IBM i Global

IBM i 

A space for professionals working with IBM’s integrated OS for Power systems to exchange ideas, ask questions, and share expertise on topics like RPG and COBOL development, application modernization, open source integration, system administration, and business continuity.


#Power


#IBMi
#Power
 View Only
  • 1.  DB2 Web Query: Security patches.

    Posted Fri January 05, 2024 07:40 AM

    Recently, in another forum, someone received a notification about a security flaw with DB2 Web Query.  It only mentioned 2.4.0 and he opened a case to see if it was applicable to 2.3.0 also (he was planning on staying on that).  This was IBM's reply:

    <IBM>

    Development's response is as follows:
    IBM does not assess out-of-support releases for vulnerabilities. General experience across many products has been that most vulnerabilities found in the oldest supported release are also applicable to the prior out-of-support release. You should proceed with the expectation that statement is applicable for Web Query.

    </IBM>

    He is now planning on upgrading to 2.4.0.

    This was my earlier conjecture prior to him getting a definitive answer.

    <MyConjecture>

    The group PTF for 2.4 is dated 2023-11-17.  It says:
    ...
    Planned Update Schedule:  Unknown
    ...
    A cursory glance at a PTF or two on that list found no mention of any CVE's.
    The group ptf for 2.3 is dated 2023-07-19.  It says:
    Planned Update Schedule:  Please see the withdrawal announcement for
    Db2 Web Query for i 2.3.0 at
    https://www.ibm.com/docs/en/announcements/withdraw-db2-web-query-i-230-5733-wqx?region=LA.

    The link above says:  Technical support continues to be available until the end of support date.  It also says the end of support for 2.3.0 was October 31, 2023
    One could interpret this as, even if there is a security leak, you are SOL when it comes to getting any fixes for 2.3.
    If you go to ibm.com and on their search bar look for: ibm i ptf cover letters wqx "Web Query 2.3.0"
    and sort by newest to oldest, you will not find anything newer than July 19 of 2023, which was before end of support.  Change that 3 to a 4 and you will find newer ones.
    Just my daily dose of FUD.  Did it work?
    </MyConjecture>


    ------------------------------
    Robert Berendt IBMChampion
    ------------------------------


  • 2.  RE: DB2 Web Query: Security patches.

    Posted Fri January 05, 2024 07:41 AM

    Original forum thread:

    https://archive.midrange.com/midrange-l/202401/msg00016.html



    ------------------------------
    Robert Berendt IBMChampion
    ------------------------------