Fix Readme
Abstract
Urgent and APAR information for IBM Security Access Manager 9.0.7.2 IF4.
Please read all urgent information in this document before performing any actions.
Content
Urgent information:
- Please ensure you have APAR IJ24066 installed, otherwise all snapshots created before the APAR is installed will not be able to be restored to the system.
- Take a snapshot and download to a local file system
- Crashes
- Defects
- Memory leaks
- Performance improvements
- Security vulnerabilities
RSA SecurID authentication mechanism.
Note:
The minimum RSA Authentication Manager version supported is 8.2 SP1
- Identify all business case scenarios used
- Testing all business use cases in test and QA environments, identical to production if possible
- Performance testing of all business use cases in identical production environment
________________________________________________________________________
IBM My Notifications
IBM strongly recommends you subscribe to My Notifications. You will be able to receive the latest urgent information of this document and feedback of IBM Products.
You find more information about My Notifications here IBM My Notifications
________________________________________________________________________
APARS fixed in ISAM 9.0.7.2 IF4
|
APAR |
Description |
| IJ35975* | ISAM 9.0.7.1 IF5 APPLIANCE CANNOT CREATE A VALID SNAPSHOT |
| IJ36046 | REQUEST LOG TIME ZONE OFFSET CHANGE DELAYED AFTER DST CHANGE |
| IJ35615 | DPWWA0636E ERROR DUE TO INCORRECT DST CONVERSION |
| IJ38050 | LMI REVERSE PROXY EDIT REMOVES SECONDARY INTERFACES |
| IJ38950* | UNEXPECTED AUTHENTICATION CHALLENGE WHEN USING 'AUTH-CHALLENGE-TYPE' |
| IJ41073* | Security Vulnerabilities fixed in the ISAM appliance |
Related Information
ISAM 9.0.7.2 IF4 download link
Previous Cumulative Fixpacks APAR History
APARS fixed in ISAM 9.0.7.2 IF3
|
APAR |
Description |
|
THE ECSSO FLOW IS NOT COMPATIBLE WITH THE PARAMETER CREATE-UNAUTH-SESSIONS ENABLED |
|
|
EMBEDDED LDAP DOES NOT LISTEN ON PORT 636 WHEN REPLICATING THE ISAM RUNTIME COMPONENT |
|
|
INCREASING THE AMOUNT OF APPLIANCE LOGGING |
|
|
LAST FOUR CHARACTERS OF THE KEYSTORE NAME IS BEING STRIPPED. |
|
|
WHILE DATABASE OF IDP STOPPED, FEDERATION FINISHED SUCCESSFULLY THOUGH HTTP STATUS OF SAMLRESPONSE RETURNS 500. |
|
|
WEBSEAL TO STS WEB SERVICE SOAP CALLS FAILS CAUSING OUTAGE FREQUENTLY |
|
|
AAC RESPONSE_TYPE GETTING CONVERTED FROM ARRAY TO STRING IF IT HAS ONLY ONE ELEMENT |
|
|
ISVA 10.0.0.1 INCOMING SAML FEDERATION FAILS AFTER EXTERNAL IDP CONFIG CHANGES |
|
|
WEBSEAL SENDING MULTIPLE "WWW-AUTHENTICATE" HEADERS TO CLIENT |
|
|
ADDING CHARSET TO CONTENT-TYPE WHEN RETURNING TEMPLATE FILES. |
|
|
REVERSE PROXY CLUSTER SYNC FAILS DUE TO TFIMSSO JUNCTIONS |
|
| IJ33195 | LASTUSEDTIME ON RBA_DEVICE TABLE IS NOT UPDATED AFTER CREATED |
|
PKMSPASSWD PAGE ACCESS ISSUE |
|
|
AFTER APPLYING FIXPACK TO ISAM DOCKR ENVIRONMENT, EVENTS DATA WILL BE REMOVED AND CANNOT SEE EVENT LOG |
|
|
CHRYSTOKI.CONF AND /USR/SAFENET/LUNACLIENT/CONFIGURED NOT UPDATED WHEN LUNA HSM KEYSTORE DELETED |
|
|
'CONTACTS' ATTRIBUTE NOT RETAINING 'ARRAY' TYPE WHEN PROVIDED IN A CLIENT REGISTRATION REQUEST |
|
|
MAX CONCURRENT WEB SESSIONS POLICY ISSUES WHEN CREATE-UNAUTH-SESSIONS = YES |
|
|
SLOWNESS WHILE LOADING SSL CERTS PAGE ON A CLUSTERED APPLIANCE |
|
|
POLICY SERVER NOT RESPONDING AS A RESULT SEC_MASTER LOGIN OR JUNCTION LIST FAILS UNTIL RUNTIME IS RESTARTED |
|
|
RUNTIME PROFILE NOT LOADING P11 KEYSTORES CORRECTLY |
|
|
CREDATTR MACRO NOT PROPERLY POPULATED ON EXPIRED PASSWORD LOGIN IF TRY TO BYPASS |
|
|
WEBSEALS FAILS TO STARTWHEN COOKIE-ATTRIBUTES CONTAINS HTTPONLY ATTRIBUTE AND "PASS-HTTP-ONLY-COOKIE-ATTR=NO" |
|
| IJ34580 | MOVING IP ADDRESS FROM ONE INTERFACE TO THE OTHER LEAVES PROXY INSTANCES WITH UNCONFIGURED NETWORK-INTERFACE |
|
OIDC CLAIM ATTRIBUTES ARE MISSING WHEN OIDC ATTRIBUTE NAME MATCHES ATTRIBUTE SOURCE NAME  |
|
|
Security vulnerabilities fixed in ISAM 9.0.7.2 IF3 |
|
|
IN CONTAINER ENVIRONMENT WGA_NOTIFICATIONS SHOULD ONLY RUN ON THE CONFIGURATION CONTAINER |
|
|
MEMORY LEAK WHEN NON GSO USER ACCESSES GSO JUNCTION |
|
|
FIXPACK INSTALLER ISSUES - INSTALL FAILURES CAN BE REPORTED AS SUCCESS |
|
APAR |
Description |
|
STATIC ROUTE FOR A NETWORK DESTINATION IS NOT CREATED CORRECTLY VIA CLI. |
|
|
STS MODULE CONFIGURED USING THE ISAM RTE |
|
|
WITH LTPA-AUTH ENABLED AFTER STEP-UP |
|
|
SLOW RESPONSE OBSERVED WITH REQUESTS |
|
|
CHANGES ARE ACTIVE' SHOW 'FALSE' |
|
|
SLOW RESPONSE FROM ISAM REST API |
|
|
CONFIGURATION OPTION TO INCREASES THE MAX OPEN FILES VALUE |
|
|
Crash: |
|
|
/PKMSLOGOUT FAILS |
|
|
WHEN USING DSC WITH LARGE DATA ITEM IN SESSION |
|
|
UNEXPECTED COOKIE BEHAVIOR WHEN INTERNALLY FOLLOWING REDIRECTS |
|
| IJ32390* | Session Fixation vulnerability |
|
Ensure graceful termination of processes during runtime profile shutdown |
|
|
REQUEST LOG TIME ZONE OFFSET CHANGE DELAYED |
|
|
TLS REMOTE SYSLOG |
|
|
DSC EXTERNAL LISTENING PORT |
|
|
MALFORMED ATTRIBUTE VALUE ERROR |
|
|
LMI ADMINISTRATOR SETTING |
|
|
SNAPSHOT CREATION FAILS |
|
|
Advanced Access Control (AAC) SESSION CACHE |
|
|
DOC: Documenting perceived end-user changes observed from IJ23104 |
|
| IJ33189* | Multiple CVE's fixed: JQUERY UPDATES NEEDED TO FIX SECURITY VULNERABILITIES |
|
Performance: |
|
|
Cookie jar does not respect cookie path which doesn't end in / |
|
|
SUPPORT FOR X5T AND X5C https://www.ibm.com/docs/en/sva/10.0.0?topic=overview-whats-new-in-this-release |
|
|
Max concurrent web session policy not working for external users |
|
|
ISV Verify Wizard hard-code for .ice.ibmcloud.com |
|
APARS fixed in ISAM 9.0.7.2 IF1
|
com.tivoli.pd.jcfg.SvrSslCfg action unconfig IS DELETING PDCA.ks. |
|
|
REVERSE PROXY MEMORY LEAK IN LTPA CACHE |
|
|
ISAM FEDERATION CANNOT SET WAYF COOKIE LIFETIME |
|
|
WHEN GLOWROOT EXTENSION IS INSTALLED FEDERATION/AAC RUNTIME |
|
|
MANAGED COOKIE RETURNED TO BROWSER DURING EAI |
|
|
REST API FOR STATISTICS DOES NOT RESPOND WHILE DST CHANGE |
|
|
ERROR: DUPLICATE KEY VALUE VIOLATES UNIQUE CONSTRAINT "DMAP_ENTRIES_PKEY" |
|
|
INCORRECT CREATE-UNAUTH-SESSIONS=YES BEHAVIOR |
|
|
ADMIN USER CANNOT ACCESS RESOURCES |
|
|
FBTRBA232E ERROR RETURNED FOR SOME MAPPING RULE NAMES IN INFOMAP AUTHENTICATION |
|
|
@TOKEN:RELAYSTATE@ NOT ESCAPED BY DEFAULT |
|
|
ENABLED SERVER SECURE PROTOCOLS FOR ISAM RUNTIME NOT WORKING IN FIPS MODE |
|
|
COOKIE-ATTRIBUTE ARE NOT ADDED WHEN HTTP/2 IS ENABLED |
|
|
SNAPSHOT CREATION FAILS WHEN RUNTIME REPLICATION IS ENABLED |
|
|
REVERSE PROXY USER-AGENT MEMORY LEAK |
|
|
REVERSE PROXY TO RSYSLOG USING TLS1.2 CONNECTION ISSUE |
|
|
TFIM STREAMING ERROR WHEN RESPONSE SIZE NEAR 16KB AND NOT CHUNKED |
|
|
STOP RUNTIME LOGGING EXTRANEOUS DSC PING ERROR MESSAGES |
|
|
RgyGroup.addMembers() METHOD DOES NOT SUPPORT BASIC USERS. |
|
|
HPDAC0949E ERROR CONTAINS INCORRECT RULE NAME |
|
|
ISVA 9.0.7.2 FAILED TO START IN FIPS MODE |
|
|
AAC IS ENCODING SPACE CHARACTER AS "+" IN THE GROUP |
|
|
CANNOT SAFELY CHECK WEBSEAL REQUEST LOG FOR DUPLICATE AUTHORIZATION HEADERS |
|
|
IP-SUPPORT-LEVEL=DISPLACED-ONLY AND "ipv6-support=no" |
|
|
CANNOT EDIT OR UPDATE RSYSLOG FORWARDING |
|
|
APPLIANCE SECURITY VULNERABILITIES |
|
|
ADD SUPPORT FOR NEW RSA SECURID AUTHENTICATION MECHANISM |
|
|
REVERSE PROXY PREMATURE TIMEOUT COMMUNICATING WITH DSC |
|
|
REVERSE PROXY ENHANCED - PWD - POLICY HANDLING OF OUD GRACE - LOGIN – COUNT |
|
|
MACROS NOT SET WHEN EXECUTING CUSTOM JAVASCRIPT WITHIN FEDERATION TEMPLATES |
|
|
UPDATE KERBEROS VERSION TO 1.16.4 |
|
LTPA memory leaks |
|
|
WebSEAL User-Agent HTTPMessage::setAttribute Memory Leak |
|
REVERSE PROXY AUDIT LOG INCLUDE X-FORWARDED-FOR AND APPLICATION URL |
APARS fixed in ISAM 9.0.7.2 GA
|
FBTOAU227E ERROR CODE RETURNED FOR /AUTHORIZE REQUEST |
|
|
REST API TRUNCATES SERVER DNS WITH A COLON |
|
|
AAC TEMPLATE PAGES USING TEMPLATE PAGE SCRIPTING (JAVASCRIPT) ARE CACHED INCORRECTLY |
|
|
REBOOT CAUSES STATIC ROUTE LOST USING DHCP |
|
|
DOCKER - PDWEB LOG LINK TO APPLICATION.LOG LOST ON RESTART |
|
|
DOCKER UPGRADE FROM 9.0.6 TO 9.0.7 FAILS TO STARTS POSTGRES CONFIGDB |
|
|
DEVICE_AUTHORIZE ENDPOINT FOR OAUTH USES DIFFERENT SEPARATOR |
|
|
ADDING OPTIONAL SAML2.0 ATTRIBUTE "PROVIDERNAME" TO SAML REQUEST(SAMLP:AUTHNREQUEST |
|
|
MACOTP NOT AFFECTED BY otp.retry.(enabled|maxNumberOfAttempts|otpRetryTimeout) |
|
|
OTP FAILED ATTEMPTS NOT LOCKING WHEN USING EXTERNAL ORACLE HVDB |
|
|
PARAMETER IS NOT VALID: HVDB_ADDRESS: |
|
|
DEFAULT TARGET URL NOT ACCEPTING RELATIVE URL WHILE CREATING SAML PARTNER |
|
|
GEONAME_ID WITH EMPTY VALUE FOR MAXMIND GEOLOCATION DATABASE V2 CAUSING FAILURE |
|
|
REGENERATING OTP TOKEN DOES NOT RESET CLOCK FOR TOKEN EXPIRY |
|
|
CANNOT EXPORT OBJECT SPACE WHEN JUNCTION HAS TRAILING FORWARD SLASH (/) IN NAME |
|
|
UPGRADE ISAM HARDWARE APPLIANCE CORRUPTS GRUB BOOT MENU |
|
|
PROXY INSTANCE ON DOCKER WILL STOP RESPONDING [junction] connect-timeout = 30 |
|
|
WEBSEAL INCORRECT HANDLING OF INACTIVE-TIMEOUT WITH DSC |
|
|
WHEN ISSUE REFRESH TOKEN IS DISABLED |
|
|
WHEN ISSUE REFRESH TOKEN IS DISABLED |
|
|
REMOTE SYSLOG FORWARDER ABILITY TO SEND CUSTOM RUNTIME .LOG FILES |
|
|
MEMORY LEAK IN REVERSE PROXY CERTIFICATE MAPPING |
|
|
ISAM SAML SP WITH LONG TARGET URL RESULTS IN HTTP 500 |
|
|
MISSING MECHANISMS IN MMFA CONFIGURATION |
|
|
WEBSEAL -> MANAGING ADMINISTRATION PAGES -> IMPORT BEHAVIOR CHANGED FROM 906 TO 907 |
|
|
ERROR FBTRBA005E WHILE IMPORTING A PARTNER |
|
|
REVERSE PROXY TRAFFIC CANNOT SHOW OLD DATA MORE THAN AROUND 10 DAYS OLD |
|
|
UNABLE TO SELECT “UNSPECIFIED” FOR DEFAULT NAMEID |
|
|
ISPASSWORDVALID() FUNCTION NOT RENDERING CORRECT VALUE |
|
|
STS CHAIN EXCEPTION HIERARCHY_REQUEST_ERR WHEN USING USERNAME AND PASSWORD MODULE |
|
|
SUPPORT FOR PERSISTENT TIMEOUT CONFIGURATION FOR WAS LIBERTY |
|
|
STALE GSO CACHE ENTRIES FOR USER CANNOT BE REMOVED AT LOGIN |
|
|
MMFA PUSH NOTIFICATION DOES NOT COMPLETE SUCCESSFULLY |
|
|
UNABLE TO DISABLE TLS RENEGOTIATION ON REVERSE PROXY ADMIN PORT |
|
|
FONT FILE IN AAC TEMPLATE FILES PRODUCES 404 HTTP ERROR |
|
|
REFRESHING TOKENS (USING HASHED REFRESH TOKENS) FAILS AT 9071 |
|
|
OAUTH RELATED DB ARTIFACTS ARE NOT ALWAYS CLEANED UP AFTER USE |
|
|
OAUTH TEMPLATE PAGE'S ERROR CODE MACRO VALUE CHANGES |
|
|
ISAM SNAPSHOTS WHEN APPLIED FAILS WITH ERROR |
|
|
GRANT MANAGEMENT NOT WORKING AT 9070 |
|
|
ISAM REVERSE PROXY 907 EDITING WEBSEAL CONFIGURATION IN THE LMI CHANGES DEFAULT LANG |
|
|
DOCKER: ISAM_CLI SHUTDOWN NO LONGER WORKS AFTER V9.0.7.1 |
|
|
REST API DOES NOT VALIDATE DUPLICATE HOST ENTRIES |
|
|
REMOTE SYSLOG AGENT HIGH CPU ONLY RESOLVED BY RESTART |
|
|
THE PASSWORD SETTINGS IN THE [ITIM] STANZA ARE NOT OBFUSCATED |
|
|
AN ACCESS POLICY USING PROTOCOLCONTEXT.GETFEDERATIONNAME() RETURNS COMPANY NAME |
|
|
REST_API: |
|
|
METHOD TO DELETE HASHED TOKENS FROM MAPPING RULE |
|
|
METHOD TO DELETE HASHED TOKENS FROM MAPPING RULE |
|
|
CANNOT DELETE CONTENTS OF DEFAULT LOCATION FOR POLICY SERVER AUDITING |
|
|
OIDC 'FBTOIC106E Invalid state' OBSERVED |
|
|
CANNOT USE LARGE TOKENS WITH IBM DB2 AS HVDB |
|
|
CANNOT USE LARGE TOKENS WITH IBM DB2 AS HVDB |
|
|
THE STATE PARAMETER IS NOT URLENCODED ON OAUTH STS RESPONSE |
|
|
AAC AUDIT LOG SHOWS ACCESS TOKEN |
|
|
INTERNAL REDIRECT FROM VIRTUAL HOST JUNCTION FAILS TO RESOURCES ON STANDARD JUNCTION |
|
|
SPACE CHARACTERS ARE ENCODED AS PLUS SIGNS IN POC ATTRIBUTES |
|
|
REST API TO RETRIEVE WEBSEAL CONFIGURATION DOES NOT SHOW EMPTY VALUES |
|
|
ISAM 9.0.7.0 UPGRADE CHANGES SERVER LOG (MSG_WEBSEALD-XXX.LOG) '--' SEPARATOR TO 'NEW LINE' SEPARATOR |
|
|
HOW EFFECTIVELY CHANGE THE SPNAMEQUALIFIER FROM IDP MAPPING RULE |
|
|
IN-PLACE TRUSTEER PIP IS OVERWRITTEN DURING FIRMWARE UPGRADE |
|
|
RSA CONFIG: |
|
|
LMI SSL CERTIFICATE UPDATE IS NOT GUARANTEED TO BE SUCCESSFUL ALL THE TIME |
|
|
DISALLOW PATH IN POLICY SERVER AUDITLOG SETTING |
|
|
OAUTH JWKS FILE MISSING "ALG" FIELD |
|
|
MAKE PRE ISAM 9.0.7.0 UNAUTHENTICATED LOGOUT CONFIGURABLE |
|
|
RUNTIME LOGGING FALSE FBTSPS134E MESSAGES |
|
|
IGNORES CLIENT ID MISMATCH BETWEEN HEADER AND BODY FOR TOKEN EXCHANGE |
|
|
REMOTE SYSLOG FORWARDER STOPS SENDING EVENTS WHEN LOG FILE IS CLEARED |
|
|
UNABLE TO CONNECT TO EXTERNAL POSTGRESQL 12 WITH SSL |
|
|
FEDERATION 30 SECOND DELAY ON DSC FAILOVER |
|
|
WEBSEAL ABENDS ON STARTUP WHEN APPLYING ENVIRONMENT VARIABLES |
|
|
ONLY WEBSEAL SERVERS SHOWN IN LMI DISTRIBUTED SESSION CACHE SERVERS SCREEN |
|
|
REDUCE DATABASE DEPENDENCY FOR SAML 2.0 |
|
|
SAML PERSISTENT NAMEID ENTRY CORRUPTION DUE TO UNHANDLED LDAP EXCEPTION |
|
|
SCIM DEMO THROWS NPE IN 9071 |
|
|
SNIPPET-FILTER SHOULD NOT INSERT SNIPPETS INTO MANAGEMENT PAGES SERVED |
|
|
AVOID AAC RUNTIME CONTENTION WHICH CAUSE DISRUPTION/HANG |
|
|
PAGE.SETVALUE BEHAVIOR WITH INFOMAP IS DIFFERENT BETWEEN AUTHSVC AND APIAUTHSVC |
|
|
REVERSE PROXY ABENDS WHEN DESERIALIZING DSC SESSION DATA |
|
|
ISAM ON DOCKER SHOULD SHOW FIXPACK ON DASHBOARD AND UNDER FIXPACKS |
|
|
UPDATE TO MULTIPLE DEPENDENT SOFTWARE PRODUCTS |
|
|
UPDATE IBM SECURITY ACCESS MANAGER DOCKER TO USE UBI 8 |
|
|
TFIM SESSION LIFETIME HAS A MAX OF 24.8 DAYS |
Was this topic helpful?
Document Information
Modified date:
04 August 2022
UID
ibm16602745