×
The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.
First, how critical is a CVE that begins with 2022 in which IBM issues a
fix in October of 2023?
Next, does the following statement indicate how much of a sick joke
"service extension" is? <snip>The issue can be fixed by applying a PTF to
IBM i. IBM i releases 7.5, 7.4, and 7.3 will be fixed.</snip>
Now, the real question: When reading the PTF cover letter for 7.5
https://www.ibm.com/support/pages/ptf/SI84088
I see: "To enable integrated web services server WSERVICE to allow
certificates with DNS names of ibm.com, developer.ibm.com". Is this to
restrict what domains can access my webservice? Does one really want to do
that? I'm not an apache configuration expert by any means. Is this just
an additional benefit IBM threw in with this PTF and not related to the CVE?
Is this the part of this PTF which really addresses the CVE?
"If you want to enable hostname certification validation for the
HTTP Web Administration Server, specify *ADMIN for the -server
parameter."
I'm guessing the PTF does nothing to fix the CVE, if you do not turn on the
additional configuration changes to address this CVE.
https://www.ibm.com/support/pages/node/7056678?myns=swgother&mynp=OCSWG60&mync=E&cm_sp=swgother-_-OCSWG60-_-E
As an Amazon Associate we earn from qualifying purchases.