IBM Support

IT45007: Thirdparty component updates for cumulative security update 9.1.0.21

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • List of third party packages updated in cumulative security
    update:  9.1.0.21
    

Local fix

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    Users of the IBM MQ components affected by the third party
    product list in the product conclusion.
    
    
    Platforms affected:
    MultiPlatform
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    A new version for some third party packages included in IBM MQ
    are available, and updated in MQ CSU 9.1.0.21
    

Problem conclusion

  • The following updates are included in this APAR :
    
    - jetty-client 9.4.54.v20240208
    - LIBCURL 8.6.0
    - OpenSSL for IBMi 3.0.13
    
    - JRE to 8.0.8.20 on AIX, Windows, and Linux
    -- Applications using the IBM MQ classes for Java and the IBM MQ
    classes for JMS who are running the application using the JRE
    embedded into the MQ installation
    -- IBM MQ Managed File Transfer Edition
    -- IBM MQ Advanced Message Protocol (AMQP)
    -- IBM MQ Telemetry Transport (MQTT)
    -- IBM MQ Explorer
    -- IBM MQ REST API
    -- IBM MQ Console
    
    --  IBM MQ has assessed the issues addressed in this update and
    will release an IBM MQ security bulletin for any vulnerabilities
    applicable to IBM MQ components? use of the Java APIs and
    runtime environment. Users who use the supplied IBM Java runtime
    to execute other code or applications not supplied with IBM MQ
    should review the complete list of vulnerabilities fixed to
    check applicability of any vulnerabilities based on the API
    usage of those applications:
    https://www.ibm.com/support/pages/java-sdk-security-vulnerabilit
    ies
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT45007

  • Reported component name

    IBM MQ BASE MP

  • Reported component ID

    5724H7271

  • Reported release

    910

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2023-11-22

  • Closed date

    2024-04-24

  • Last modified date

    2024-04-24

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    IBM MQ BASE MP

  • Fixed component ID

    5724H7271

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSYHRD","label":"IBM MQ"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"910","Line of Business":{"code":"LOB67","label":"IT Automation \u0026 App Modernization"}}]

Document Information

Modified date:
24 April 2024