Download
Downloadable File
| File link | File size | File description |
|---|---|---|
Abstract
This interim fix addresses security vulnerabilities in Apache Struts (CVE-2026-73635), js-cookie (CVE-2026-46625), immutable (CVE-2026-59879, CVE-2026-59880), and log4j (CVE-2026-49844) in Tivoli Netcool/OMNIbus Web GUI 8.1.0 Fix Pack 41.
Prerequisites
This interim fix requires IBM Tivoli Netcool/OMNIbus Web GUI V8.1.0 Fix Pack 41 to be installed.
Installation Instructions
The included ZIP file contains modified versions of the following files:
$JazzSMHOME/profile/installedApps/${jazzsm.was.cell}/isc.ear/OMNIbusWebGUI.war/ client-assets/ WEB-INF/lib/log4j-api-2.25.5.jar WEB-INF/lib/log4j-core-2.25.5.jar WEB-INF/lib/struts2-core-6.11.0.jar WEB-INF/lib/version.jar
where $JazzSMHOME is the root JazzSM installation directory and ${jazzsm.was.cell} is the cell name (JazzSMNode01Cell).
Steps for installing the fix on a Unix platform:
- Stop the JazzSM server
e.g.$JazzSMHOME/profile/bin/stopServer.sh server1 - Unzip the interim fix file
e.g.unzip WebGUI-81041-InterimFix002.zip - Execute the install_IF script
e.g../install_IF.sh -dash $JazzSMHOME/ui -webgui $WEBGUI_HOME - Start the JazzSM server
e.g.$JazzSMHOME/profile/bin/startServer.sh server1
Note: The original files are backed up to $WEBGUI_HOME/backup/8.1.0.41_IF002 where $WEBGUI_HOME is the root OMNIbus Web GUI installation directory.
Verifying the Interim Fix
- Log onto WebGUI.
- Verify the WebGUI fix pack and interim fix version.
Uninstallation Instructions
- Stop the JazzSM server
e.g.$JazzSMHOME/profile/bin/stopServer.sh server1 - Move to the interim fix backup directory
e.g.cd $WEBGUI_HOME/backup/8.1.0.41_IF002 - Execute the uninstall script
e.g../uninstall_IF.sh -dash $JazzSMHOME/ui -webgui $WEBGUI_HOME - Start the JazzSM server
e.g.$JazzSMHOME/profile/bin/startServer.sh server1
Problems Solved
DT: CSP known issue - Defect Ticket number
WEBGUINOI: Jira issue number
WEBGUINOI-568
......................................................
Short Description: Upgrade Apache Struts from 6.8.0 to 6.11.0 to remediate CVE-2026-73635 (locale-based DoS).
Summary: PSIRT: CVE-2026-73635. Upgrades Apache Struts from version 6.8.0 to 6.11.0 to remediate the reported locale-based Denial of Service security vulnerability.
WEBGUINOI-507
......................................................
Short Description: Fix js-cookie vulnerability for CVE-2026-46625.
Summary: PSIRT: CVE-2026-46625. Upgrades js-cookie to remediate the reported security vulnerability.
WEBGUINOI-533
......................................................
Short Description: Upgrade immutable from 3.8.3 to 4.3.9 to fix CVE-2026-59879 and CVE-2026-59880.
Summary: PSIRT: CVE-2026-59879, CVE-2026-59880. Upgrades immutable.js from version 3.8.3 to 4.3.9 to remediate the reported security vulnerabilities.
WEBGUINOI-536
......................................................
Short Description: Upgrade log4j to 2.25.5 to remediate CVE-2026-49844.
Summary: PSIRT: CVE-2026-49844. Upgrades log4j from version 2.25.4 to 2.25.5 to remediate the reported security vulnerability.
Document Location
Worldwide
Product Synonym
OMNIbus_GUI 8.1.0 FP0041 IF002; OMNIbus_GUI 8.1.0 Fix Pack 41 Interim Fix IF002; OMNIbus_GUI 8.1.0.41.IF2; 8.1.0.41.IF2; Web GUI 8.1.0.41.IF2; Web GUI 8.1.0 FP0041 IF002; Web GUI 8.1.0 Fix Pack 41 Interim Fix IF002
Problems (APARS) fixed
Was this topic helpful?
Document Information
Modified date:
12 September 2026
UID
ibm17287288