IBM Support

PH44271: Vulnerability in IBM HTTP Server used by IBM WebSphere Application Server due to Expat (CVE-2022-25315 CVSS 7.8 and more)

Download


Downloadable File

File link File size File description

Abstract

Vulnerability in IBM HTTP Server used by IBM WebSphere Application Server due to Expat (CVE-2022-25315 CVSS 7.8 and more)

Download Description

PH44271 resolves the following problem:

ERROR DESCRIPTION:
Confidential for Security Integrity fixCVE-2022-25235, CVE-2022-25236, CVE-2022-25313, CVE-2022-25315

PROBLEM SUMMARY:
Confidential for Security Integrity fix CVE-2022-25235, CVE-2022-25236, CVE-2022-25313, CVE-2022-25315

The fix for this APAR is currently targeted for inclusion
in fix packs 8.5.5.22, 9.0.5.12

For more information, see 'Recommended Updates for WebSphere Application Server':
http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
This fix supersedes (includes) the fix for PH39660, PH40343, PH41945, PH42030, PH42862, PH43122, PH43887, PH44393

 

This fix is superseded by later interim fixes.
The interim fix for this APAR has been superseded by a later interim fix. Download and install the interim fix for PH44829 to resolve this APAR.
If this APAR applied to any older fixpacks that the superseding APAR does not, the download link will be preserved below.

Prerequisites

None

Download Package

 
IMPORTANT NOTE:
WebSphere Application Server and Liberty fix access requires S&S Entitlement in 2021. Use properly registered IDs to download the fixes in this table. 

This fix is superseded by later interim fixes.
The interim fix for this  APAR has been superseded by a later interim fix. Download and install the interim fix for PH44829 to resolve this APAR.

Problems Solved

PH44271, PH39660, PH40343, PH41945, PH42030, PH42862, PH43122, PH43887, PH44393

Change History

  • March 11 2022: Add 9.0.5.11 fixes
  • March 29 2022: Remove all but 9.0.5.9 and add supersede link to PH44829
  • April 11 2022: Remove final 9.0.5.9 fix as PH44271 is being removed from Fix Central.

On

Technical Support

Contact IBM Support at https://www.ibm.com/software/mysupport/s/ or 1-800-IBM-SERV (US only).

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"ARM Category":[{"code":"a8m0z0000001j54AAA","label":"WebSphere Application Server traditional-All Platforms-\u003EDownload Documents - L3 Publishing Category"}],"ARM Case Number":"","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"7.0.0;8.0.0;8.5.5;9.0.5"}]

Problems (APARS) fixed
PH44271, PH39660, PH40343, PH41945, PH42030, PH42862, PH43122, PH43887, PH44393

Document Information

Modified date:
11 April 2022

UID

ibm16560734