Showing posts with label Alerts. Show all posts
Showing posts with label Alerts. Show all posts

Thursday, July 9, 2015

FLASH: Info Letter: Changes to ECC broadband callhome server IP addresses

This Flash concerns the call home function of the TSSC (TS3000 System Console), which is the console that's used for IBM tape products like the TS3500 Tape Library (3584), the TS7700 Virtualization Engine, the TS7650 Deduplication product(s) ... If you want a clear introduction to the TSSC and the Electronic Customer Care & Assist On Site, you can find a very good presentation by Joachim Müller over here.

ECC is used "to provide broadband connectivity for both Dial-in and/or Dial-out for the attached Tape Products. While TS3000 supports modem attachment for Dial-in and Dial-out as well, broadband connectivity is the recommended method in todays infrastructure".

Now, what's the Flash about ? I'm taking over most of the content

Abstract
The IP addresses for some of the ECC target server are being changed. 

Background:
As documented in the IBM Data Protection & Retention (DP&R) System Connectivity and Security Whitepaper v2.10 from 4/16, one server will be discontinued and replaced by a new server, for both basic ECC callhome as well as ECC Edge callhome. www.ibm.com/support/techdocs/atsmastr.nsf/WebIndex/WP102531
--> This link doesn't seem to work, so try V2.20 of the document over here.



Solution (Procedure):
Customer network configuration may need to be updated in order to allow the ECC client running on TSSC to be able to connect to the new server IP address through the customer firewall or proxy server.
Failure to update firewall/proxy rules may eventually result in failure to successfully call home.
Note: No changes are required to TSSC configuration itself. Updated ECC configuration is downloaded by the callhome process automatically.


For completeness, here are the products that are affected
  • TS3500 Tape Library (3584)
  • TS7700 Virtualization Engine)
  • TS7650 Deduplication Appliance (3958-AP1) ProtecTIER Appliance Edition
  • TS7650G Deduplication Gateway (3958-DD1-5) ProtecTIER Enterprise Edition

Tuesday, March 17, 2015

Security Bulletin: Multiple vulnerabilities impact DS8000 HMC

Here's a new security bulletin on the DS8870 (and above). You can find it over here.
I'm not taking over all its content because it's a bit too elaborate but here's the summary

"Summary

There are multiple vulnerabilities in the DS8000 HMC which are covered in this bulletin and include the Padding Oracle On Downgraded Legacy Encryption (POODLE) SSLv3 vulnerability (CVE-2014-3566). This bulletin also covers several items which were updated to address other vulnerabilities.

Vulnerability Details


Before applying the patches or versions noted in this advisory, please read the additional notes - there are potential impacts to clients which connect to the updated servers since SSLv3 is disabled. You should verify that disabling SSLv3 does not cause compatibility issues.

While this advisory covers mainly CVE-2014-3566, product updates included also address the list of CVEs"
CVEs are concentrating on Open SSL, IBM Java and NTP.

Affected Products and Versions are DS8870 R7.2 and above, DS8800/DS8870 R6.3 SP 9 and above.

The fix is available as a full update as well as patch. You find all the necessary details in the bulletin itself.

Tuesday, December 16, 2014

Security Bulletin: POODLE vulnerability in SSLv3 affects IBM Explorer for z/OS and IBM CICS Explorer

Here's a security bulletin. I'm taking over some of its content. Just take a look over here for all the details, workarounds and mitigations.

Summary

SSLv3 contains a vulnerability that has been referred to as the Padding Oracle On Downgraded Legacy Encryption (POODLE) attack. This vulnerability affects all versions of IBM Explorer for z/OS and IBM CICS Explorer.

Vulnerability Details

CVE ID: CVE-2014-3566

DESCRIPTION: IBM Explorer for z/OS and IBM CICS Explorer could allow a remote attacker to obtain sensitive information, caused by a design error when using the SSLv3 protocol. A remote user with the ability to conduct a man-in-the-middle attack could exploit this vulnerability by using a POODLE (Padding Oracle On Downgraded Legacy Encryption) attack to decrypt SSL sessions and access the plaintext of encrypted connections.

CVSS Base Score: 4.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/97013 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)

Affected Products and Versions

This vulnerability affects all versions of IBM Explorer for z/OS and IBM CICS Explorer.

Thursday, January 30, 2014

Potential exposure to job aborts in z/OS environment with zHPF enabled running on a DS8870 with R7.1

Here's a new flash alert on the DS8870. You can find the alert over here.
I'm taking over the content here as well.

Abstract

z/OS clients with zHPF enabled running on a DS8870 with R7.1 bundles below 87.10.102.0 are exposed to job aborts due to Channel Errors (IOS071I START PENDING)

Content

The job aborts due to Channel Errors (IOS071I START PENDING) are caused by an internal condition of the DS8870 when zHPF is enabled.
Based on the number of transferred bytes per track the calculation for the amount of SMBs (sequential memory buffer) the DS8870 needs to allocate for transferring data over the channel may be wrong.
This wrong calculation leads to a code exception or an I/O hang in the DS8870 which may result in job aborts and IOS071I START PENDING messages.

The issue was introduced in the R7.1 GA bundle 87.10.87.0 and fixed in the bundles identified in the Resolution section below.

Exposed Microcode bundles:
R7.1: all Microcode bundles below 87.10.102.0 R7.1 SP3, multiple field occurrences observed, all on bundle 87.10.91.1

Mitigation:

Disable zHPF until a service window can be scheduled to update DS8870 firmware to a bundle containing the fix.

Resolution :

A DS8870 microcode build to fix this issue has been made available in Bundle 87.0.102.0 or higher.

87.10.102.0 R7.1 SP3
87.20.220.0 R7.2 GA

For those customers upgrading code from R7.0 to R7.1 and running zHPF the minimum recommended microcode level is 87.10.102.0 (R7.1 SP3)

Friday, August 27, 2010

AD2R abend after upgrading to DB2 9.1 when running CICS TS 4.1

Thought I might as well mention this flash (alert). I'm just quoting the alert you can find over here.

Abstract
After you upgrade to DB2 V9.1, transactions in your CICS Transaction Server for z/OS (CICS TS) V4.1 region start to fail with an abend AD2R ( abendAD2R ). The CICS exception trace indicates that the DB2 thread abended with an 0C4 Reason 0003EB60 ( RSN3EB60 ). Your CICS TS V3.2 regions are not affected by the change.

Content
DB2 V9.1 APAR PM20489 has been opened to address an abend 0C4 in DSNMLTOK at offset 4 and will fix this problem. If possible, you should wait until the PTF for this APAR is available before upgrading to DB2 V9.1 if running CICS TS V4.1.

As soon as PM20489 closes and the PTF becomes available, this document will be updated and included in the My Notifications email for CICS Transaction Server and on Twitter for IBM_CICS. You can also track specific CICS APARs if you would like to be notified when the PTF for this APAR becomes available.

Diagnosing the Problem
Following is the CICS exception trace entry:
AP 319D D2EX1 *EXC* THREAD TCB HAS ABENDED WITH ABEND
000000C4,REASON,0003EB60

The reason code is not a valid DB2 reason code.

Prior to this, within the CICS trace entries, you will see:
AP 3180 D2EX1 ENTRY APPLICATION REQUEST EXEC SQL UNKNOWN

If a system dump is captured for the abend AD2R, the kernel error table will show an abend0C4 followed by transaction abend percolates:
ERROR TYPE ERR_CODE MODULE OFFSET
PROGRAM_CHECK 0C4/AKEA UNKNOWN UNKNOWN
TRAN_ABEND_PERCOLATE ---/AD2R DFHPCP 00000604
TRAN_ABEND_PERCOLATE ---/AD2R DFHD2EX1 00002CDC
TRAN_ABEND_PERCOLATE ---/AD2R DFHERM 0000137E

The PSW of this abend0C4-38 points into module DSNLMTOK +4 to a StoreMultiple (EBEC D008 0024 STMG R14,R12,8(R13) ).