Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Tuesday, March 17, 2015

Security Bulletin: Multiple vulnerabilities impact DS8000 HMC

Here's a new security bulletin on the DS8870 (and above). You can find it over here.
I'm not taking over all its content because it's a bit too elaborate but here's the summary

"Summary

There are multiple vulnerabilities in the DS8000 HMC which are covered in this bulletin and include the Padding Oracle On Downgraded Legacy Encryption (POODLE) SSLv3 vulnerability (CVE-2014-3566). This bulletin also covers several items which were updated to address other vulnerabilities.

Vulnerability Details


Before applying the patches or versions noted in this advisory, please read the additional notes - there are potential impacts to clients which connect to the updated servers since SSLv3 is disabled. You should verify that disabling SSLv3 does not cause compatibility issues.

While this advisory covers mainly CVE-2014-3566, product updates included also address the list of CVEs"
CVEs are concentrating on Open SSL, IBM Java and NTP.

Affected Products and Versions are DS8870 R7.2 and above, DS8800/DS8870 R6.3 SP 9 and above.

The fix is available as a full update as well as patch. You find all the necessary details in the bulletin itself.

Thursday, February 12, 2015

Security Bulletin: GNU C library (glibc) vulnerability affects DS8000 and XIV

IBM issued some security bulletins referring to all models of the DS8000 and the Gen2 and Gen3 of the XIV.

In general, here's what it's about :

"Summary

GNU C library (glibc) vulnerability that has been referred to as GHOST affects DS8000

Description: 

The gethostbyname functions of the GNU C Library (glibc) are vulnerable to a buffer overflow. By sending a specially crafted, but valid hostname argument, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the targeted process or cause the process to crash. The impact of an attack depends on the implementation details of the targeted application or operating system. This issue is being referred to as the "Ghost" vulnerability."

For more information and fixes, please refer to the appropriate flashes.
For DS8000 : link.
For XIV Gen2 : link.
For XIV Gen3 : link.

Tuesday, December 16, 2014

Security Bulletin: POODLE vulnerability in SSLv3 affects IBM Explorer for z/OS and IBM CICS Explorer

Here's a security bulletin. I'm taking over some of its content. Just take a look over here for all the details, workarounds and mitigations.

Summary

SSLv3 contains a vulnerability that has been referred to as the Padding Oracle On Downgraded Legacy Encryption (POODLE) attack. This vulnerability affects all versions of IBM Explorer for z/OS and IBM CICS Explorer.

Vulnerability Details

CVE ID: CVE-2014-3566

DESCRIPTION: IBM Explorer for z/OS and IBM CICS Explorer could allow a remote attacker to obtain sensitive information, caused by a design error when using the SSLv3 protocol. A remote user with the ability to conduct a man-in-the-middle attack could exploit this vulnerability by using a POODLE (Padding Oracle On Downgraded Legacy Encryption) attack to decrypt SSL sessions and access the plaintext of encrypted connections.

CVSS Base Score: 4.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/97013 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)

Affected Products and Versions

This vulnerability affects all versions of IBM Explorer for z/OS and IBM CICS Explorer.

Monday, October 27, 2014

Recent security vulnerabilities

OK, I admit, you haven't heard much of me lately but I've been too busy with other stuff that was not all that mainframe related. Still, I couldn't help noticing that there were quite some security issues lately. So, I thought I'd put up a couple of links that might be helpful. And I hope I'll find the time to blog a little more again from now on.

  • Security Bulletin: Vulnerability in SSLv3 affects IBM Virtualization Engine TS7700 (CVE-2014-3566)
    SSLv3 contains a vulnerability that has been referred to as the Padding Oracle On Downgraded Legacy Encryption (POODLE) attack. SSLv3 is enabled in IBM Virtualization Engine TS7700.
  • Security Bulletin: Vulnerability in SSLv3 affects TS3500 (CVE-2014-3566)
    SSLv3 contains a vulnerability that has been referred to as the Padding Oracle On Downgraded Legacy Encryption (POODLE) attack. SSLv3 is enabled in TS3500.
  • Security Bulletin: POODLE vulnerability in SSLv3 affects IBM Explorer for z/OS and IBM CICS Explorer (CVE-2014-3566)
    SSLv3 contains a vulnerability that has been referred to as the Padding Oracle On Downgraded Legacy Encryption (POODLE) attack. This vulnerability affects all versions of IBM Explorer for z/OS and IBM CICS Explorer.
  • Security Bulletin: A Security vulnerability has been discovered in Apache Struts which impacts the DS8000 GUI (CVE-2014-0114)
    A security vulnerability has been discovered in Apache Struts which impacts the DS8000 GUI



Thursday, February 28, 2013

Red Alert - System z Security Portal for Security and Integrity Fixes

I'm not sure whether to call this a red alert. It's more a reminder that you should get starting to use the IBM System z Security Portal. Here's the link :

Reminder to access the System z Security Portal for Security and Integrity Fixes

It was also on the IBM-Main discussion group a couple of months ago when IBM contacted all z/OS customers either directly or through BP about a couple of security issues. As the Red Alert says : "IBM treats information about security and integrity fixes on z/OS as Confidential". Therefore no Red Alerts are issued about security issues but they are fenced off behind the Security Portal. There's a whole process to obtain access to his security portal. You can find all information over here.

In fact a manager should send a mail to your IBM representative or a BP representative who will then send it on to IBM confirming you're a z/OS customer. It must contain the names and ResourceLink IDs of the persons who should have access to the Security Portal. It must also contain the following phrases :
(1) the information is provided "AS IS" without warranties of any kind, implied or otherwise,
(2) any use of the information is at the user's own risk,
(3) the information in this portal and database may change without notice,
(4) the information is IBM Confidential and may be used by you for internal purposes only and may not be disclosed to any third party without IBM's prior written consent, and
(5) in no event shall IBM be held liable for any damages whatsoever arising out of or in connection with the use of any of the information".
If you do not feel comfortable with this, do contact your local IBM representative who will surely give you more details about this. If you're not sure how the mail should look like, just send me a mail and I'll send you an example.

If you want to have an overview of all past Red Alerts, then take a look over here. You can also subscribe on that same page so you'll be notified of any future Red Alert.

Friday, September 7, 2007

CCR2 Newsletter - september issue

You might've noticed I've not been posting as regularly as before. I think it really has to do with the holiday period : less announcements, less events, less interesting publications (on Techdocs e.g.) ... and I'm not really eager on posting when there's nothing much to tell. Cucumber season ?

It's been 5 months since I mentioned IBM's CCR2 Newsletter. All details on this newsletter, its content and how to subscribe are in my previous post.
I guess that CCR2 is the first one to pick up the pace again, because there are some really nice articles in it. My selection ?
  • "Did you say mainframe?!" podcasts
    In fact these are mainly about mainframe and SOA. There's e.g. "CICS Transaction Server V3.2 –- Continuing to put the S in SOA" talking about "CICS application connectivity, CICS application reuse and CICS application service management".

Wednesday, May 2, 2007

Vanguard Software Products

Less than 2 years ago, on August 23, 2005 IBM announced to resell the Vanguard Software Products as "a complete solution for RACF security management". I quote the 2005 announcement : "Vanguard products dramatically improve the efficiency of security administration provide expert level vulnerability analysis and system auditing tools, and add real-time event, intrusion detection, and policy enforcement capabilities to the zSeries Server. Everyday security functions can be performed with accuracy in a fraction of the time".
Now, IBM made the following announcement : 'Developer Relations Remarketing software withdrawal: Vanguard products'. The products are Vanguard Administrator, Vanguard Advisor, Vanguard Analyzer, Vanguard Enforcer and Vanguard SecurityCenter.
No doubt this is related to the acquisition of Consul a couple of months ago. The Consul suites will be incorporated into the Tivoli Security Management Products.

Tuesday, April 3, 2007

Introduction to the New Mainframe

I started my career on mainframe in 1988 with an intensive 1-year course at IBM. The first 4 months we followed lots of introductory courses on z/OS, JCL, ISPF, CICS, DB2, CLIST, COBOL... you know the drill. The rest of the year was a mixture of courses and a practical training on site at a customer site. When the customer was satisfied, you could stay afterwards. As you can see : I'm still around. So training young people on mainframe is not that new. But I guess the need for new people on the mainframe is much more urgent now than it was back then in the eighties.
So there I was, after 4 months with a 'thorough' knowledge of z/OS, just to find out they'd dropped me in a VM/VSE site. We planned some courses, but in the mean time I had to pick up on VM, VSE, DL/I, Rexx as fast as I could. And I think that's where the big difference lies with now. Where to get your information, introductory publications on all those items. Internet was something of the future. Redbooks were much more scarce. So I ploughed through any IBM documentation I could find, mainly command references and user's guides. And we all know how well these were written at the time.
So I'm glad that IBM is putting great effort into making good introductory publications to the mainframe. It started out with z/OS basics in 2005, which has been updated regularly since then. It serves as a manual for students at universities all over the world. Now it's called 'Introduction to the New Mainframe: z/OS Basics'. And IBM is adding other redbooks in this series. So far they have :
I'm particulary pleased to see the last one being added to the list. I surely would've liked to have that one, back then in 1988. Since then I worked mainly in a z/OS environment, but lately I've been working in a VM/VSE environment again on a 1 day per week basis. So I'm definitely going to read this introduction to catch up on VSE. I wonder if they will also bring out an interactive version of this redbook. I just found out there's an interactive version of the z/OS Basics : 'z/OS Basics : an interactive module'. I found the link on the Community Page of the mainframe charter site.

Wednesday, December 6, 2006

IBM to acquire Consul

On the Consul site we read that "On December 5, 2006, IBM and Consul entered into a definitive agreement for IBM to acquire Consul". On the IBM site, you can find the entire press release.
Consul is a leading provider of compliance and security audit software that helps clients track, report and investigate non-compliant behavior, such as unauthorized activity by information technology administrators or other users.
I know them best for their mainframe products like Consul/RACF but apparantly it's their cross site coverage that makes this company an asset to the IBM products. Or as we find on their site :
"Consul's 20 year history as the leader in audit and compliance software means you can rely on us for the most comprehensive solution available on the market. With the first and only solution for log management, privileged user monitoring and audit (PUMA™), and security audit and compliance reporting across the enterprise, from perimeter to network devices, to applications, databases, operating systems, and the mainframe, the Consul InSight Suite meets your needs to track, report on, and investigate non-compliant behavior.
Consul offers two distinct industry acclaimed product suites:"