MH01548
08/12/15
|
Security Fixes
- Fixed multiple Java vulnerabilities:
CVE-2015-4733, CVE-2015-4732, CVE-2015-2590,
CVE-2015-4731, CVE-2015-4748, CVE-2015-2664,
CVE-2015-2621, CVE-2015-2601, CVE-2015-4749,
CVE-2015-2625, and CVE-2015-1931
- Fixed Kerberos vulnerabilities: CVE-2014-5353
and CVE-2014-5355
- Fixed multiple openssl vulnerability:
CVE-2014-8176, CVE-2015-1788, CVE-2015-1789,
CVE-2015-1790, CVE-2015-1791, CVE-2015-1792, and
CVE-2015-3216
- Fixed NTP vulnerabilities: CVE-2015-1799 and
CVE-2015-3405
General fixes
- Updated description for 5767 incorrect on HMC
SX instead of TX.
- Fixed issue of Backup CCD failed with HSCP0200.
- Fixed issue of bkconsdata over nfs to NFSv4
server fails.
- Fixed issue of CEC going in recovery due to IOR
lpar not defined in save area.
|
MH01536
07/14/15
|
Known Issues:
- The install may fail on HMCs that have a
certificate signed with a weak signature
algorithm. Users can verify the HMC
Certificate Signature Algorithm and update the
certificate if needed prior to installing this
PTF. For further information and instructions on
preventing or resolving the issue
see:
http://www.ibm.com/support/docview.wss?uid=nas8N1020801
- Beginning June 30, 2015, a new server is
required for customers using Electronic Service
Agent on the HMC to Call Home to IBM. Ensure
any external firewall allows https connection to
new server IP 129.42.50.224. For a list of
all required IP addresses and ports see the
whitepaper "ESA for HMC Connectivity Security for
IBM POWER6, POWER7 and POWER8 Processor-Based
Systems and IBM Storage Systems DS8000" available
at:
http://www-01.ibm.com/support/esa/security.htm
Security Fixes
- Fixed multiple Java vulnerabilities:
CVE-2015-0480, CVE-2015-0486, CVE-2015-0488,
CVE-2015-0478, CVE-2015-0477, CVE-2015-1916
- Fixed httpd and openssl "Logjam" vulnerability:
CVE-2015-4000
- Fixed Multiple Heap Buffer Overflow, "Zero Day",
Vulnerabilities: CVE-2014-8139 CVE-2014-8140
CVE-2014-8141, CVE-2014-9636
- Fixed a potential security issue with viosvrcmd.
General fixes
- Updated the code signing certificate for the
vterm applet.
|
MH01518
05/07/2015 |
Security Fixes
- Fixed multiple vulnerabilities in OpenSSL:
CVE-2015-0207, CVE-2015-0208, CVE-2015-0209,
CVE-2015-0285, CVE-2015-0286, CVE-2015-0287,
CVE-2015-0288, CVE-2015-0289, CVE-2015-0292,
CVE-2015-0293, CVE-2015-1787
- Fixed multiple vulnerabilities in Tomcat:
- CVE-2014-0075, CVE-2014-0095, CVE-2014-0096,
CVE-2014-0099, CVE-2014-0119
- Fixed multiple vulnerabilities in glibc:
CVE-2013-7423, CVE-2014-7817, CVE-2014-9402,
CVE-2015-1472
- Fix for RC4 stream cipher "Bar Mitzvah"
vulnerability: CVE-2015-2808
General fixes
- Fixed an issue with Leap Second, where HMC could
encounter a system hang or performance degradation
after the leap second is added at the end of June
30th 2015.
- RC4 based ciphers have been disabled.
|
MH01504
04/06/2015
|
Security Fixes
- CVE-2015-0204, CVE-2015-0138 (Freak)
General fixes
- Fixed a problem where HMC was enabling weak
ciphers that were not in the lshmcencr enabled
cipher list.
|
MH01511
03/17/2015 |
- Fixed a problem that can cause errors with
PowerVC and the enhanced GUI tasks.
|
MH01502
03/09/2015
|
Securityfixes
- Fixed multiple vulnerabilities in Network Time
Protocol (NTP): (CVE-2014-9293, CVE-2014-9294,
CVE-2014-9295, CVE-2014-9297, CVE-2014-9298)
- Fixed multiple vulnerabilities in IBM Java SDK:
(CVE-2015-0410, CVE-2014-6593)
General fixes
- Fixed an issue where the java applet causes the
HMC console to stop responding to input when a
vterm is open for a long time and/or when F10 is
pressed in the vterm
- Fixed an issue where launching ASM to POWER5
systems in failed authentication state would
result in a blank screen.
|
MH01458
02/12/2015 |
Security Fixes
- NTP security fix for CVE-2014-9295
- Fixed a problem where the HMC local login's
browser session attempts to connect to external,
non-IBM IP addresses.
- Fix for GNU C library (glibc) vulnerability that
has been referred to as GHOST: CVE-2015-0235
- openssl security fixes for: CVE-2014-3570,
CVE-2014-3571, CVE-2014-3572, CVE-2045-8275,
CVE-2014-3569, CVE-2015-0205, CVE-2015-0206
General Fixes
- Updated mkprofdata manpages
- Fixed a problem where custom groups may be
removed when HMC is rebooted.
- Fixed a problem where mkprofdata command was
unable to recover partition data successfully
leaving system in recovery.
- Fixed a problem where chlparutil -s command has
no effect on sample rate
- Fixed a problem where HMC Master/Slave
replication may fail.
- Fixed a problem where problem analysis for a
server or frame may stop causing service events to
not be reported
- Fixed a problem where ASM task failed to connect
to POWER5 servers.
- Corrected wording for IBM i partitions on
performance panel.
- Fixed a problem where HMC incorrectly allowed
8205-E6C to upgrade to an unsupported firmware
level.
- Fixed a problem where HMC reboot hangs at
initializing or boots but fails to list any
servers
- Fixed an issue where after an HMC upgrade,
lshmcencr may list no active ciphers with weak
ciphers enabled on the web GUI.
|