• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Guru: Access Client Solutions 1.1.9.11 – Security First, With Continued Investment In SQL Tooling

    January 26, 2026 Gregory Simmons

    Big Blue has released IBM i Access Client Solutions (ACS) version 1.1.9.11, and while the release is anchored by an important security fix, it also reflects IBM’s continued investment in the SQL tooling that has become central to day-to-day IBM i development and administration. This is not a feature-heavy update on its own, but it arrives after a series of releases that have steadily expanded the usefulness of both Run SQL Scripts and SQL Performance Center.

    The primary driver for upgrading to ACS 1.1.9.11 is the remediation of CVE-2025-66516, an XML External Entity vulnerability related to how ACS processes certain PDF content. The issue originates from ACS’s use of Apache Tika within the Run SQL Scripts interface, where Tika is used to identify content types when working with binary data stored in Db2 for i tables. Under specific conditions, a specially crafted XFA file embedded in a PDF could be leveraged to exploit the ACS client. Given how widely Run SQL Scripts is used by developers, DBAs, and system administrators, this vulnerability represents a real-world risk rather than a theoretical edge case.

    If your shop is running ACS 1.1.9.8, 1.1.9.9, or 1.1.9.10, upgrading to 1.1.9.11 should be a priority.

    IBM has been unusually direct in its guidance, strongly recommending that customers upgrade to ACS 1.1.9.11 and discontinue use of versions 1.1.9.8 through 1.1.9.10. That kind of language is a clear signal that this update should be treated as mandatory rather than optional maintenance.

    Outside of the security fix, ACS 1.1.9.11 includes a small set of corrective changes. These address issues such as incorrect cursor positioning when using the DDS RTNCSRLOC keyword and a defect that prevented ACS from properly detecting the availability of version 1.1.9.10 during update checks. The limited scope of these fixes underscores that the release is focused on stability and risk reduction.

    What gives this update broader context, however, is the steady stream of enhancements IBM has delivered to ACS over the past year. Run SQL Scripts has seen continued refinement, including expanded examples, improved diagnostics, and better handling of security-related scenarios, reinforcing its role as the primary SQL workbench for IBM i professionals. At the same time, SQL Performance Center has gained deeper integration and visibility, making it easier to analyze SQL behavior, review performance data, and move from problem identification to actionable tuning without leaving the ACS environment.

    These enhancements are part of a clear trend. IBM continues to position ACS not just as a connectivity tool, but as the central workstation for IBM i development, database analysis, and system management. Improvements to SQL tooling, IFS integration, and Java compatibility all point to an expectation that ACS will remain actively used and frequently updated.

    The bottom line is straightforward. If your shop is running ACS 1.1.9.8, 1.1.9.9, or 1.1.9.10, upgrading to 1.1.9.11 should be a priority. The security fix alone justifies immediate action, and it comes on top of ongoing improvements that make ACS increasingly valuable as a daily driver for IBM i work. Staying current with ACS is no longer just about new features; it is part of maintaining a secure and reliable IBM i environment.

    Until next time, happy coding.

    Gregory Simmons is a Project Manager with PC Richard & Son. He started on the IBM i platform in 1994, graduated with a degree in Computer Information Systems in 1997 and has been working on the OS/400 and IBM i platform ever since. He has been a registered instructor with the IBM Academic Initiative since 2007, an IBM Champion and holds a COMMON Application Developer certification. When he’s not trying to figure out how to speed up legacy programs, he enjoys speaking at technical conferences, running, backpacking, hunting, and fishing.

    RELATED STORIES

    Guru: Taming The CRTSRVPGM Command – Options That Can Save Your Sanity

    Guru: CRTSRVPGM Parameters That Can Save or Sink You

    Guru: A First Look at Bob, The IBM i Assistant That’s Closer Than You Think

    Bob More Than Just A Code Assistant, IBM i Chief Architect Will Says

    IBM Pulls The Curtain Back A Smidge On Project Bob

    Big Blue Converges IBM i RPG And System Z COBOL Code Assistants Into “Project Bob”

    Guru: When Attention Turns To You – Writing Your Own ATTN Program

    Guru: WCA4i And Granite – Because You’ve Got Bigger Things To Build

    Guru: When Procedure Driven RPG Really Works

    Guru: Unlocking The Power Of %CONCAT And %CONCATARR In RPG

    Guru: AI Pair Programming In RPG With Continue

    Guru: AI Pair Programming In RPG With GitHub Copilot

    Guru: RPG Receives Enumerator Operator

    Guru: RPG Select Operation Gets Some Sweet Upgrades

    Guru: Growing A More Productive Team With Procedure Driven RPG

    Guru: With Procedure Driven RPG, Be Precise With Options(*Exact)

    Guru: Testing URLs With HTTP_GET_VERBOSE

    Guru: Fooling Around With SQL And RPG

    Guru: Procedure Driven RPG And Adopting The Pillars Of Object-Oriented Programming

    Guru: Getting Started With The Code 4 i Extension Within VS Code

    Guru: Procedure Driven RPG Means Keeping Your Variables Local

    Guru: Procedure Driven RPG With Linear-Main Programs

    Guru: Speeding Up RPG By Reducing I/O Operations, Part 2

    Guru: Speeding Up RPG By Reducing I/O Operations, Part 1

    Guru: Watch Out For This Pitfall When Working With Integer Columns

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags: Tags: 400guru, Access Client Solutions, ACS, ACS 1.1.9.10, ACS 1.1.9.11, ACS 1.1.9.8, ACS 1.1.9.9, CVE-2025-66516, DB2 for i, FHG, Four Hundred Guru, IBM i, Java, Run SQL Scripts, SQL, XML

    Sponsored by
    GiAPA – The IBM i Developer’s Best Friend

    Want to Speed Up Your IBM i Applications?

    GiAPA pinpoints where performance can be optimized – down to program statements.

    First performance tips free!

    Highlights from www.GiAPA.com:

    • Automatic analysis of all applications
    • Total potential time savings shown
    • Finds optimizations – even in applications believed to run OK
    • Uses <0.1% CPU
    • Free Trial

    2-minute Intro Video    

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    It Looks Like 2026 Will Be a Good Year For Power-IBM i Upgrades IBM Power Offsite Data Protection That Fits The Way IBM i Shops Already Work

    Leave a Reply Cancel reply

TFH Volume: 36 Issue: 3

This Issue Sponsored By

  • Rocket Software
  • FalconStor
  • GiAPA – The IBM i Developer’s Best Friend
  • Raz-Lee Security
  • WorksRight Software

Table of Contents

  • Shaking The IBM i Magic Eight Ball For 2026
  • IBM Power Offsite Data Protection That Fits The Way IBM i Shops Already Work
  • Guru: Access Client Solutions 1.1.9.11 – Security First, With Continued Investment In SQL Tooling
  • It Looks Like 2026 Will Be a Good Year For Power-IBM i Upgrades
  • IBM i PTF Guide, Volume 28, Number 4

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • IBM Starts Winding Down Power10 System Sales
  • Guru: Service Programs And Activation Groups – Design Decisions That Matter
  • Strategic Topics To Think About For 2026, Part 1
  • Shield Gooses Performance Of Nagios Monitoring Tool, Adds AI Reporting
  • IBM i PTF Guide, Volume 28, Number 6
  • Rolling The Die In 2026: IBM i Predictions, Take Two
  • Perhaps 2026 Is The Year For Power Systems To Boom A Little
  • Guru: Binder Source Is Your Service Program’s Owner’s Manual
  • Skills Displaces Cybersecurity As Top Concern For IBM i Shops
  • IBM i PTF Guide, Volume 28, Number 5

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle