IBM Support

IT02298: IBM TIVOLI STORAGE MANAGER IS IMPACTED BY MULTIPLE VULNERABILITIES (CVE-2013-6747, CVE-2014-0963)

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • IBM Tivoli Storage Manager is affected by multiple problems
    related to SSL/TLS communications,
    which, under very specific conditions, can cause
    Tivoli Storage Manager servers and/or storage agents and the
    systems on which they are running
    to become unresponsive, hang or crash.
    
    By default, Tivoli Storage Manager does not use TLS/SSL
    communications and therefore, the exposure only exists if
    you are using TLS/SSL.
    
    See the following security bulletins for details:
    http://www.ibm.com/support/docview.wss?uid=swg21674824
    
    http://www.ibm.com/support/docview.wss?uid=swg21674825
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * All users of Tivoli Storage Manager using SSL/TLS for        *
    * communications                                               *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * See Error Description.                                       *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Apply fixing level when available.  This problem is          *
    * currently projected to be fixed in levels 6.2.7, 6.3.5 and   *
    * 7.1.1.                                                       *
    * See the security bulletin references in the Error            *
    * Description section for interim fixes for levels 6.2.6,      *
    * 6.3.4.30 and 7.1.0.                                          *
    * Note that this is subject to change at the discretion of     *
    * IBM.                                                         *
    ****************************************************************
    

Problem conclusion

  • The problem was fixed.
    Affected Platforms: AIX, HP-UX, Solaris, Linux, and Windows.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT02298

  • Reported component name

    TSM SERVER

  • Reported component ID

    5698ISMSV

  • Reported release

    62A

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2014-06-05

  • Closed date

    2014-06-06

  • Last modified date

    2014-06-09

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    TSM SERVER

  • Fixed component ID

    5698ISMSV

Applicable component levels

  • R62A PSY

       UP

  • R62H PSY

       UP

  • R62L PSY

       UP

  • R62S PSY

       UP

  • R62W PSY

       UP

  • R63Z PSY

       UP

  • R63A PSY

       UP

  • R63H PSY

       UP

  • R63L PSY

       UP

  • R63S PSY

       UP

  • R63W PSY

       UP

  • R71Z PSY

       UP

  • R71A PSY

       UP

  • R71H PSY

       UP

  • R71L PSY

       UP

  • R71S PSY

       UP

  • R71W PSY

       UP

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSGSG7","label":"Tivoli Storage Manager"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"62A","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
09 June 2014