MH01549
08/12/15
|
Security Fixes
- Fixed multiple Java vulnerabilities:
CVE-2015-4733, CVE-2015-4732, CVE-2015-2590,
CVE-2015-4731, CVE-2015-4748, CVE-2015-2664,
CVE-2015-2621, CVE-2015-2601, CVE-2015-4749,
CVE-2015-2625, and CVE-2015-1931
- Fixed Kerberos vulnerabilities: CVE-2014-5353 and
CVE-2014-5355
- Fixed multiple openssl vulnerability:
CVE-2014-8176, CVE-2015-1788, CVE-2015-1789,
CVE-2015-1790, CVE-2015-1791, CVE-2015-1792, and
CVE-2015-3216
- Fixed NTP vulnerabilities: CVE-2015-1799 and
CVE-2015-3405
General fixes
- Fixed issue of bkconsdata over nfs to NFSv4
server fails.
- Fixed issue of CEC going in recovery due to IOR
lpar not defined in save area
|
MH01537
07/14/15
|
Known Issues:
- The install may fail on HMCs that have a
certificate signed with a weak signature
algorithm. Users can verify the HMC
Certificate Signature Algorithm and update the
certificate if needed prior to installing this PTF.
For further information and instructions on
preventing or resolving the issue see:
http://www.ibm.com/support/docview.wss?uid=nas8N1020801
- Beginning June 30, 2015, a new server is required
for customers using Electronic Service Agent on the
HMC to Call Home to IBM. Ensure any external
firewall allows https connection to new server IP
129.42.50.224. For a list of all required IP
addresses and ports see the whitepaper "ESA for
HMC Connectivity Security for IBM POWER6, POWER7
and POWER8 Processor-Based Systems and IBM Storage
Systems DS8000" available at:
http://www-01.ibm.com/support/esa/security.htm
Security Fixes
- Fixed multiple Java vulnerabilities:
CVE-2015-0480, CVE-2015-0486, CVE-2015-0488,
CVE-2015-0478, CVE-2015-0477, CVE-2015-1916
- Fixed httpd and openssl "Logjam" vulnerability:
CVE-2015-4000
- Fixed Multiple Heap Buffer Overflow, "Zero Day",
Vulnerabilities: CVE-2014-8139 CVE-2014-8140
CVE-2014-8141, CVE-2014-9636
- Fixed a potential security issue with viosvrcmd.
General fixes
- Updated the code signing certificate for the
vterm applet.
- Fixed an issue where the server will go to an
incomplete state if a user creates a new virtual
network with a name that conflicts with
auto-generated network names.
|
MH01519
05/07/2015 |
Security Fixes
- Fixed multiple vulnerabilities in OpenSSL:
CVE-2015-0207, CVE-2015-0208, CVE-2015-0209,
CVE-2015-0285, CVE-2015-0286, CVE-2015-0287,
CVE-2015-0288, CVE-2015-0289, CVE-2015-0292,
CVE-2015-0293, CVE-2015-1787
- Fixed multiple vulnerabilities in Tomcat:
- CVE-2014-0075, CVE-2014-0095, CVE-2014-0096,
CVE-2014-0099, CVE-2014-0119
- Fixed multiple vulnerabilities in glibc:
CVE-2013-7423, CVE-2014-7817, CVE-2014-9402,
CVE-2015-1472
- Fix for RC4 stream cipher "Bar Mitzvah"
vulnerability: CVE-2015-2808
Includes CVEs fixed earlier:
- CVE-2014-3569, CVE-2014-3570, CVE-2014-3571,
CVE-2014-3572, CVE-2014-8275, CVE-2015-0205,
CVE-2015-0206
General fixes
- Fixed an issue with Leap Second, where HMC could
encounter a system hang or performance degradation
after the leap second is added at the end of June
30th 2015.
- RC4 based ciphers have been disabled.
|
MH01505
04/06/2015
|
Security Fixes
Includes CVEs fixed earlier:
- CVE-2014-3569, CVE-2014-3570, CVE-2014-3571,
CVE-2014-3572, CVE-2014-8275, CVE-2015-0205,
CVE-2015-0206
General fixes
- Fixed a problem where HMC was enabling weak
ciphers that were not in the lshmcencr enabled
cipher list.
|