IBM Support

Fix packs for DataPower Gateway 10.6.0.x

Download


Downloadable File

File link File size File description

Abstract

Lists of fixes in IBM DataPower Gateway 10.6.0.x fix packs.

Download Description

Fix packs and firmware images are located in either Fix Central, Passport Advantage, or the Entitled Registry.

In IBM Knowledge Center you can find information about new and changed features, limitations, and restrictions.

Library upgrade to support TLS

10.6.0.0 includes an updated library to support TLS and cryptographic operations. The updated crypto library improves security and usability, but the added complexity of this implementation comes with a performance cost. This update is needed to maintain the proper security posture, which includes CVE updates.

Important



10.6.0.0

Release date: 13 June 2024
Last modified: 13 June 2024
Status: Available

APAR
Description
IT44550 DATAPOWER LOGS ERROR READING FROM CONNECTION: SYSTEM ERROR (110)
IT45245 DATAPOWER MIGHT RESTART WHEN MONITORING GATEWAYSCRIPT FILES FOR UPDATES
IT45786 DATAPOWER SHOULD NOT ALLOW DUPLICATE ENTRIES UNDER SFTP CLIENT POLICIES FOR USER AGENT
IT45833 MEDIUM SEVERITY VULNERABILITIES IN GOLANG
IT45855 MQV9+ OR MQMFT MIGHT NOT RETRIEVE MESSAGES WHILE UNITS-OF-WORK IS ENABLED
IT45966 API GATEWAY API WITH LONGEST BASE PATH IS NOT ROUTED WHEN THERE ARE MULTIPLE CANDIDATES.
IT45973 INCORRECT VALUE OF $(API.OPERATION.PATH) WHEN PATTERN KEYWORD IS SPECIFIED IN THE PATH PARAMETER.
IT46008 CSS BANNER NOT DISPLAYED IN NEW UI.
IT46030 COMPATIBILITY ISSUE OF OBJECT.PROTOTYPE.TOSTRING AFTER UPGRADE.
IT46043 CANNOT CONVERT API YAML OF FORCEHTTP500FORSOAP11 TO DATAPOWER CONFIGURATION.
IT46052 REMOVE THE ANGULAR.JS LIBRARY.
IT46054 CORRUPTED BINARY ATTACHMENTS IN MULTIPART HANDLING.
IT46061 DATAPOWER MIGHT RESTART WHEN PREPARING FOR USER ACTIVITY SUCH AS IMPORT, EXPORT, AND SO FORTH.
IT46062 APIM.SETVARIABLE OF MESSAGE.STATUS.CODE NEEDS TO SET THE REASON PHRASE WHEN INCLUDED.
IT46070 API GATEWAY LOGS MIGHT CONTAIN SPECIAL CHARACTERS FOR THE SPACE NAME.
IT46079 THE QUERY PARAMETER VALIDATION DOES NOT SUPPORT THE URL-ENCODED FORMAT.
IT46081 ADDRESS FALSE POSITIVE FINDINGS IN VULNERABILITY SCANS.
IT46096 WRONG API PARAMETER TYPE WHEN THE FORMAT IS BYTE, BINARY, DATE, DATE-TIME, OR PASSWORD.
IT46101 DATAPOWER B2B EBMS3 SOAP 1.2 MESSAGES INCORRECTLY SET THE MUSTUNDERSTAND ATTRIBUTE.
IT46105 UPDATE NODEJS LIBRARY TO ADDRESS CVE-2024-27982
IT46108 API WITH CONSUME DECLARATION DOES NOT HAVE A HIGHER PRIORITY.
IT46116 MIGRATED V5 POST RESPONSE EXTENSION CORRUPTS CLIENT RESPONSE
IT46117 GATEWAYSCRIPT MIGHT NOT THROW AN ERROR WHEN THE BUFFER OBJECT IS ACCESSED OUT OF BOUND.
IT46118 THE API GATEWAY MIGHT RESTART WHEN SENDING A MULTIPART MESSAGE WITH AN INVALID INVOKE URL IN THE INVOKE ASSEMBLY ACTION.
IT46119 API SUBSCRIPTION SERVICES WITH SAME BASE PATH AND OPERATION RETURN THE WRONG RESPONSE.
IT46131 API RATE LIMIT STATUS DOES NOT RETURN DATA FROM SECONDARY GATEWAY-PEERING INSTANCES.
IT46132 DATAPOWER FOR LINUX, SECURE RESTORE DOES NOT RESET THE PASSWORD FOR THE ADMIN ACCOUNT.
IT46135 TEMPORARY FILES THAT GATEWAYSCRIPT GENERATE DO NOT HONOR THE TTL IF A RELOAD HAPPENS BEFORE TTL IS REACHED.
IT46145 DATAPOWER FOR VMWARE, NEW UI DOES NOT DISPLAY ALL RAID ARRAY ACTIONS.
IT46146 REST API RETURNS NUMBER VALUES FOR THE NAME INSTEAD OF A STRING VALUE.
IT46156 DATAPOWER MQ CLIENT MIGHT GET UNEXPECTED CONNECTION ERRORS
IT46167 UNEXPECTED 404 RESPONSE FOR AN API PATH WITH MANY SPECIAL CHARACTERS.
IT46196 PROBE CANNOT CAPTURE TRANSACTIONS AFTER THE PROBE CAPTURE IS DELETED AND RE-CREATED.
IT46197 DATAPOWER MIGHT RESTART AFTER UPDATING OBJECTS IN CONFIGURATION SEQUENCES.
IT46255 DATAPOWER UI AND REST MANAGEMENT REQUESTS DO NOT RETURN WARNINGS FOR FIRMWARE UPDATE ACTION.
IT46261 GATEWAY PEERING GROUP MIGHT BE OPERATIONAL UP WHILE INVALID LOCAL NODE IS DEFINED FOR CLUSTER MODE.
IT46271 AFTER AN IRREGULAR RESTART, THE DATAPOWER APPLIANCE HAS OLD VERSIONS OF OBJECTS.
IT46274 UPDATE KERNEL TO ADDRESS CVE-2023-4016.
IT46276 UPDATE KERNEL TO ADDRESS MULTIPLE CVES.
IT46277 UPDATE KERNEL TO ADDRESS CVE-2023-38403.
IT46284 DATAPOWER MIGHT RESTART AFTER DISABLING OR DELETING A GATEWAY-PEERING CLUSTER NODE.
IT46285 API CONNECT GATEWAY SERVICE MIGHT RESTART WHEN /GATEWAY-SERVICE-CONFIGURATION-DELETE IS INVOKED WITH NO BODY.
IT46286 INCORRECT COUNT OF CAPTURED TRANSACTIONS IN THE NEW PROBE.
IT46292 ITX TAG MISSING FROM ILMT-SCAN IN ALL RELEASES
IT46293 MEMORY LEAK ON QUERYING SUBSCRIPTION WITH PATTERN
IT46294 CLEAN UP REFERENCE TO REMOVED CATALOG
IT46301 MEMORY LEAK TO ROUTE AN API CONNECT API WITH QUERY, HEADER, OR FORM PARAMETERS.
IT46324 ENABLING TLS ON GATEWAY PEERING GROUP MIGHT HANG GATEWAY
IT46448 CRITICAL SEVERITY VULNERABILITY IN OPENSSL (CVE-2024-4741)

Change history
Last modified: 13 June 2024

  • 13 June 2024: Added fix list for the 10.6.0.0 fix pack.

Off

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB67","label":"IT Automation \u0026 App Modernization"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateway"},"ARM Category":[{"code":"a8m50000000L0rqAAC","label":"DataPower"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"10.6.0"}]

Problems (APARS) fixed
IT44550; IT45245; IT45786; IT45833; IT45855; IT45966; IT45973; IT46008; IT46030; IT46043; IT46052; IT46054; IT46061; IT46062; IT46070; IT46079; IT46081; IT46096; IT46101; IT46105; IT46108; IT46116; IT46117; IT46118; IT46119; IT46131; IT46132; IT46135; IT46145; IT46146; IT46156; IT46167; IT46196; IT46197; IT46255; IT46261; IT46271; IT46274; IT46276; IT46277; IT46284; IT46285; IT46286; IT46292; IT46293; IT46294; IT46301; IT46324; IT46448;

Document Information

Modified date:
28 June 2024

UID

ibm17156692