IBM Support

IBM Cloud Orchestrator Fix Pack 8 (2.5.0.8) for 2.5

Download


Abstract

IBM Cloud Orchestrator 2.5.0.8 has been made generally available and contains fixes to version 2.5.

Download Description

Table of Contents
Sections Description

The Change history section provides an overview on what is new in this release with a description of any new functions or enhancements when applicable.

The How critical is this fix section provides information related to the impact of this release to allow you to assess how your environment may be affected.

The Prerequisites section provides important information to review prior to the installation of this release.

The Download package section provides the direct link to obtain the download package for installation in your environment.

The Installation instructions section provides the installation instructions necessary to apply this release into your environment.

The Known side effects section contains a link to the known problems (open defects) identified at the time of this release.

Supporting Documentation
Document Description

Click to review the detailed system requirements information for a complete list of hardware requirements, supported operating systems, prerequisites and optional supported software, with component-level details and operating system restrictions.

IBM Knowledge Center provides an entry point to product documentation. You can view, browse, and search online information related to the product.

Click to review a complete list of the defects (APARs) resolved in this release including a list of resolved defects for the entire version family.

 

Prerequisites

Prerequisites include:

Review the Software prerequisites page in the IBM Knowledge Center to ensure your environment meets the minimum hypervisor and operating system requirements, especially if you are upgrading from a previous release of IBM Cloud Orchestrator.

Review the Prerequisites tab in the system requirements report for supported versions of Data Protection and Recovery, Databases and Process Management tools.

Back to top

Installation Instructions

This fix pack can be installed as a fresh installation or as an upgrade of an existing installation. Follow the instructions in the tabs below.


Fresh installation of IBM Cloud Orchestrator

 

Step 1: Review the Installing topic in the IBM Knowledge Center.

---------------------------------------------------------------------------

Upgrade of IBM Cloud Orchestrator from version 2.5 or later

 

The following upgrade scenarios are supported:

  • IBM Cloud Orchestrator V2.5 -> IBM Cloud Orchestrator V2.5.0.8
  • IBM Cloud Orchestrator V2.5.0.1 -> IBM Cloud Orchestrator V2.5.0.8
  • IBM Cloud Orchestrator V2.5.0.1 Interim Fix 1 -> IBM Cloud Orchestrator V2.5.0.8
  • IBM Cloud Orchestrator V2.5.0.2 -> IBM Cloud Orchestrator V2.5.0.8
  • IBM Cloud Orchestrator V2.5.0.2 LA0005 or LA0006  -> IBM Cloud Orchestrator V2.5.0.8
  • IBM Cloud Orchestrator V2.5.0.3 -> IBM Cloud Orchestrator V2.5.0.8
  • IBM Cloud Orchestrator V2.5.0.4 -> IBM Cloud Orchestrator V2.5.0.8
  • IBM Cloud Orchestrator V2.5.0.4 with DirectDriver LA -> IBM Cloud Orchestrator V2.5.0.8
  • IBM Cloud Orchestrator V2.5.0.5 -> IBM Cloud Orchestrator V2.5.0.8
  • IBM Cloud Orchestrator V2.5.0.6 -> IBM Cloud Orchestrator V2.5.0.8
  • IBM Cloud Orchestrator V2.5.0.7 -> IBM Cloud Orchestrator V2.5.0.8

 

Step 1: Review the Upgrading from IBM Cloud Orchestrator V2.5 topic in the IBM Knowledge Center.

-------------------------------------------------------------------------------------------------------------

Migration of IBM Cloud Orchestrator from version 2.4.0.2 or later

 

The following migration scenarios are supported:

  • IBM Cloud Orchestrator V2.4.0.2 -> IBM Cloud Orchestrator V2.5.0.8
  • IBM Cloud Orchestrator V2.4.0.3  -> IBM Cloud Orchestrator V2.5.0.8
  • IBM Cloud Orchestrator V2.4.0.4 -> IBM Cloud Orchestrator V2.5.0.8
  • IBM Cloud Orchestrator V2.4.0.5 -> IBM Cloud Orchestrator V2.5.0.8

 

 

Step 1: Review the Migrating from IBM Cloud Orchestrator V2.4.0.2 or later topic in the IBM Knowledge Center.

 

Step 2: If you are migrating from an IBM Cloud Orchestrator 2.4.0.2 (or later) environment, review the During Migration and After Migration sections and apply the steps appropriate for your setup.

Note: All references to version 2.4.0.4 also apply to version 2.4.0.5 or later.


During Migration

SQL0964C error message

During migration the following message might be displayed:

SQL0964C  The transaction log for the database is full.  SQLSTATE=57011

To solve this problem, clear the transaction logs. For the procedure to clear transaction logs, see IBM DB2 Knowledge Center.

 


After Migration

Creating actions

If you added an action to a predefined toolkit in the IBM Cloud Orchestrator 2.4.0.2 environment and the action was not migrated in the IBM Cloud Orchestrator 2.5.0.8 environment, create the action manually by following the procedure described in Creating an action.


Download Package

 
Download options
Access type Description

Review eAssemblies Parts List for a list of part numbers you can download for this product.

IBM Software Group OEM offerings are designed for partners who develop and sell business solutions with embedded or bundled IBM middleware software. Clients with Flexible Contract Type (FCT) license purchases and IBM Business Partners must sign in to download the software package.

 

Click the HTTP link in the Download section below to obtain the release from Fix Central.

Image directory contents

  • 2.5.0-CSI-ICO-FP0008.tgz: IBM Cloud Orchestrator Version 2.5 Fix Pack 8 for Red Hat Enterprise Linux Multilingual
  • 2.1.0.6-SCCM-IFIX05.tar: IBM SmartCloud Cost Management 2.1 Fix Pack 6 ifix05

How critical is this fix?

 
Impact Assessment
Impact Description

Corrective

This is a maintenance release. It contains fixes for client-reported and internally found defects.

  • CVE-2017-3736 CVE-2017-3732 CVE-2016-0705 CVE-2018-1517 CVE-2018-1656 CVE-2018-2964 CVE-2018-2973 CVE-2018-2952 CVE-2018-2940 CVE-2018-12539  - Multiple vulnerabilities in IBM® SDK Java™ Technology Edition that were disclosed as part of IBM Java SDK updates in July 2018.
  • CVEID: Not Applicable -  The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server does not properly handle requests, which allows remote attackers to execute code.
  • CVE-2018-1695 - WebSphere Application Server form logout could be vulnerable to spoofing attack.
  • CVE-2018-1567 - A vulnerability in java deserialization can result in execution of untrusted data via the application server's SOAP port.
  • CVEID: Not Applicable - Cacheable HTTPS Response
  • CVE-2018-3183 CVE-2018-3169 CVE-2018-3149 CVE-2018-3180 CVE-2018-3214 CVE-2018-13785 CVE-2018-3136 CVE-2018-3139 - IBM SDK, Java Technology Edition Quarterly CPU - Oct 2018 - Includes Oracle Oct 2018 CPU
  • CVE-2018-1767 - 3RD PARTY XSS in IBM WebSphere CacheMonitor
  • CVE-2018-1777 - 3rd party reflected xss in admin console
  • CVE-2018-1794 - 3RD PARTY Reflected XSS - WebSphereOauth20sp
  • CVE-2018-1793 - 3RD PARTY Reflected XSS in WebSphereSamISP
  • CVE-2014-7810 - WebSphere Application Server traditional and liberty vulnerability
  • CVE-2018-1770 - 3RD PARTY CSRF and OOB-XXE Vulnerabilities in WebSphere Web Application Server's Integrated Solutions Console 9.0.0.8, 8.5.5.13, and 8.5.5.9
  • CVE-2018-1719 - WebSphere Application Server is susceptible to TLS downgrade when using FIPS, JVM property, and non WebSphere Application Server keystore/truststore.
  • CVE-2018-1621 - Password disclosure in WebSphere Application Server trace log.
  • CVE-2018-1301 CVE-2017-15715 CVE-2017-15710 - Apache vulnerabilities affect IBM HTTP Server

  • CVE-2017-12613 - Apache Portable Runtime affects IBM HTTP Server

Test Results

Definitions

Regression: An error in the Maintenance Delivery Vehicle (MDV) that produces incorrect or unexpected behavior causing a supported feature to stop functioning as designed.
This includes:

  • Coding errors that cause a regression
  • Documentation or packaging problems that cause a regression
  • Errors reported in a new function delivered in a MDV that cause a regression

 

Incomplete: An error in the MDV has not regressed, but does not work as designed.
This includes:

  • Fixed APARs which did not solve the original problem but did not break anything new
  • APARs reporting documentation errors, such as readme errors, that cause problems applying an MDV but do not lead to a regression

 


Notes:
  • Regression and incomplete APARs are considered fix-in-error or MDV-in-error
  • Definitions above apply only to valid APARs that result in product fixes (APARs returned as working-as-designed are not assessed for being fix-in-error)
  • Issues in major releases due to new functionality do not apply in this definition

 

There are no known regressions to report.

Known Side Effects

 
Review the following list of known issues and open defects:

Review the Known errors and limitations section of the IBM Knowledge Center for issues related to this release.

Open defects

Review the following list of open defects for IBM Cloud Orchestrator on the IBM Support Portal.

Change History

What's new

For information about the new features and enhancements, review the What is new in this release topic in the IBM Knowledge Center.

On
[{"DNLabel":"IBM Cloud Orchestrator 2.5 fixes","DNDate":"07 Dec 2018","DNLang":"English","DNSize":"26194211457","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7ETivoli&product=ibm/Tivoli/IBM+SmartCloud+Orchestrator&release=2.5.0&platform=All&function=all","DNURL_FTP":"","DDURL":null}]
[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS4KMC","label":"IBM SmartCloud Orchestrator"},"Component":"","Platform":[{"code":"PF002","label":"AIX"}],"Version":"2.5.0.8","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
06 December 2018

UID

ibm10739511