STERLING B2B INTEGRATOR (CVSS 6.5)
IT47206UPDATE NETTY (CVSS 5.3)
IT47207DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47204DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47205DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT45623ADD AUTHORIZATION TO MYFG 2.0
IT46195DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46983UPDATE JETTY (CVSS 5.3)
IT46710IBM STERLING B2B INTEGRATOR IS AFFECTED BY MULTIPLE VULNERABILITIES IN CKEDITOR

 

Regular Fixes

APARDescription
IT45445ERROR UPDATING AS2 RELATIONSHIP VIA REST API
IT45320REQUEST FOR CORRECTIONS TO MYFILEGATEWAY PHRASING FOR THE NORWEGIAN LANGUAGE
IT45170REST API CLIENT FOR DELETE OPERATION RETURNS HTTP 405 METHOD NOT ALLOWED
IT46128STERLING SFTP SERVER ADAPTER IS NOT ALLOWING TO CREATE DIRECTORY (MKDIR) WITH ABSOLUTE PATH AFTER RUNNING IS COMMAND
IT45932ERRORS REPORTED IN FTPCLIENT.LOG WHEN DOING A FTP LIST
IT45709STORED CROSS SITE SCRIPTING
IT45066JCE_DIST_FILE PARAMETER PRESENT IN UPGRADED SI 6.1.2.1 AND ABOVE
IT46851IMPROPER SERVER VALIDATION ON EMAIL FIELD
IT45190UNABLE TO GENERATE GRAPHICAL TRAFFIC SUMMARY REPORT AFTER UPGRADE
IT45808UPGRADE FROM 6114 TO 6125 FAILS WHEN FIPS MODE IN ENABLED
IT45934MAILBOX MESSAGE CAN'T BE VIEWED THROUGH UI WHEN MESSAGENAME IS SHORTER THAN 3 CHARATERS
IT46775GLOBAL MAILBOX EVENT RULES DISAPPEARING
IT45201WORKFLOWMONITOR APIS FAILING WHEN MULTIPLE API PODS EXIST IN OCP ENV
IT45464COM.IBM.JSSE2.RENEGOTIATE=DISABLED DOES NOT DISABLE SSL RENEGOTIATION    
IT46318XMLTOJSONTRANFORMER ERRORS AFTER UPGRADE TO 6.2.0.1        
IT45749UPDATES TO SPEC2000 ATA STANDARDS
IT46504CMS SERVICE FAILING TO VERIFY SIGNATURE WITH ERROR: CANNOT FIND CLASS NAME FOR OID: OID 1.2.840.113549.1.9.52
IT46453STERLING B2B INTEGRATOR DOESN'T START AFTER THE UPGRADE TO 6.1.2.5 ON WINDOWS 2022    
IT45313SOA OUTBOUND MESSAGE CREATION TAKES A SIGNIFICANTLY LONG TIME    
IT453106.1.2.3 FAILED_DELETE_LOG CONTAINS ENTRIES FOR ALREADY DELETED FILES  
IT45315PASSWORD FIELD FOR CREATING AND UPDATING AS2 PARTNERS USING THE API B2BAPIS/SVC/AS2TRADINGPARTNERS/ IS NOT MASKED
IT45754UNABLE TO STOP EXTERNAL PURGE    
IT45718CHECKOUT OF AUTHORISED USER KEY NOT GENERATING THE KEY IN OPENSSH FORMAT WHEN DEFAULTSFTP IS SET TO 2.0    
IT45873PROPERTY *.FORCEREMOTEDNS=TRUE NOT HONOURED IN SSHKEYGRABBER WITH REMOTE PERIMETER SERVER AND DEFAULTSFTP=2.0    
IT45115OPTION "USE IMPLICIT SSL" IN SFG PARTNER PROTOCOL DOES NOT RETAIN THE NON-DEFAULT "YES" SETTING
IT45610DELETE OPERATION ON /B2BAPIS/SVC/WORKFLOWS NOT WORKING CORRECTLY
IT46389PROFILE IMPORTS FAIL DUE PGP FIELD IS REQUIRED EVEN THOUGH PROFILE DOESN'T USE PGP
IT45770UI PERFORMANCE ISSUES CD NODES/XREF
IT45447NATIVE PGP ENCRYPTION OVER TEXTMODE
IT45311WEBSPHEREMQ SUITE ASYNC RECEIVE ADAPTER - INCONSISTENT STATUS AFTER DEPLOYMENT
IT45462SSHKEYGRABBER - JAVA.LANG.NULLPOINTEREXCEPTION USING REMOTE PS ON 6.1.2.3
IT45901UPGRADE TO 6.1.2.4 (OLD MEDIA) THROWS ERROR "[TEMPLATEDEPLOYER.WORK()] ERROR OCCURED DEPLOYING TEMPLATE: ...."    
IT46134CAN'T LIST THE UPLOAD/DOWNLOAD FILES MENU IN MYFILEGATEWAY 2.0
IT45898PROPERTY FOR ENABLE OR DISABLE CASE SENSITIVITY IN SFTP CLIENT LIST SERVICE IN A FUTURE FIX PACK
IT45178FAILURES DURING SFTP PUT SERVICE ARE NOT SHOWN ON THE COMMUNICATION SESSION DETAILS SCREEN
IT456556124 DUMMY IFIX INSTALLATION IS FAILING ON RHL AND WINDOWS
IT46465SSHD CLIENT CAUSING MEMORY LEAK IN 6122
IT46568"KB DEBUG NEW CODE IN PLACE" IN EXTPURGE_EXE.LOG
IT46466PGP UNPACKAGE SERVICE CORRUPTING DOCUMENT NAME    
IT44592B2BI UPGRADE UPDATES THE DOCUMENT STORAGE OF BUSINESS PROCESSES
IT45663PURGE PROCESS NOT PURGING ALL THE FILES ON FILESYSTEM
IT46328ADMIN AUDIT REPORTS SHOW WRONG USER AROUND CERTIFICATES, CONTRACTS, AND BP    
IT46467ENTRY IN CUSTOMER_OVERRIDES NOT USED FOR CHECK_EXPIRE_DAYS    
IT45840ASI, AC, AND API PODS TAKING LONGER TIME TO STARTUP IN V6.1.2.3    
IT45461EDIINTPARSE BP FAILS WITH FAILURE UNPACKAGING MESSAGE ERROR - CLASS: 0; SUBCLASS: 0; CODE: 0
IT45200PRODUCTION, PEM/PCM 504 GATEWAY TIMEOUT WHEN CONNECTING TO B2BI REST APIS IN OCP ENVIRONMENT
IT46177RUNNING WORKFLOW LAUNCHER CREATES A NEW SYSTEM.LOG FOR EVERY EXECUTION    
IT45827AVAILABLE CYPHERS ARE DIFFERNT IN UI AND WITH RESTAPI    
IT46773ISSUE WITH SFTP DELETE SERVICE ON WINDOWS SERVER WITH SOLAR WINDS SFTP_SERVER    
IT45459WEBSPHERE MQ SUITE ASYNC RECEIVE ADAPTERS DO NOT START UP AFTER RESTART    
IT46805B2B MAIL CLIENT ADAPTER VERY SLOW TO RETRIEVE MESSAGES    
IT46506IN B2BI 6.1.2.1 THE APPLICATION REPORTS THE SFTP 2.0 LOGIN METHOD AS 'PASSWORD' EVEN WHEN THE USER LOGS IN USING A PUBLIC KEY.
IT46449ERRORS IN THE PERIMETER.LOG AND THE SYSTEM.LOG, BUT THE CAUSE IS UNCLEAR
IT45173UNABLE TO VIEW FULL LIST OF PREFERRED MAC ALGO LISTS IN RESTAPI    
IT46778USING MULTIPLE PARAMETERS IN LDAP SEARCH_FILTER    
IT46410AFTER UPGRADE TO 6.0.3.9, NEED A WAY TO SPECIFY A CONTENT SECURITY POLICY
IT45569EXCESSIVE LOGGING IN MAVERICK3SP.LOG AFTER UPGRADING TO 6.1.2.2    
IT44193HEALTHCHECKUTILITY.SH RECEIVE SEVERE: ERROR WHILE CALLING WATCHER. JAVA.LANG.NULLPOINTEREXCEPTION
IT46378H005 ORDER TYPES ARE NOT DISPLAYED CORRECTLY WHEN CREATING A NEW OFFER    
IT45672NEED SYNTAX FOR OPSCMD SETTUNINGPARAMS    
IT46944SUPPORT OBJECT EXPORT WITHOUT DEPENDENCIES
IT46983EBICS CLIENT URL THROWS 503 SERVICE UNAVAILABLE

Fix Pack (V6.1.2.7)
 
LinkDate ReleasedStatus
Download
Note: This Fix Pack also contains APAR security and regular fixes from 6.0.3.9 release.
 

Security Fixes

 
APARDescription
IT47587DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47513DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT45994DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47147DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47604DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47169DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39127DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47598DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47465DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47672DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47589DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44307DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47669DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47407DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46745DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46746DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT44310DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47666DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47605DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47475DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47361DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47425DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47683DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47515DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT39127DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47165DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47786DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47787DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47791DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47792DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47793DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47794DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47788DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47789DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47795DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47790DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46742DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
GM-13428DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
GM-13398DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
GM-13391DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)


Regular Fixes
 

 
APARDescription
IT47620IBM WEBSPHERE APPLICATION SERVER LIBERTY UPGRADE
IT47367MQFTE INBOUND FLOWS TO B2BI MAILBOX IS NOT WORKING ON FRESH AND UPGRADED SETUP'S
IT47496RECONCILE: EBICS ORDERS ARE FAILING WHEN DB USED IS MSSQL (RECONCILE 6204 REL FIX TO 6127 MAINT BRANCH)
IT47368FTE AGENT ADAPTER IS NOT GETTING ENABLED. REMAINS IN STOPPED STATE
IT47270HISTORICAL: PREFERRED CIPHER LIST WHILE CREATING SSH REMOTE PROFILES FROM B2BAPIS ARE NOT PICKED UP FROM PROPERTIES LIKE IT IS DONE FOR B2BI DASHBOARD
IT47325PERMISSION CREATION IS FAILING ON BUILD CYCLE 354 AND ABOVE
IT47414DISALLOW THE UPLOADING A FILE THAT IS FILTERED BY ITS EXTENSION
IT47202MBI REMAIN ALERT POP-UP INVALID DATE FORMAT. DATE FORMAT IS YYYY-MM-DD
IT47619DISABLE MQCSP AUTHENTICATION MODE - GETTING 2035 NOT_AUTHORIZED ERROR
IT47220ZIP FILES SENT USING RESTAPICLIENT POST HAS ADDITIONAL NEW LINE CHARACTER
IT47201UNABLE TO SEND ZIP FILES USING RESTAPICLIENT USING PUT
IT46968UPGRADE TO 6.1.2.5 RESETS THE JVM MEMORY TO 1920 MB
IT47271WSMQ BACKOUTENABLED=TRUE IS NOT WORKING
IT47413STERLING FILEGATEWAY DEFAULT PGP UNPACKAGE SERVICE NOT PROCESSING CERTAIN REGULAR EXPRESSIONS AFTER UPGRADE TO V6.1.2.6
IT43637HIGH CPU ON BOTH DC1 NODES
IT47614BACKPORT: GLOBAL MAILBOX - ERROR WHEN TRYING TO ACCESS THE GM UI FROM B2BI AFTER UPGRADE TO 6202
IT47015TRADING PARTNER CODE LIST TEXT1 - TEXT9 IN UI ONLY ALLOWS 150 CHARACTERS AND CUTS OFF
IT46608SI VALIDATION MAP IS SENDING CODES TO ITXA TO GENERATE 997 AK403 VALUE AS '10' INSTEAD OF EXPECTED '2'

iFix Pack (V6.1.2.7_1)
 
LinkDate ReleasedStatus
Download
Note: This Fix Pack applies only to IBM Sterling B2B Integrator and does not contain fixes for Global Mailbox.
 

Security Fixes

 
APARDescription
IT48006DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47864SECURITY VULNERABILITY - XSS ISSUES ON OFTP PROFILE SCREENS (CVSS 5.4)
IT47924STORED XSS IN MAILBOX DIRECTORY NAME WHEN THE DIRECTORY IS CREATED USING THE SFTP 1.0 SERVER IMPLEMENTATION
IT47893APPLICATION DISPLAYS A USER INPUT WITHOUT ANY MODIFICATION ON THE QUEUEWATCH LOGIN PAGE
IT47925DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47995DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47867DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48000UPDATE SPRING SECURITY (CVSS 9.1)
IT47921DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46060DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47979DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47947DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47884DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48216DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
 

iFix Pack (V6.1.2.7_2)
 
LinkDate ReleasedStatus
Download
 
 

Security Fixes

 
APARDescription
IT46060DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47586DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48345DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48206DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48350DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48420DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48308DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47863DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48445DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48423DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48402DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48371DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48352DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48335DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48333DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48336DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48126DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48088DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48075DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48426DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48343DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48329DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48356DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48282DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48283DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48425DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48188DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48346DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48334DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)

Fix Pack (V6.1.2.8)
 
LinkDate ReleasedStatus
Download
 

Security Fixes

APARDescription
IT47863DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48206DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48901DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47995DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47672DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47925DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47924DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47893DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47947DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48829DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48640DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48796DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48454DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48505DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48420DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48521DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48958DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48562DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48868DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48832DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48557DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT46060DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48896DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48402DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48371DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48006DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48350DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48308DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48866DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47683DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48480DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48352DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48216DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48198DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48893DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48563DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48302DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48345DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47864DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48828DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48934DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48442DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48597DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48874DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48526DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT48872DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)
IT47979DESCRIPTION IS NOT AVAILABLE (SECURITY/INTEGRITY ISSUE)


Regular Fixes

APARDescription
IT47452XPATHBPLAUNCHEREVENTLISTENER ERROR CAUSED BY FILENAME WITH "&"
IT47774DEBUG ENTRIES IN LOG-FILES WHERE LOG-LEVEL IS SET OFF OR ERROR
IT47119SFG FILEOPERATIONS WORK FLOWS ERRORS OUT IN AN OCP ENVIRONMENT
IT47684STERLING INTEGRATOR 6.1.1.4 SFTP SERVER ADAPTER 2.0 SHOWING WRONG CREDENTIAL TYPE IN THE COMMUNICATION SESSION
IT48824MYFILEGATEWAY - UI COSMETIC DEFECT
IT48129UPDATE B2BAPIS EMAIL VALIDATION TO SUPPORT A WIDER RANGE OF EMAILS
IT48845DOMTODOC IN BP CAUSING .DAT FILES TO BE CREATED IN DOCUMENT_DIR WHICH COULD NOT BE PURGED
IT47727BPDETAIL REPORT SUMMARY SECTION MISSING ASYNC_QUEUED, HALTED_SOFTSTOP, AND ACTIVE_WAITING
IT47714PURGE NOT PURGING ALL THE FILES FROM FILESYSTEM, IF STORAGE IS SET TO FILE SYSTEM
IT47715./CONTROLLERWORKFLOW.SH -F H GENERATE 'UNABLE TO COMMIT CHANGE COULD NOT COMMIT WITH AUTO-COMMIT SET ON' MESSAGE
IT47716ORPHAN ROWS IN TRANS_DATA
IT47728QUEUEWATCHER DOES NOT SHOW ENTRIES FROM CUSTOMIZATION UI IN CLUSTER
IT47600LIVENESSPROBE FAILING TO DETECT CRASHED NOAPP JVM DUE TO INACCURATE GREP IN B2BILIVELINESSCHECK.SH SCRIPT
IT47801THE DIGITAL CERTIFICATES CREATION/UPDATE TIMESTAMP DOES NOT ACCURATELY REFLECT WHEN A CERTIFICATE GETS UPDATED
IT47432SECURE TOKEN IS DISPLAYED FOR A FEW URL'S
IT47885USEREXIT FOR IMAILBOXUSEREXIT_ONMAILBOXCREATE AND IMAILBOXUSEREXIT_ONMAILBOXUPDATE NOT WORKING
IT48656B2BI CRASHING MULTIPLE TIMES REQUIRING A RESTART
IT48839EBICS HEV ORDER FAILING
IT45136MULTIPLE DELETE ERROR IN EXTERNAL PURGE LOGS(EXTPURG.LOG)
IT48851EBICS NEW STEP WHILE CREATING RESOURCE TAG IN VERSION 6.1.2.2
IT48020ENCODING DROP DOWN NOT VISIBLE IN PARTNER ROLE SCREEN WHEN TRYING TO ADD A PARTNER
IT44626SAP RFC XML SCHEMA BUILDER DOESN'T WORK IN SI 6123
IT48037GLOBAL MAILBOX MESSAGES OLDER THEN 30 DAYS ARE NOT EXTRACTABLEIT48058
IT48058PGP DECRYPTION FAILS IF A .PGP EXTENSION IS DETECTED IN THE MIDDLE OF A FILE WITH NO EXTENSION
IT48849EBICS SERVER OFFER CONFIGURATION SIGNATURE VALIDATION ERROR WITH TWO A TYPE SIGNATURES
IT48360CHINESE CHARS IN FILENAME ARE REPLACED WITH BLANK WHEN FILE IS DOWNLOADED VIA BROWSER FROM MYFILEGATEWAY
IT48051ERROR IN EDITING REPORT USING REPORT MANAGER
IT44838MBX_CREATEMESSAGE FUNCTION OF THE EXTRACTABLEUNTIL PARAMETER FOR TIMESTAMPS 12:00 TO 12:59 IS BEING SEEN AS AM INSTEAD OF USING 24HOUR CLOCK
IT44708ERROR IN NOAPP.LOG WHILE RESTARTING B2B INTEGRATOR
IT44802VIRTUAL ROOT RESET TO DEFAULT MAILBOX WHEN PARTNER IS EDITED
IT45663PURGE PROCESS NOT PURGING ALL THE FILES ON FILESYSTEM
IT44466ISSUE EDITING SFG COMMUNITIES WHEN THE UI LANGUAGE IS SET TO GERMAN
IT46846TRANSACTION REGISTER SEARCH REFRESHES SQL QUERY IN PAGE NAVIGATION
IT46851IMPROPER SERVER VALIDATION ON EMAIL FIELD
IT45817TRANSLATION FOR 2 NEW STRINGS IN APPLICATION*.PROPERTIES
IT47886OCP ENVIRONMENT - EXTERNAL PURGE CREATING NEW SYSTEM LOG FOR EVERY START
IT45189SSHMACALGLIST_SSHD SETTINGS ARE NOT REFLECTED IN SSH REMOTE PROFILE
IT44247ERROR CREATING AN EBICS PARTNER CONFIGURATION
IT48840MAILBOX ADD A FILE WITH SPECIAL CHARACTERS - EXTENDED ASCII CHARACTERS IN MESSAGE NAME AND GET ERROR INVALID META DATA [FILENAME]:SPECIFIED VALUE [TESTá_AUG_13.TXT] HAS NON-PERMISSIBLE CHARACTERS.
IT48698IN B2BAPI SCHEDULING, THE "DATEEXCLUSIONS" PARAMETER FAILS TO RETRIEVE MULTIPLE DAYS PER MONTH
IT48841HELM CHART GENERATES WRONG PORT IN INGRESS FOR HELM CHART VERSION 2.0.5
IT48892CHINESE FILEGATEWAY UI IS GARBLED IN 6.1.2.3
IT45560RESUME OF FILE DOWNLOAD USING REGET COMMAND DOES NOT REDUCE THE EXTRATABILITY COUNT OF THE FILE
IT48606MAP EDITOR UNABLE TO LOAD SCHEMA INTO MAP - PROGRAM CLOSES
IT40989OUTBOUND X12 ENVELOPE ISA/IEA CONTAINS INCORRECT WORDING FOR ISA11
IT47888COMMAND LIMITING POLICY IS NOT WORKING INTERMITTENTLY
IT38789CUSTOMER_OVERRIDES PROPERTIES IN CUSTOMIZATION-UI / DB ARE NOT DISPLAYED IN QUEUEWATCHER
IT48886UPGRADE MEIG JARS IN B2BI TO VERSION 1.0.0.12
IT48454UPGRADE MEIG JARS IN B2BI TO VERSION 1.0.0.11

[{"Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SS3JSW","label":"IBM Sterling B2B Integrator"},"ARM Category":[{"code":"a8m50000000CjqAAAS","label":"Sterling File Gateway"}],"Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"6.1.0"}]

Document Information

Modified date:
06 February 2026

UID

ibm16335211