APAR status
Closed as program error.
Error description
Koopa parser distributed for importing schema from COBOL Copybook (.cpy) file has Log4j vulnerable classes that can be exploited for security attacks during runtime.
Local fix
ITXCQ - ITX00061272 GK / GK Circumvention: None
Problem summary
Users Affected: IBM Transformation Extender users using Design Server (COBOL Copybook Importer) Problem Description: Koopa parser distributed for importing schema from COBOL Copybook (.cpy) file has Log4j vulnerable classes that can be exploited for security attacks during runtime. Platforms Affected: All
Problem conclusion
Fixed a problem with Koopa parser used for importing schema from the COBOL Copybook (.cpy) file to avoid exploitation of classes vulnerable to security attacks with Log4j component. Applies to: 10.1.0.1, 10.1.1.0 Fixed in the next service packs and releases. To obtain the fix for this APAR: To see if the next service pack or product release is available, check the IBM Transformation Extender Release Notes page: https://www.ibm.com/support/docview.wss?uid=swg27008337 If the service pack or product release is available, download it from Fix Central: http://www.ibm.com/support/fixcentral/ If the service pack or product release is not available and you require the APAR fix immediately, request a Limited Availability Interim Fix (LAIF) by opening a case: https://www.ibm.com/mysupport/ Prior to version 9.0.0, IBM Transformation Extender was called IBM WebSphere Transformation Extender.
Temporary fix
Comments
APAR Information
APAR number
PH44889
Reported component name
TX HIPPA EDI
Reported component ID
5724M6100
Reported release
A10
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2022-03-15
Closed date
2022-03-28
Last modified date
2022-05-22
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
TX HIPPA EDI
Fixed component ID
5724M6100
Applicable component levels
[{"Line of Business":{"code":"LOB59","label":"Sustainability Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSVSD8","label":"Transformation Extender"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"A10"}]
Document Information
Modified date:
23 May 2022