IBM Support

Download IBM Content Collector 4.0.1.17 interim fix 1

Download


Abstract

This document provides links to the download page for Content Collector 4.0.1.17 interim fix 1.

Download Description

When you click the download link below, a sign-in page opens. Enter your IBM ID and password to proceed. If you have forgotten your IBM ID or have never registered, follow the instructions on the sign-in page.


 

Prerequisites

The server package of this interim fix requires one of the following versions of Content Collector installed on your operating system:
4.0.1.10, 4.0.1.11, 4.0.1.12, 4.0.1.13, 4.0.1.14, 4.0.1.15, 4.0.1.16, 4.0.1.17
For information about hardware and software compatibility, see the detailed system requirements document at:

[{"PRLabel":"Prerequisites for IBM Content Collector 4.0.1","PRLang":"English","PRSize":"1 B","PRPlat":{"label":"Windows","code":"PF033"},"PRURL":"https://www.ibm.com/support/pages/node/614445"},{"PRLabel":"IBM Software Product Compatibility Reports","PRLang":"English","PRSize":"1 B","PRPlat":{"label":"Windows","code":"PF033"},"PRURL":"https://www.ibm.com/software/reports/compatibility/clarity/index.html"}]

Installation Instructions

For other detailed information regarding features included in the release and installation instructions, refer to the Readme file:4.0.1.17-IBM-ICC-IF001.pdf

Download Package

The fix pack includes all the fixes to date. The download package consists of the following files:

Readme file:

  • 4.0.1.17-IBM-ICC-IF001.pdf
 
Fix files:
  • 4.0.1.17-IBM-ICC-AIX-IF001.gz (for AIX)
  • 4.0.1.17-IBM-ICC-Linux32-IF001.tgz (for Linux)
  • 4.0.1.17-IBM-ICC-WIN-IF001.zip (for Windows)

How critical is this fix?

This fix includes the fixes listed below security vulnerabilities.

CVE-2026-41254 (CVSS 7.5)
Description
A flaw in the Little CMS component may allow an attacker to inflict a denial-of-service via maliciously constructed
ICC profile data. Such data may be embedded in a variety of different types of data, primarily images such as JPEG
/ PNG / TIFF / BMP, but also other types such as PDF.
The fix updates the Little CMS component to address the flaw.
Product Applicability
The issue is applicable to products or applications which process untrusted ICC data, either in the form of standalone
ICC profiles via the java.awt.color.ICC_Profile API, or by parsing data which may contain embedded ICC profiles,
such as JPEG, PNG, TIFF, and BMP, via the javax.imageio APIs.

CVE-2026-47057 (CVSS 7.5)
Description
A flaw in the Nashorn javascript engine used by the javax.script component (in IBM Java 8 and IBM Semeru 11)
may allow an attacker to inflict a DoS via maliciously crafted javascript code.
The fix addresses the flaw.
Product Applicability
The issue is applicable to products or applications which execute untrusted javascript code using the javax.script
APIs.

CVE-2026-47063 (CVSS 7.5)
Description
A flaw in the Cryptographic Message Syntax (CMS) protocol employed in JAR signing may facilitate existential
forgery, i.e. the ability to craft a fake signature which is treated as valid.
The fix addresses the flaw.
Product Applicability
The issue is applicable to products or applications which open signed JARs obtained from untrusted sources.

CVE-2026-47058 (CVSS 7.4)
Description
A flaw in the Nashorn javascript engine used by the javax.script component (in IBM Java 8 and IBM Semeru 11)
may allow an attacker to inflict a DoS via maliciously crafted javascript code.
The fix addresses the flaw.
Product Applicability
The issue is applicable to products or applications which execute untrusted javascript code using the javax.script
APIs.

CVE-2026-60147 (CVSS 6.5)
Description
A flaw in the Security component may lead to certificate "DNSName" exclusion constraints not being enforced
correctly when wildcards are used.
The fix ensures that DNSName constraints are enforced correctly.
Product Applicability
The issue is applicable to products or applications which validate certificate chains (e.g. during TLS handshaking) or
choose certificates directly using the java. security.cert.X509CertSelector API.

CVE-2026-46968 (CVSS 5.9)
Description
A flaw in the JSSE component may allow a client to circumvent client authentication in certain circumstances.
The fix ensures that client certificates are always verified when client authentication is enabled.
Product Applicability
The issue is applicable to products or applications which act as a TLS server with client authentication enabled (i.e.
mTLS).

CVE-2026-47027 (CVSS 5.3)
Description
A flaw in the JAR verifier may allow an attacker to inflict a DoS using a maliciously crafted JAR file.
The fix addresses the flaw.
Product Applicability
The issue is applicable to products or applications which open signed JAR files obtained from untrusted sources.

CVE-2026-47021 (CVSS 5.3)
Description
A flaw in the AWT component may allow an attacker to inflict a DoS using maliciously crafted X Bitmap (XBM)
image data.
The fix addresses the flaw.
Product Applicability
The issue is applicable to products or applications which process untrusted XBM image data using AWT / Swing
image processing APIs such as java.awt.Image, java.awt.image., or javax.swing.ImageIcon.

CVE-2026-47059 (CVSS 3.7)
Description
A flaw in the AWT component may allow an attacker to inflict a DoS using maliciously crafted image data.
The fix addresses the flaw.
Product Applicability
The issue is applicable to products or applications which process untrusted image data using AWT / Swing image
processing APIs such as java.awt.Image, java.awt.image., or javax.swing.ImageIcon.

CVE-2026-47010 (CVSS 3.7)
Description
A flaw in the javax.imageio component may allow a client to inflict a DoS on a server application by providing a
maliciously crafted JPEG image.
The fix addresses the flaw.
Product Applicability
The issue is applicable to products or applications which process untrusted JPEG data using the javax.imageio API
e.g. by calling javax.imageio.ImageIO.read().

CVE-2026-8400 (CVSS 8.1)
Description
A flaw in the IBM ORB's remote Exception handling code may allow a malicious remote IIOP server to induce the
client to load and instantiate an arbitrary class using its no-arg constructor. There is a possibility this could be used
in conjunction with "gadget" classes to facilitate an exploit.
The fix ensures that the Exception handling code will only load and instantiate subclasses of java.lang.Throwable,
and that class deserialization (JEP 290) filters are respected.
Product Applicability
The issue affects products that might use the IBM ORB to connect to an untrusted IIOP server.

CVE-2026-16441 (CVSS 6.9)
Description
A flaw in the OpenJ9 JVM's method resolution logic may allow malicious code to silently execute a class's interface
default methods even when those methods have been declared as abstract in a concrete superclass.
The fix addresses the flaw.
Product Applicability
The issue is applicable to products or applications which run untrusted code under a security manager.

CVE-2026-16439 (CVSS 5.8)
Description
A flaw in the OpenJ9 JVM's Xtrace engine may lead to a buffer underflow, with a NULL being written immediately
before a trace buffer.
The fix addresses the flaw.
Product Applicability
The defect may be exposed by any deployment where Xtrace is used, but active exploitation would require the
product to be running untrusted code under a security manager.

CVE-2026-16243 (CVSS 5.7)
Description
A flaw in the OpenJ9 JIT compiler causes the jdk.internal.util.ArraysSupport.vectorizedMismatch() API to behave
incorrectly if a zero (0) value is passed as a parameter.
The fix addresses the flaw.
Product Applicability
The issue affects product where an attacker could induce a zero (0) value to be passed into the
jdk.internal.util.ArraysSupport.vectorizedMismatch() internal API.
Note: that direct invocation of this internal API is not supported, but this CVE is issued out of caution because it is
possible to invoke it if access to internal APIs has been enabled.
This issue is applicable on Power and Z platforms only - i.e. AIX, z/OS, Linux on Power, and Linux on Z.

VULN-15849 (CVSS 7.0) – Use of End-of-Life (EOL) Dojo Version (High)
Description
The application uses Dojo Toolkit version 1.10.4, a legacy release originally published in 2015 that is no longer
actively maintained by the upstream Dojo project. As an unsupported third-party library, it is considered End-ofLife/obsolete from a security maintenance perspective, since it no longer receives security updates and may leave
known vulnerabilities unpatched.
Fix
The fix updates the Dojo Toolkit component used by the IBM Content Collector for Files, Email & Sharepoint
(ICCFES On-Prem) web application to a currently supported, actively maintained version, remediating this End-ofLife risk 1.17.3 version (identified during penetration testing as Defect ID VULN-15849, CVSS 7.0, CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).
Product Applicability
The issue is applicable to the IBM Content Collector for Files, Email & Sharepoint (ICCFES On-Prem) web
application, which uses the Dojo Toolkit as a front-end JavaScript framework component.

On
[{"DNLabel":"Interim fix","DNDate":"26 Aug 2026","DNLang":"Language Independent","DNSize":"2 GB","DNPlat":{"label":"Windows","code":"PF033"},"DNURL":"https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=Enterprise%2BContent%2BManagement&product=ibm/Information+Management/Content+Collector&release=4.0.1.17&platform=ALL&function=fixId&fixids=4.0.1.17-IBM-ICC-IF001&includeRequisites=1&includeSuperse","DNURL_FTP":"","DDURL":null}]

Document Location

Worldwide

[{"Line of Business":{"code":"LOB76","label":"Data Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSAE9L","label":"Content Collector"},"ARM Category":[{"code":"a8m50000000L1KJAA0","label":"Installation"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"4.0.1"}]

Document Information

Modified date:
25 August 2026

UID

ibm17283450