IBM Support

Fix packs for DataPower Gateway 10.6.0.x

Download


Downloadable File

File linkFile sizeFile description
   
   
   
   
   

Abstract

Lists of fixes in IBM DataPower Gateway 10.6.0.x fix packs.

Download Description

Fix packs and firmware images are located in either Fix Central, Passport Advantage, or the Entitled Registry.

In IBM Knowledge Center you can find information about new and changed features, limitations, and restrictions.

Attention: In the next LTS, you cannot modify the browser URL to access the WebGUI.

Host keys and establishing an SSH session

10.6.0.4 - The DataPower SSH server now supports ECDSA and ED25519 SSH host keys. After you upgrade, ECDSA and ED25519 keys are generated. After the upgrade, The SSH handshake chooses one of these stronger algorithms over RSA. As a result, you might see a receive a warning about the change to the host identification, which is expected due to the key update.

Updated component firmware on HSM-equipped appliances to 2.09-0702

10.6.0.2 updates HSM-equipped appliances to support FIPS 140-3.

  • For HSM-equipped appliances with component firmware 2.09-0702 and later, the following restrictions apply.
    • The key transport algorithm must be rsa-oaep-mgf1p or rsa-oaep.
    • OAEP parameters are unsupported.
    • The OAEP digest algorithm cannot be md5 and ripemd160.
    • For the rsa-oaep key transport algorithm, the OAEP digest algorithm and the MGF algorithm must match.
  • For HSM-equipped appliances with component firmware 2.04-49 and earlier, the key transport algorithm must be rsa-1_5.

Library upgrade to support TLS

10.6.0.0 includes an updated library to support TLS and cryptographic operations. The updated crypto library improves security and usability, but the added complexity of this implementation comes with a performance cost. This update is needed to maintain the proper security posture, which includes CVE updates.

Important



10.6.0.8

Release date: 10 December 2025
Last modified: 10 December 2025
Status: Available

APAR
Description
DT420234DataPower might restart if ITX DPA file cannot be read
DT423135Login failure from one user might cause intermittent errors for other users
DT446795Analytics service remains in DataPower after unassociating in API Manager
DT448180DataPower might restart when using certificate authentication to log in over SSH and using the -n or -t flags.
DT448224DataPower might restart when OpenTelemetry is enabled and an AAA policy runs JWT actions
DT448972New UI: Processing policies with hundreds of rules can fail to load in the editor.
DT449315DataPower might reload when using GatewayScript FS module
DT449434REST or new UI requests for large backups or exports might fail with the max node size exceeded message
DT449619Edit Web Service Proxy with MQV9+ remote gives HTTP 503
DT449835Some SNMP OIDs are missing
DT450554Make GatewayScript engine lightweight
DT450353API call returns 401 error due to deleted API definitions being chosen
DT451049Network error when the remote server is unstable and GWS uses multiple urlopener APIs
DT451647When viewing certificate details, some details might not be displayed
DT451656Cannot access tenant UI after changing the idle timeout for the tenant web management service.
DT451718API gateway stylesheet cache not cleared when user registry is deleted
DT452211DataPower HTTP TLS client might hang if server closes connection during handshake
DT452230Enhance schema validation of operation-switch policy in API YAML
DT454318JWT Validate action does not get the property value correctly for "request.parameters.*"
DT454655DataPower might restart if AMQP broker disconnects unexpectedly.
DT454833DataPower might reload if resource consumption from the strict rate limit cache persists when the domain is being disabled.
DT456571DataPower might restart when an unresponsive gateway peer triggers an invalid TMS response.
DT457308Console log targets can go down after configuration
DT457316Memory growth when using HTTP Bearer security scheme due to missing URL resource and response payload releases
DT457361Duplicate API registries when processing snapshot
DT457446REST requests to the file store do not enforce depth limit if depth=0
DT457536Validate parameters with exclusiveMinimum and exclusiveMaximum
DT457616After modifying extension file, Filestore type gateway extension files disappears
DT457652TypeError during peer enrollment
DT457828Gateway might reload when token management cache provides an invalid or empty response
DT458264Messages might be routed to the wrong queue when an MQ task restarts

10.6.0.7

Release date: 3 October 2025
Last modified: 3 October 2025
Status: Available

APAR
Description
DT419120After change the basic authentication password in APIC Cloud Manager third party oauth provider it is not updated in DataPower
DT419847New UI does not correctly reflect the MQ V9+ GMO setting
DT431976API Connect gateway service does not become operational with too many APIC domains are on same device
DT436301API Connect gateway might restart when new APIs are published while taking traffic
DT437592SFTP fails since firmware upgrade to 10.6
DT440104Improve performance of RMI GET /mgmt/config with state=1
DT440181File names that APIM generates for an API gateway might be too long (> 255)
DT442595DataPower HTTP/2 server might not honor idle timeout
DT442780In new UI, domain status shows probe not enable after it is enabled
DT442897DataPower service variable var://service/mpgw/response-size only works for POST or PUT requests
DT443431In new UI, web service proxy wizard does not display MQ queue manager references
DT443961Temporary file for Debug Probe is not deleted
DT444596UI does not inform user if export was denied due to insufficient permissions
DT444654DataPower might restart if RBM access profile is invalid.
DT446126New UI unable to select Default domain for import when restoring backup.
DT446624Excessive HTTP/2 reset frame rates can cause CPU spin
DT446737DataPower might restart if an XML firewall with a dynamic backend is modified while processing traffic.
DT446757MQMD header's AccountingToken field might have the wrong value
DT446793Missing support to disable parsing form-data parameter
DT447247Corrupt payload to APIGW with Parse Action or DP Service/MPGW with XML processing will reload DataPower
DT447310One down B2B Profile can impact the entire B2B Profile Group.
DT447390DataPower might reload in the low CPU environment
DT447610Missing millisecond and timezone information in DefaultLog property in Probe data
DT447646GatewayScript debugger might restart when using debug-action command
DT447680DataPower upgrade causes missing Internal Scripts and Gateway Peering Sync Failures in APIC Gateway Cluster.
DT447871DataPower might reject LDAP authorization request when pool is full even when reject-on-pool limit is off
DT447961MQ v9+ client does not honor timeout used in the backend MQ URL URL.
DT448113APIs with user registry stop working after DRR
DT448465DataPower might restart from an invalid parameter value in MQ URL
DT448472Gateway peering might not function as expected if the password includes backslashes or whitespace characters.
DT448523DataPower might show linear growth in Gateway peering cache used by the API security token manager resulting in long sync times and throttling of gateway instances consuming too much RAM.
DT449152New UI unable to construct MessageCountMonitor rate limit
DT450624Active sessions of a deleted user do not automatically disconnect.
DT451077Add support for a reference to a non-schema object in an API
DT451360Intermittent landlord reload while doing upgrade/downgrade on tenant
DT451411New UI not showing directories nested more than 7 layers deep
DT451514Failed to SSH into 10.6.0.6 container images
DT451627Secure backups might fail when many configuration checkpoints are present
DT452112MQRC 2142 error occurs when no NameValue is present

10.6.0.6

Release date: 2 July 2025
Last modified: 2 July 2025
Status: Available

APAR
Description
DT418173Automatically recover member catalog snapshot IDs when reading member to peers table
DT421758Secure backup times out due to domain checkpoints
DT422223ebMS2 Ping fails with missing TLS credentials
DT425671DataPower SSH should comply with generalized key type
DT435919DataPower MQ v9+ clients cannot consume messages
DT435974CORS related headers are not included in the invoke response when response is multipart/related Content-Type
DT436904Memory spike or out-of-memory during import from a SOAP request
DT436926Wrong captured parameter value when using grouping constructs in the path parameter's pattern keyword
DT437472Show HSM directory in drop down when HSM license enabled (DataPower 10.5.0.14, 10.6.0.2, 10.6.0.3 and 10.6.04)
DT437888Unexpected sync issue if IP binding in the same interface is used to configure different gateway peering groups
DT438304AAA Custom token AAA info file custom token being improperly updated.
DT438764API gateway might not complete the processing of an invoke policy
DT438921Unable to change expired password using REST management interface
DT439455Reload when urlopen requests span across a domain restart
DT439537DataPower reload when using concurrent GatewayScript urlopen for sending requests to backend
DT439558Debug probe commands does not work for non-admin privileged user
DT439663Two APIs with the same name and different content cause 0x88e00371 error
DT439725Using peer-groups in gateway peering can leak connections
DT439856DataPower reload after using assembly setvar to clear message.attachements array item
DT439857DataPower reload when having customized preflow and enable debug probe
DT439858Datapower Timezone calculation in GatewayScript is different than the DataPower system time
DT439946The modification on DataPower GatewayScript does not take effect
DT439952Gateway might reload while probe data is retrieved with probe-settings disabled
DT439953Gateway peering monitoring process might not work expectedly if password contains special characters
DT440341Api collection missing or incomplete after DataPower restart.
DT440654Temporary filesystem exhausted by MQ error logs like AMQERR
DT442533DataPower might restart from using RMI to fetch probe data
DT442827DataPower might restart from OpenTelemetry if a HTTP header has been removed by XSLT or GWS
DT443387APIC Gateway Service may fail to process catalog snapshots on DRR causing 404 responses
DT443398DataPower might encounter a crash when IBM MQ v9+ handler hits the front timeout of Multi-protocol gateway.
DT443465DataPower tenant requires a restart to increase memory
DT443467DataPower might restart if the MQ handler has a timeout while processing
DT444257DataPower might exhibit high CPU utilization when connections are in CLOSE_WAIT state.
DT444370TLS client profiles might be incorrectly deleted from the API gateway

10.6.0.5

Release date: 30 April 2025
Last modified: 30 April 2025
Status: Available

APAR
Description
DT409134Erroneous error message for the RAID battery
DT419932Cannot close the notification panel when there are no notifications
DT423281GUI might report incorrect error when restarting a domain
DT423400DataPower might experience memory spikes with amp:GetServiceListFromDomainRequest requests. Memory spikes can occur with SOAP dp:get-config requests for nonprivileged users
DT423402REST FetchFile action returns 403 response when the user is authorized
DT423445DataPower might unexpectedly restart when GatewayScript uses bigint
DT424500DataPower might reload when refreshing a large API Connect v5c catalog
DT424778Intermittent TLS error "0A00010F:SSL routines::bad length" in DataPower 10.6.0.3
DT424822In the GUI, importing configuration in the XML format might fail
DT424875DataPower might restart when ITX has an error
DT424936MQ v9+ handler might continuously consume messages when its admin-state is disabled.
DT425672In the GUI, cannot save changes to XML threat protection for an XML firewall
DT425698API Connect TLS client profile not removed from configuration after being detached from the catalog
DT425739File system monitor reports that the 'raid' file system does not exist or is not available
DT425844In the web service proxy wizard, WSRR subscription policy attachments are not displayed on the SLA policy tab
DT425864API Gateway might restart if an invoke policy has a bad URL parameter and OpenTelemetry is used
DT425911Password change causes initiating session to be logged out
DT426022MQ v9+ handler cannot route messages to the specified queue in ObjectName of MQOD.
DT426062Configuration sequence might time out when processing large API Connect snapshots
DT426070API Connect gateway service fails to delete snapshot when an error occurs while processing the snapshot event
DT426460API Connect catalog summary erroneously reports "Cannot write WSDL"
DT426479Improve messages for OAI3 parameter validation
DT433389Monitoring process of the gateway-peering group s not restarted after updating cluster-node list
DT433392IBM MQ v9+ queue manager might stop to retry connections when network conditions are unstable
DT433393Down secondary node is not removed from the secondaries list in gateway-peering cluster status provider
DT433418Gateway-peering process is not restarted while peer-node list is changed in a gateway-peering group
DT433515Priority in the gateway-peering group does not effect the related gateway peering
DT433729In GUI, the labels for the encrypted and temporary space are swapped in file management
DT433755Cannot flush the stylesheet and document caches from an XML manager
DT433829New UI might not populate the date field with the selected date
DT434382GUI fails to load multi-protocol gateway processing rules that are missing their transform files
DT434412Identification credentials are not deleted after being removed from TLS client profile in API Manager
DT435251DataPower might restart when cleaning up MQ connections
DT435281IMS Connect client fails to send data when segmentation is enabled
DT435551In new UI, flushing the document cache in an XML manager is not working as expected
DT435711System might restart after a read timeout on a GatewayScript urlopen.open() call
DT435817Gateway might fail to trigger a 911 to resync catalog data from API Manager when an error occurs on a webhook event.
DT436044Persistent restarts of the API Connect gateway service when the catalog contains thousands of APIs
DT436099DataPower might restart when a TLS profile is modified while it is in use.
DT436579In new UI, export utility cannot select objects that have the same name
DT436845Runtime latency when TLS connection is closed

10.6.0.4

Release date: 28 February 2025
Last modified: 28 February 2025
Status: Available

Known issue
Description
DT416800Log files located in nested directories are not appearing on the System Log page
DT416807IBM MQ v9+ queue manager of DataPower does not retry connection when SSL related errors (2393 and 2381) occur
DT417089Activity log bytes_received and bytes_sent overflow
DT417151JWT Validate policy does not resolve context variables used in the audience claim field
DT417697DataPower might leak memory on XMI ObjectStatus calls
DT418223DataPower might restart with multiple urlopen calls from a single GatewayScript
DT418232API Connect LDAP Password might be exposed in logs with debug logging
DT418611Support multiple business IDs in Ping eBMS Destination Action
DT418613For API Connect Gateway Invoke Assembly the proxy-authorization header is added even when user/password provided in the connection policy are blank
DT419032DataPower might watchdog restart while waiting for a TLS connection shutdown alert
DT419917API parameter must support maxLength and minLength of type string
DT420343Requesting an error report may hang and cause a watchdog reload on next configuration change
DT420373REST Management Interface does not honor field names such as object names using a numerical value that does not begin with 0, expecting only a string
DT420523DataPower might reload when urlopen tries to send data
DT421417DataPower MQ v9+ client creates unbounded FFDC files that cause temporary space depletion
DT422155Update gateway peering for CVE-2024-12224 and CVE-2024-11738
DT422157RMI session not closed when query URI is invalid
DT422168DataPower SNMP response for dpStatusSSHTrustedHostStatusHost is not correct
DT422283API gateway might watchdog when committing OpenTelemetry
DT422448API Gateway duplication in XPath Rules/Fields on 10.6.0.1
DT423068When Autocommit is disabled in a Kafka Cluster, DataPower is unable to consume any messages sent to the cluster service
DT423109Kafka hostname validation behavior not matching with the TLS client profile configuration
DT423126User policies deployed to an API gateway or v5 compatible gateway fail to deploy certificate files
DT423284DataPower syslog-tcp log targets might not clean up all connections
DT423337DataPower might unexpectedly reload in an MQv9+ handler if the back side times out
DT423378DataPower might restart if AMQP broker modified while processing traffic
DT423381API gateway might leak memory when an assembly action output is not sent to message
DT423401IBM MQ v9+ handler fails to process messages with multiple MQRFH2 headers
DT423625DataPower memory increase while retrieving GatewayScript debug sessions
DT423627Error referencing API Schema object with name greater than 255 characters
DT423681DataPower - MQ Connectivity failure, Messages lost despite using unit of work enabled in QM object configuration
DT423951Saving changes via UI to locked Ethernet interface claims to be successful but is not
DT423985MQMD header is intermittently missing resulting in a receive 2033 error
DT424023Fix the memory Leak in Analytics Endpoint when remove or disable the configuration
DT424137RMI sessions not cleaned up after returning a 403 in response to the request for accessing singleton resource in non-default domain
DT424144Gateway might restart if quota-enforcement-server related command is executed after configuration change
DT424492DataPower XMI error log is empty in response
DT424498CVE-2022-40228 - force user logout when password changed
DT424525Context variables of the request body and parameters might be null when accessed by set variable policy
DT424562Display status of WS-Addressing Reply Point on WS-Addressing Tab

10.6.0.3

Release date: 11 December 2024
Last modified: 11 December 2024
Status: Available

APAR
Description
IT46852REST LOADCONFIGURATION WITH NESTED OBJECTS OR ARRAYS MIGHT RESULT IN AN INCORRECT CONFIGURATION
IT46861REMOVE INTERNAL USER SESSIONS FROM THE LIST OF ACTIVE USERS
IT47054WEB SERVICE PROXY WIZARD DISPLAYS (NONE) FOR ALL PROCESSING RULES WHEN NOT USING THE DEFAULT POLICY
IT47059IN NEW GUI, EDITING A FILE IN NESTED DIRECTORY ON AN OBJECT PAGE CAN RETURN AN ERROR
IT47116AUTOMATIC DRR SHOULD RESULT IN THE SAME CONFIGURATION AS A MANUAL DRR
IT47124IN POLICY EDITOR, STYLESHEET PARAMETERS WITHOUT A TYPE DO NOT DISPLAY
IT47158GATEWAY PEERING MONITOR DOES NOT STOP WHEN DOMAIN IS DISABLED OR QUIESCED
IT47183APIC V5C UDP MIGHT THROW UNEXPECTED ERROR FOR A KEY IN THE CONFIGURATION TO IMPORT
IT47184UPDATE DATAPOWER REDIS LIBRARY TO ADDRESS CVES - CVE-2024-31449 & CVE-2024-31228
IT47185GATEWAY MIGHT RESTART IF GATEWAY PEERING IS DOWN DUE TO THE REFERENCED PEERING GROUP BEING DOWN.
IT47186REMOVING GATEWAY-PEERING PRODUCT LINKS CAN RESULT IN UNEXPECTED BEHAVIOR
IT47187API CONNECT GATEWAY EXTENSION CANNOT COMPLETE IF A PREVIOUS EXTENSION CONTAINED AN INVALID EXTENSION
IT47190RATE LIMIT STATUS PROVIDER NOT RESET CORRECTLY
IT47191REPEATEDLY CREATING AND DELETING APIC CATALOGS FROM A SCRIPT CAN CAUSE AN ERROR
IT47193APIC GRAPHIQL EDITOR DOES NOT UNDERSTAND NEW OPTIONS
IT47227APIC V5C UDP POLICY DELETE MIGHT LEAVE ORPHANED OBJECTS
IT47228B2B GATEWAY MIGHT RESTART WHEN AN ERROR OCCURS IN A ONE-WAY PULL TO AN INBOUND GATEWAY
IT47240API GATEWAY INCORRECTLY REJECTS INTEGERS WITH EXPONENTS AS INCORRECT PARAMETERS
IT47242API GATEWAY INCORRECTLY REJECTS FLOATING POINT NUMBER WITH EXPONENT AS INCORRECT PARAMETER
IT47257APIC PARAMETER VALIDATION ERROR SHOULD RETURN HTTP 400 RESPONSE CODE
IT47258OUTBOUND SNI SETTINGS FOR A DATAPOWER MQ CLIENT MIGHT NOT BE APPLIED AFTER THE CONFIGURATION CHANGE
IT47304DATAPOWER MIGHT RESTART WHEN ADDING A GATEWAY-PEERING INSTANCE TO A GATEWAY-PEERING GROUP
IT47386DATAPOWER GATEWAY MIGHT HANG AND RESTART WHEN PROCESSING HIGH RATES OF HTTP/2 TRAFFIC
IT47394HIGH SEVERITY VULNERABILITY IN MQ (CVE-2024-25016)
IT47395ADDRESS FALSE POSITIVE RESULTS FROM VULNERABILITY SCAN

10.6.0.2

Release date: 30 October 2024
Last modified: 30 October 2024
Status: Available

APAR
Description
IT45888DATAPOWER MIGHT WATCHDOG RELOAD DURING THE PROCESSING OF A SAVE INTERNAL-STATE COMMAND.
IT46468HTTP/2 SHOULD WORK WITH TLS 1.2 AND TLS 1.3 OR WITH ONLY TLS 1.3
IT46594PING EBMS DESTINATION ACTION IS MISSING IN THE NEW UI
IT46627DATAPOWER MIGHT RESTART AFTER A STATIC ROUTE IS ADDED
IT46633DATAPOWER MIGHT RESTART WHEN ASYNCHRONOUS GATEWAYSCRIPT WRITES TO OUTPUT AFTER THE CONNECTION IS CLOSED
IT46665THE PROBE OF INTERNAL RULES/ACTIONS SHOULD NOT BE COLLECTED
IT46718UPDATE SERVER SUBSCRIPTION WHEN ORG AND CAT NAME CHANGE IN AN API COLLECTION
IT46756PREVENT AUTOFILLED PASSWORD FIELD FROM BEING USED TO DISPLAY CERTIFICATE DETAILS
IT46760FOR OAUTH PROVIDER, REQUEST BODY PARAMETERS MIGHT NOT BE REDACTED BEFORE THEY ARE SENT TO THE ANALYTICS ENDPOINT
IT46764THE AAA CONFIGURATION EDIT SEEMS TO BE WORKING INCORRECTLY IN THE NEW DATAPOWER UI
IT46836DATAPOWER RELOAD OCCURS WHEN ATTEMPTING TO PROCESS AN EMPTY OAUTH TOKEN
IT46867APIC GATEWAY SERVICE ERROR SHOULD TRIGGER CATALOG REFRESH
IT46868UI DOES NOT SHOW NEWLY UPLOADED FILE IN APPLICATION DOMAIN
IT46869SPECIAL CHARACTERS NOT RECOGNIZED IN LDAP XSL CONFIGURATION
IT46870TIMEOUT IS NOT CONSIDERED IN AN SOAP TCPCONNECTIONTEST REQUEST.
IT46875CATALOG UPDATES THAT FAIL TO COMPLETE SUCCESSFULLY MIGHT STILL RETURN OK RESPONSE
IT46891WHEN UNITS-OF-WORK IS ENABLED, THE TRANSACTION CANNOT COMPLETE IF THE REPLY2QM IN MQMD IS NOT FOUND
IT46896FROM AN OBJECT CONFIGURATION, THE SHOW COMMAND WITH AN EXTRA SPACE CAUSES A RESTART
IT46897GATEWAY MIGHT RESTART WHEN MODIFYING GATEWAY PEERING OBJECT TO CHANGE LOCAL ADDRESS
IT46898GATEWAY MIGHT RESTART WHEN RUNNING GATEWAYSCRIPT DURING REPUBLISH
IT46899DATAPOWER MQV9 CONNECTION ERROR REASON CODE 2393
IT46905WSP POLICY RULES NOT SHOWN FOR AN OPERATION IN NEW UI
IT46918USE OF ELEMENTS WITH THE SAME LOCAL-NAME() RESULT IN FAILURE WITH WSDL FILES THAT ARE SET FOR STRICT CONFORMITY.
IT46946GATEWAY SERVICE MIGHT FAIL TO PROCESS CHANGES FOR A CATALOG THAT CONTAINS OAUTH CONFIGURATIONS.
IT46962OVA DATAPOWER PLATFORM DOES NOT ALLOW NTP TO BE SET BY OVF-ENV.XML
IT46973Upgrading can cause XSLT to fail, DataPower cannot handle valid use of @xsi:nil
IT46984RATE LIMIT HEADERS FOR ASSEMBLY COUNT LIMITS ARE MISSING FOR API REQUEST
IT46992SNI MAPPING DOES NOT UPDATE WITH NEW CERTIFICATE
IT46998API COLLECTION WITH % IN ORGANIZATION NAME OR ID MIGHT CAUSE GATEWAY RESTART
IT47001APIC GATEWAY MIGHT RESTART IF OAUTH REFRESH TOKEN IS MISSING REQUIRED ELEMENTS
IT47005APIC PARSES MIME BOUNDARY STRINGS INCORRECTLY
IT47006UNCAUGHT EXCEPTION IN API CONNECT GATEWAY SERVICE WHEN THERE IS NO DATA IN GATEWAY PEERING DATABASE FOR A CATALOG
IT47007API MANAGER REGISTRY UPDATE SHOULD CLEAR XSLT CACHE FOR NEW/UPDATED FILES
IT47021MEDIUM SEVERITY VULNERABILITY IN NSS (CVE-2023-6135)
IT47117API GATEWAY MIGHT NOT GET ITS FULL CONFIGURATION AFTER A RESTART
IT47122UPDATE KERNEL TO ADDRESS SEVERAL FALSE POSITIVE VULNERABILITIES
IT47123DATAPOWER MQ CLIENT REPORTS MESSAGE CODE 0X8D200052 "THE (XYZ) REQUEST FAILED (2500)"
IT47127UPDATE XML LIBRARY TO ADDRESS CVE-2024-25062
IT47128MEDIUM SEVERITY VULNERABILITIES IN KERNEL - CVE-2023-52340 & CVE-2023-25775
IT47143HIGH SEVERITY VULNERABILITY IN NODE - CVE-2024-45590 & CVE-2024-45296
IT47144HIGH SEVERITY VULNERABILITY IN DPOS - CVE-2024-2961
IT47145MEDIUM SEVERITY VULNERABILITY IN KERNEL - CVE-2024-22365
IT47226NETWORK DENIAL OF SERVICE IN OS KERNEL - CVE-2023-52881

10.6.0.1

Release date: 28 August 2024
Last modified: 28 August 2024
Status: Available

APAR
Description
IT44550DATAPOWER LOGS ERROR READING FROM CONNECTION: SYSTEM ERROR (110)
IT44570AMQP HANDLER STUCK IN PENDING STATE AFTER APPLYING CONFIGURATION CHANGES.
IT44571WHILE LOADING, AMQP HANDLER STOPS PULLING MESSAGES.
IT44865MODIFYING THE RETRY INTERVAL OR THE COMMENT FIELD OF THE AMQP BROKER CAN CAUSE THE OBJECT TO GO DOWN IN THE PENDING STATE.
IT44904DATAPOWER MIGHT RELOAD WHEN THE AMQP CONNECTION FOR THE AMQP URLOPENER IS BROKEN DUE TO NETWORK ERRORS
IT45143LOG TARGET TRIGGER MIGHT HANG DURING A COPY OR MOVE OPERATION AGAINST AN EXTERNAL SERVER
IT45289DATAPOWER VULNERABILITY FOR ERROR MESSAGE VERBOSITY
IT45380SECURE BACKUP TIMES OUT AFTER UPGRADE
IT45389API CONNECT GATEWAY EXTENSIONS MIGHT CAUSE HIGH MEMORY USE.
IT45793TLS BAD LENGTH ERROR WHEN USING TLS VERSION 1.3 AND SESSION CACHING.
IT45832DATAPOWER MIGHT RELOAD WHEN USING SELECT=XSL:NIL FOR AN XSLT TEMPLATE PARAMETER.
IT45849DATAPOWER DOES NOT ALLOW THE SETTING OF A CUSTOM TLS PROFILE FOR WSDL RETRIEVAL.
IT45999LOGS FOR THROTTLER USAGE CONTAIN AN INCORRECT VALUE FOR TOTAL TEMPORARY SPACE.
IT46069ADD XSLT EXTENSION FUNCTION APIM:GETREGISTRY TO THE API GATEWAY XSLT COMPATIBILITY MODULE
IT46140IN NEW UI, CERTIFICATE DETAILS IS MISSING
IT46150SUPPRESS HTTP/2 HOST HEADER IN REQUEST
IT46160NEW PROBE SHOWS INCORRECT OUTPUT IN XML FORMAT.
IT46184AFTER UPGRADE, PREVIOUS VERSION OF ILMT SWIDTAGS MIGHT PERSIST AND BE INCLUDED IN SCAN REPORTS
IT46214API CONNECT GATEWAY SHOULD ALLOW CASE-INSENSITIVE WSDL QUERY PARAMETER FOR WSDL RETRIEVAL
IT46248API MANAGER DOES DETECT SEMANTIC SWAGGER ERRORS IN THE API THAT THE GATEWAY DETECTS.
IT46253DATAPOWER RETURNS INCORRECT TIME REPRESENTATION.
IT46255DATAPOWER UI AND REST MANAGEMENT REQUESTS DO NOT RETURN WARNINGS FOR FIRMWARE UPDATE ACTION.
IT46260DATAPOWER UI DOES NOT DISPLAY LOGS THAT ARE NOT WRITTEN TO THE LOGTEMP: DIRECTORY.
IT46269THE DEFAULT RECURSION LIMIT FOR REGULAR EXPRESSION CAUSES STACK OVERFLOW IN DATAPOWER.
IT46273DATAPOWER MQV9+ CONFIGURATION FOR WS ENDPOINT REWRITE POLICY IS LOST ON SHUTDOWN OR RESTART
IT46278APIC ERROR WHEN USING WSDLS WITH A DEFAULT XML NAMESPACE
IT46279OPEN OBJECT LIST LOG LINKS IN NEW TAB
IT46299WRONG STATUS CODE IN ACTIVITY LOG WITH ENABLED FORCEHTTP500FORSOAP11 TOGGLE
IT46315API GATEWAY CANNOT COME UP AFTER DRR DUE TO PORT BIND ERROR
IT46326IN NEW UI, CANNOT ENABLE OR DISABLE MEMBERS IN A LOAD BALANCER GROUP
IT46335THE ADD WSDL INPUT FIELD FOR THE WSDL FILE URL CANNOT HANDLE URLS PROPERLY.
IT46340IN NEW UI, EXPORT ACTION DOES NOT EXPORT ALL DOMAINS
IT46345IN NEW UI, PROBE SCREEN STUTTERS WHEN SCROLLING THROUGH THE TRANSACTION LIST
IT46347TCP PORT STATUS FILTER RESETS WHEN SCROLLING THROUGH RESULTS
IT46355PARSED OBJECTS DOES NOT SERIALIZED TO THE BACKEND IF PROBE ENABLED
IT46376WHEN NBLEAK IS ACTIVE, DATAPOWER MIGHT RESTART DURING AN OAUTH AUTHORIZATION CALL
IT46385IN NEW UI, THE UNDO OPERATION FOR COMPARE CONFIGURATION MIGHT FAIL
IT46407DATAPOWER MIGHT RELOAD WHILE PROCESSING AN XSLT
IT46418FOR API GATEWAY, API QUERY PARAMETER PROCESSES INCORRECTLY WHEN THE QUERY NAME IS ENCODED IN THE URL
IT46426MQV9+ HANDLER STOPS RETRIEVING MESSAGES FROM QUEUE
IT46438REQUEST OR RESPONSE TYPE SOAP SERVICE CANNOT CORRECTLY PROCESS JSV VALIDATE ACTION IN RULE.
IT46454WHEN A HEADER IS GREATER THAN 16 KB, SERVICE MIGHT THROW AN ERROR FOR A TLS HTTP/1.1 REQUEST
IT46479DATAPOWER MIGHT LOAD DURING GARBAGE COLLECTION OF JSON KEYS
IT46480IN OCP ENVIRONMENT THAT USE LOAD BALANCING FOR ROUTES, UI USAGE MIGHT FAIL
IT46484WHEN REPLY-TO-Q IS SET TO EMPTY, MQV9+ HANDLER TRIES TO OPEN THE QUEUE
IT46493DO NOT ALLOW UI TO RESET DEFAULT DOMAIN
IT46494NOT ALL MEMORY RECOVERED WHEN USING PROBE
IT46495ZE IT43340 FIX APAR - PLAN.SPACEID IS NOT AVAILABLE IN THE V5C CONTEXT
IT46512DATAPOWER MIGHT RELOAD WHEN A NEW CONNECTION IS CREATED IN THE FAP CONNECTION POOL
IT46513MEMORY LEAK WHEN USING APIGW:SET-VARIABLE EXTENSION FUNCTION IN XSLT OR GATEWAY SCRIPT
IT46531APIGW V10 APIM MODULE COMPATIBILITY ISSUE WITH APIM.GETVARIABLE(REQUEST.BODY.SOMEPROPERTY)
IT46595UI DOES NOT DISPLAY TEXT WHEN FONT DOWNLOADS FAIL
IT46612PROBLEM PARSING MIME DATA MIGHT CAUSE PART OF PAYLOAD TO BE SKIPPED IN API CONNECT API CALL
IT46639DATAPOWER XML FIREWALL PROBE CAPTURE MIGHT RESTART WHEN FILTERING BY PATH
IT46644API CONNECT GATEWAY ON TENANTS MIGHT NOT START DUE TO NTP SERVICE
IT46662DATAPOWER EBMS3 MIGHT USE WRONG DESTINATION ENCRYPTION SETTINGS IN B2B EXTERNAL PARTNER PROFILE
IT46663DATAPOWER B2B GATEWAY SHOULD TREAT AS4 MESSAGE AS BINARY IF NO PARTINFO MIMETYPE IS FOUND
IT46664UI FILE MANAGEMENT CANNOT COPY FILES TO NEWLY CREATED DIRECTORY
IT46666RATE LIMIT REMAINING MIGHT BE UNSYNCED AFTER GETTING EVICTED EVENT.
IT46667DEPLOYING LARGE GATEWAY EXTENSION MIGHT CAUSE LONG DEPLOYMENT DURATION.
IT46678HIGH SEVERITY VULNERABILITY IN GLIBC
IT46680CLIENT KEY FAILED TO BE UPDATED WITH SPECIAL CHARACTER IN KEY
IT46681UNEXPECTED REMAINING IN LOCAL WHEN USING IPV6 ADDRESSES FOR RATE LIMIT GATEWAY PEERING IN CLUSTER MODE
IT46682IN NEW UI, AUDIT RECORDS REPORT INCONSISTENT INTERFACE TYPE
IT46684GATEWAY-PEERING GROUP CANNOT BE DELETED WHEN THE DOMAIN IS DELETED
IT46685INTERMITTENT CRASH OCCURS WITH GATEWAY PEERING STATUS
IT46686POTENTIAL DATA TRUNCATION AND DOS VULNERABILITY IN KERBEROS
IT46687MEDIUM SEVERITY VULNERABILITIES IN KERNEL
IT46688MEDIUM SEVERITY VULNERABILITY IN GO (CVE-2024-24789)
IT46689HIGH SEVERITY VULNERABILITY IN NODE.JS (CVE-2024-22020)
IT46692UPDATE NODEJS LIBRARY TO ADDRESS CVE-2024-4067
IT46693UPDATE PYTHON LIBRARY TO ADDRESS CVE-2023-27043
IT46694UPDATE OPENSSH LIBRARY TO ADDRESS CVE-2024-6387
IT46695ADDRESS MEMORY LEAK IN FORM DATA
IT46696SIGNATURE PAYLOAD STORED AS BINARY
IT46697HIGH SEVERITY VULNERABILITY IN NODE.JS BRACES MODULE (CVE-2024-406)
IT46698ENHANCE THE LOGIC OF MULTIPLE API CANDIDATES SCENARIO IN API ROUTING
IT46700UNABLE TO OVERRIDE OAUTH-PROVIDER WHEN DEPLOY SET TO IMMEDIATE
IT46701GWD ABILITY TO RECOVER WHEN RESTARTING DURING THE DEPLOYMENT OF LARGE EXTENSIONS
IT46708DATAPOWER MIGHT HANG OR RESTART WHEN PROCESSING 10 GB OR LARGER DATA
IT46715UI HANGS WHEN TRYING TO ACCESS WSP CONFIGURED WITH EMBEDDED POLICIES
IT46716WEB SERVICE PROXY DOES NOT WORK WELL WITH GITOPS
IT46717IN NEW UI, DOMAIN BACKUP-RESTORE OR EXPORT ACTIONS CAUSES CLI SESSIONS TO FREEZE
IT46719PROBE SETTINGS UPDATED BY THE COMMIT OF THE GATEWAY PEERING MANAGER
IT46731ADDING GATEWAY SERVICE TO A CATALOG RESPONDS WITH A 504 TIMEOUT
IT46732API GATEWAY JSONATA EXPRESSION CAN NOW COERCE RESULTS INTO AN ARRAY
IT46740PROCESSING OF CLOUD SNAPSHOT BY DATAPOWER (APIC-GW-SERVICE) MIGHT NOT BE REFLECTED IN CLOUD MANAGEMENT CONSOLE
IT46747DATAPOWER MIGHT RELOAD WHEN GATEWAY PEERING USES A PEER GROUP AND PEERS HAVE DIFFERENT LENGTHS OF IP ADDRESSES
IT46906API GATEWAY RESTARTS WHEN CLIENT SECURITY POLICY USES EXTRACT CREDENTIAL METHOD FROM HTTP

10.6.0.0

Release date: 13 June 2024
Last modified: 13 June 2024
Status: Available

APAR
Description
IT44550DATAPOWER LOGS ERROR READING FROM CONNECTION: SYSTEM ERROR (110)
IT45245DATAPOWER MIGHT RESTART WHEN MONITORING GATEWAYSCRIPT FILES FOR UPDATES
IT45515API GATEWAY REJECTS CALLS WHEN A HEADER NAME STARTS WITH '-'.
IT45786DATAPOWER SHOULD NOT ALLOW DUPLICATE ENTRIES UNDER SFTP CLIENT POLICIES FOR USER AGENT
IT45833MEDIUM SEVERITY VULNERABILITIES IN GOLANG
IT45855MQV9+ OR MQMFT MIGHT NOT RETRIEVE MESSAGES WHILE UNITS-OF-WORK IS ENABLED
IT45966API GATEWAY API WITH LONGEST BASE PATH IS NOT ROUTED WHEN THERE ARE MULTIPLE CANDIDATES.
IT45973INCORRECT VALUE OF $(API.OPERATION.PATH) WHEN PATTERN KEYWORD IS SPECIFIED IN THE PATH PARAMETER.
IT46008CSS BANNER NOT DISPLAYED IN NEW UI.
IT46030COMPATIBILITY ISSUE OF OBJECT.PROTOTYPE.TOSTRING AFTER UPGRADE.
IT46043CANNOT CONVERT API YAML OF FORCEHTTP500FORSOAP11 TO DATAPOWER CONFIGURATION.
IT46052REMOVE THE ANGULAR.JS LIBRARY.
IT46054CORRUPTED BINARY ATTACHMENTS IN MULTIPART HANDLING.
IT46061DATAPOWER MIGHT RESTART WHEN PREPARING FOR USER ACTIVITY SUCH AS IMPORT, EXPORT, AND SO FORTH.
IT46062APIM.SETVARIABLE OF MESSAGE.STATUS.CODE NEEDS TO SET THE REASON PHRASE WHEN INCLUDED.
IT46070API GATEWAY LOGS MIGHT CONTAIN SPECIAL CHARACTERS FOR THE SPACE NAME.
IT46079THE QUERY PARAMETER VALIDATION DOES NOT SUPPORT THE URL-ENCODED FORMAT.
IT46081ADDRESS FALSE POSITIVE FINDINGS IN VULNERABILITY SCANS.
IT46096WRONG API PARAMETER TYPE WHEN THE FORMAT IS BYTE, BINARY, DATE, DATE-TIME, OR PASSWORD.
IT46101DATAPOWER B2B EBMS3 SOAP 1.2 MESSAGES INCORRECTLY SET THE MUSTUNDERSTAND ATTRIBUTE.
IT46105UPDATE NODEJS LIBRARY TO ADDRESS CVE-2024-27982
IT46108API WITH CONSUME DECLARATION DOES NOT HAVE A HIGHER PRIORITY.
IT46116MIGRATED V5 POST RESPONSE EXTENSION CORRUPTS CLIENT RESPONSE
IT46117GATEWAYSCRIPT MIGHT NOT THROW AN ERROR WHEN THE BUFFER OBJECT IS ACCESSED OUT OF BOUND.
IT46118THE API GATEWAY MIGHT RESTART WHEN SENDING A MULTIPART MESSAGE WITH AN INVALID INVOKE URL IN THE INVOKE ASSEMBLY ACTION.
IT46119API SUBSCRIPTION SERVICES WITH SAME BASE PATH AND OPERATION RETURN THE WRONG RESPONSE.
IT46131API RATE LIMIT STATUS DOES NOT RETURN DATA FROM SECONDARY GATEWAY-PEERING INSTANCES.
IT46132DATAPOWER FOR LINUX, SECURE RESTORE DOES NOT RESET THE PASSWORD FOR THE ADMIN ACCOUNT.
IT46135TEMPORARY FILES THAT GATEWAYSCRIPT GENERATE DO NOT HONOR THE TTL IF A RELOAD HAPPENS BEFORE TTL IS REACHED.
IT46145DATAPOWER FOR VMWARE, NEW UI DOES NOT DISPLAY ALL RAID ARRAY ACTIONS.
IT46146REST API RETURNS NUMBER VALUES FOR THE NAME INSTEAD OF A STRING VALUE.
IT46156DATAPOWER MQ CLIENT MIGHT GET UNEXPECTED CONNECTION ERRORS
IT46167UNEXPECTED 404 RESPONSE FOR AN API PATH WITH MANY SPECIAL CHARACTERS.
IT46196PROBE CANNOT CAPTURE TRANSACTIONS AFTER THE PROBE CAPTURE IS DELETED AND RE-CREATED.
IT46197DATAPOWER MIGHT RESTART AFTER UPDATING OBJECTS IN CONFIGURATION SEQUENCES.
IT46255DATAPOWER UI AND REST MANAGEMENT REQUESTS DO NOT RETURN WARNINGS FOR FIRMWARE UPDATE ACTION.
IT46261GATEWAY PEERING GROUP MIGHT BE OPERATIONAL UP WHILE INVALID LOCAL NODE IS DEFINED FOR CLUSTER MODE.
IT46271AFTER AN IRREGULAR RESTART, THE DATAPOWER APPLIANCE HAS OLD VERSIONS OF OBJECTS.
IT46274UPDATE KERNEL TO ADDRESS CVE-2023-4016.
IT46276UPDATE KERNEL TO ADDRESS MULTIPLE CVES.
IT46277UPDATE KERNEL TO ADDRESS CVE-2023-38403.
IT46284DATAPOWER MIGHT RESTART AFTER DISABLING OR DELETING A GATEWAY-PEERING CLUSTER NODE.
IT46285API CONNECT GATEWAY SERVICE MIGHT RESTART WHEN /GATEWAY-SERVICE-CONFIGURATION-DELETE IS INVOKED WITH NO BODY.
IT46286INCORRECT COUNT OF CAPTURED TRANSACTIONS IN THE NEW PROBE.
IT46292ITX TAG MISSING FROM ILMT-SCAN IN ALL RELEASES
IT46293MEMORY LEAK ON QUERYING SUBSCRIPTION WITH PATTERN
IT46294CLEAN UP REFERENCE TO REMOVED CATALOG
IT46301MEMORY LEAK TO ROUTE AN API CONNECT API WITH QUERY, HEADER, OR FORM PARAMETERS.
IT46324ENABLING TLS ON GATEWAY PEERING GROUP MIGHT HANG GATEWAY
IT46448CRITICAL SEVERITY VULNERABILITY IN OPENSSL (CVE-2024-4741)
IT46457LOW SEVERITY VULNERABILITY IN OPENSSL (CVE-2024-4603)
IT46602LOW SEVERITY VULNERABILITY IN OPEN-VM-TOOLS (CVE-2023-20867)
IT46621RMI REQUESTS SHOULD BE REPORTED IN ACTIVE USERS STATUS PROVIDER
IT46823HIGH SECURITY VULNERABILITY IN KERNEL

Change history
Last modified: 10 December 2025

  • 10 December 2025: Added fix list for the 10.6.0.8 fix pack.
  • 3 October 2025: Added fix list for the 10.6.0.7 fix pack.
  • 2 July 2025: Added fix list for the 10.6.0.6 fix pack.
  • 30 April 2025: Added fix list for the 10.6.0.5 fix pack.
  • 28 February 2025: Added fix list for the 10.6.0.4 fix pack.
  • 11 December 2024: Added fix list for the 10.6.0.3 fix pack.
  • 30 October 2024: Added fix list for the 10.6.0.2 fix pack.
  • 28 August 2024: Added fix list for the 10.6.0.1 fix pack.
  • 13 June 2024: Added fix list for the 10.6.0.0 fix pack.

Off

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateway"},"ARM Category":[{"code":"a8m50000000L0rqAAC","label":"DataPower"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"10.6.0"}]

Problems (APARS) fixed
IT44550; IT45245; IT45786; IT45833; IT45855; IT45966; IT45973; IT46008; IT46030; IT46043; IT46052; IT46054; IT46061; IT46062; IT46070; IT46079; IT46081; IT46096; IT46101; IT46105; IT46108; IT46116; IT46117; IT46118; IT46119; IT46131; IT46132; IT46135; IT46145; IT46146; IT46156; IT46167; IT46196; IT46197; IT46255; IT46261; IT46271; IT46274; IT46276; IT46277; IT46284; IT46285; IT46286; IT46292; IT46293; IT46294; IT46301; IT46324; IT46448; IT46457; IT46602; IT45515; IT44550; IT44570; IT44571; IT44865; IT44904; IT45143; IT45289; IT45380; IT45389; IT45793; IT45832; IT45849; IT45999; IT46069; IT46140; IT46150; IT46160; IT46184; IT46214; IT46248; IT46253; IT46255; IT46260; IT46269; IT46273; IT46278; IT46279; IT46299; IT46315; IT46326; IT46335; IT46340; IT46345; IT46347; IT46355; IT46376; IT46385; IT46407; IT46418; IT46426; IT46438; IT46454; IT46479; IT46480; IT46484; IT46493; IT46494; IT46495; IT46512; IT46513; IT46531; IT46595; IT46612; IT46639; IT46644; IT46662; IT46663; IT46664; IT46666; IT46667; IT46678; IT46680; IT46681; IT46682; IT46684; IT46685; IT46686; IT46687; IT46688; IT46689; IT46692; IT46693; IT46694; IT46695; IT46696; IT46697; IT46698; IT46700; IT46701; IT46708; IT46715; IT46716; IT46717; IT46719; IT46731; IT46732; IT46740; IT46747; IT46823; IT46906; IT46621; IT45888; IT46468; IT46594; IT46627; IT46633; IT46665; IT46718; IT46756; IT46760; IT46764; IT46836; IT46867; IT46868; IT46869; IT46870; IT46875; IT46891; IT46896; IT46897; IT46898; IT46899; IT46905; IT46918; IT46946; IT46962; IT46973; IT46984; IT46992; IT46998; IT47001; IT47005; IT47006; IT47007; IT47021; IT47117; IT47122; IT47123; IT47127; IT47128; IT47143; IT47144; IT47145; IT47226; IT46852; IT46861; IT47054; IT47059; IT47116; IT47124; IT47158; IT47183; IT47184; IT47185; IT47186; IT47187; IT47190; IT47191; IT47193; IT47227; IT47228; IT47240; IT47242; IT47257; IT47258; IT47304; IT47386; IT47394; IT47395; DT416800; DT416807; DT417089; DT417151; DT417697; DT418223; DT418232; DT418611; DT418613; DT419032; DT419917; DT420343; DT420373; DT420523; DT421417; DT422155; DT422157; DT422168; DT422283; DT422448; DT423068; DT423109; DT423126; DT423284; DT423337; DT423378; DT423381; DT423401; DT423625; DT423627; DT423681; DT423951; DT423985; DT424023; DT424137; DT424144; DT424492; DT424498; DT424525; DT424562; DT409134; DT419932; DT423281; DT423400; DT423402; DT423445; DT424500; DT424778; DT424822; DT424875; DT424936; DT425672; DT425698; DT425739; DT425844; DT425864; DT425911; DT426022; DT426062; DT426070; DT426460; DT426479; DT433389; DT433392; DT433393; DT433418; DT433515; DT433729; DT433755; DT433829; DT434382; DT434412; DT435251; DT435281; DT435551; DT435711; DT435817; DT436044; DT436099; DT436579; DT436845; DT418173; DT418173; DT421758; DT422223; DT425671; DT435919; DT435974; DT436904; DT436926; DT437472; DT437888; DT438304; DT438764; DT439455; DT439537; DT439558; DT439663; DT439725; DT439856; DT439857; DT439858; DT439946; DT439952; DT439953; DT440341; DT440654; DT442533; DT442827; DT443387; DT443398; DT443465; DT443467; DT444257; DT444370; DT438921; DT419120; DT419847; DT431976; DT436301; DT437592; DT440104; DT440181; DT442595; DT442780; DT442897; DT443431; DT443961; DT444596; DT444654; DT446126; DT446624; DT446737; DT446757; DT446793; DT447247; DT447310; DT447390; DT447610; DT447646; DT447680; DT447871; DT447961; DT448113; DT448465; DT448472; DT448523; DT449152; DT450624; DT451077; DT451360; DT451411; DT451514; DT451627; DT452112; DT420234; DT423135; DT446795; DT448180; DT448224; DT448972; DT449315; DT449434; DT449619; DT449835; DT450554; DT451049; DT451647; DT451656; DT451718; DT452211; DT452230; DT454318; DT454655; DT454833; DT456571; DT457308; DT457316; DT457361; DT457446; DT457536; DT457616; DT457652; DT457828; DT450353; DT458264;

Document Information

Modified date:
05 January 2026

UID

ibm17156692