Download
Downloadable File
| File link | File size | File description |
|---|---|---|
Abstract
This document provides links to the download page for Content Collector 4.0.1.16 interim fix 7.
Download Description
IBM Content Collector downloads
- All versions
- Version 4.0.1 fix pack 16- selected tab,
Prerequisites
Installation Instructions
Download Package
Readme file:
- 4.0.1.16-IBM-ICC-IF007.pdf
- 4.0.1.16-IBM-ICC-AIX-IF007.gz (for AIX)
- 4.0.1.16-IBM-ICC-Linux32-IF007.tgz (for Linux)
- 4.0.1.16-IBM-ICC-WIN-IF007.zip (for Windows)
How critical is this fix?
This fix covers the security Vulnerabilities Fixes.
The following list displays the known issues that are fixed in interim fix007
This fix includes the fixes listed below security vulnerabilities. Details for each fix are provided in the corresponding sections of this document.
CVE-2026-21925 (CVSS 4.8)
Description
A flaw in the implementation of the javax.rmi.ssl.SslRMIClientSocketFactory API could allow man-in-the-middleattacks when connecting to remote hosts.
The fix ensures that the identity of a remote endpoint is verified correctly when connecting. If necessary this can bedisabled by setting the following new system property to "false":
-Djdk.rmi.ssl.client.enableEndpointIdentification=false
Product Applicability
The fix is applicable to products/applications which use the javax.rmi.ssl.SslRMIClientSocketFactory API.
Note that the Java Runtime's default JMX agent exposes an RMI/SSL server, so JMX clients connecting to such aserver will generally use the vulnerable API.
CVE-2026-21932 (CVSS 7.4)
Description
If the URI passed to java.awt.Desktop.browse() points to an executable file it will be executed directly. Thiscontradicts the specification, which states that the target file will be opened using the default browser.
The fix ensures that the API behaves in accordance with the specification.
Product Applicability
The issue is applicable to products or applications which pass untrusted URIs into the java.awt.Desktop.browse()API. It also affects products or applications that execute untrusted code under a security manager.
This issue is applicable on Windows and Mac OS only.
CVE-2026-21933 (CVSS 6.1)
Description
A flaw in the com.sun.net.httpserver.HttpServer API may facilitate cross-site-scripting (XSS)attacks.
The fix addresses the flaw.
Product Applicability
The issue is applicable to products or applications which use the com.sun.net.httpserver.HttpServer API.
CVE-2026-21945 (CVSS 7.5)
Description
A flaw in the CertPath component allows a malicious TLS client to inflict a server-side request forgery (SSRF) and/ordenial-of-service (DoS) attack by sending a client certificate with a malicious Authority Information Access (AIA)extension value.
The X.509 certificate specification in RFC 5280 does not include any means to validate URIs specified in AIA extensionvalues, and these values must be processed before the client's identity has been verified - i.e. before the client istrusted.
To mitigate this issue, the fix introduces a new security property that can be used to specify which AIA locations arepermitted:
com.sun.security.allowedAIALocations
By default this property specifies no locations, meaning that all AIA URIs will be rejected. The security property can beset directly, or overridden by specifying the list in a system property of the same name. Full documentation can befound in the java.security file, and we will also document the changes in our release notes.
Product Applicability
The issue applies to products or applications which act as TLS servers with client authentication (mTLS) and AuthorityInformation Access (AIA) enabled.
Note that AIA is not enabled by default. It is enabled by setting the system propertycom.sun.security.enableAIAcaIssuers to "true". Deployments in which AIA is enabled will need to specify theURIs that are allowed, using the security/system property mentioned in the description above.
Note:This Interim Fix includes previous fixes(IF001 till IF007)
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
18 August 2026
UID
ibm17269383