Security fixes LU20266 and LU20664 for ESM Microservice 15.0
search cancel

Security fixes LU20266 and LU20664 for ESM Microservice 15.0

book

Article ID: 444777

calendar_today

Updated On:

Products

Common Components and Services for z/OS

Issue/Introduction

Customers may need to apply security fixes for ESM Microservice (LU20266, LU20664) even if the component is not actively used (no ESMPROC running). This guidance clarifies if manually copying HFS elements is sufficient for dormant systems.

Environment

Common Components and Services

ESM Microservice 15.0

Resolution

  • Copying the ESMJAR and ESMZWESO files to the target system's OMVS path is sufficient to ensure the updated code is present on the system. 
  • Since you are not implementing the component, the manual HOLDDATA actions can be safely ignored.
  • Unless the ESMPROC is actually configured and started, the microservice (and its associated Log4j/Tomcat libraries) remains dormant and does not pose a security risk.