Readme File for IBM® Spectrum Symphony 7.2.0.2 Interim Fix 600108

Readme file for: IBM Spectrum Symphony

Product Release: 7.2.0.2

Update Name: Interim Fix 600108

Fix ID: sym-7.2.0.2-build600108

Publication date: Jan 18, 2021

This interim fix provides instructions on upgrading Apache Ant to 1.10.9 in IBM Spectrum Symphony 7.2.0.2 to address security vulnerability CVE-2020-11979.

Contents

1. List of fixes

2. Download location

3. Product and components affected

4. Installation and configuration

5. Uninstallation

6. List of files

7. Product notifications

8. Copyright and trademark information

 

1.    List of fixes

APAR: P104029

2.    Download location

Download interim fix 600108 from the following location: http://www.ibm.com/eserver/support/fixes/

3.    Product and components affected

Component name, Platform, Fix ID:

PMC/PERF/REST, Linux x86_64, sym-7.2.0.2-build600108

4.    Installation and configuration

Follow the instructions in this section to download and install this interim fix to your cluster.

System requirements

Linux x86_64

Installation

a.      Log on to the primary host as the cluster administrator and stop the WEBGUI, REST, purger, and plc services:

> source profile.platform

> egosh user logon -u Admin -x Admin

> egosh service stop WEBGUI REST purger plc

b.      Log on to each management host in the cluster and move the following file to a backup directory for recovery purposes, for example:

> mkdir -p /tmp/ant_bk

> mv $EGO_TOP/perf/3.6/lib/ant-1.9.2.jar /tmp/ant_bk

c.       On each management host, download the sym-7.2.0.2_x86_64_build600108.tar.gz package and extract its contents to the top-level installation directory:

> tar zxof sym-7.2.0.2_x86_64_build600108.tar.gz -C $EGO_TOP

d.      Delete all subdirectories and files in the following directories:

> rm -rf $EGO_TOP/gui/work/*

> rm -rf $EGO_TOP/gui/workarea/*

> rm -rf $EGO_TOP/kernel/rest/workarea/*

Note: If you configured the WLP_OUTPUT_DIR parameter and APPEND_HOSTNAME_TO_WLP_OUTPUT_DIR is set to true in the $EGO_CONFDIR/conf/wlp.conf file, you must clean up the $WLP_OUTPUT_DIR/webgui_hostname/gui/workarea/ directory.

e.      Launch your browser and clear the browser cache.

f.        From the primary host, start the WEBGUI, REST, purger, and plc services:

> source profile.platform

> egosh service start WEBGUI REST purger plc

5.    Uninstallation

If required, follow the instructions in this section to uninstall this interim fix from your cluster:

a.      Log on to the primary host as the cluster administrator and stop the WEBGUI, REST, purger, and plc services:

> source profile.platform

> egosh user logon -u Admin -x Admin

> egosh service stop WEBGUI REST purger plc

b.      On each management host, remove the following file that were introduced by this interim fix:

> rm -f $EGO_TOP/perf/3.6/lib/ant-1.10.9.jar

c.       Log on to each management host as the cluster administrator, restore the file that you backed up during installation:

> mv /tmp/ant_bk/ant-1.9.2.jar $EGO_TOP/perf/3.6/lib/

d.      Delete all subdirectories and files in the following directories:

> rm -rf $EGO_TOP/gui/work/*

> rm -rf $EGO_TOP/gui/workarea/*

> rm -rf $EGO_TOP/kernel/rest/workarea/*

Note: If you configured the WLP_OUTPUT_DIR parameter and APPEND_HOSTNAME_TO_WLP_OUTPUT_DIR is set to true in the $EGO_CONFDIR/conf/wlp.conf file, you must clean up the $WLP_OUTPUT_DIR/webgui_hostname/gui/workarea/ directory.

e.      Launch your browser and clear the browser cache.

f.        From the primary host, start the WEBGUI, REST, purger, and plc services:

> source profile.platform

> egosh service start WEBGUI REST purger plc

6.    List of files

68c175612534e304b64b3780e17ae811 sym-7.2.0.2_x86_64_build600108.tar.gz

92251abf72cdcededfad473cc40dcbe2 perf/3.6/lib/ant-1.10.9.jar

7.    Product notifications

To receive information about product solution and patch updates automatically, subscribe to product notifications on the My Notifications page http://www.ibm.com/support/mynotifications/ on the IBM Support website (http://support.ibm.com). You can edit your subscription settings to choose the types of information you want to get notification about, for example, security bulletins, fixes, troubleshooting, and product enhancements or documentation changes.

8.    Copyright and trademark information

© Copyright IBM Corporation 2021

U.S. Government Users Restricted Rights - Use, duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp.

IBM®, the IBM logo, and ibm.com® are trademarks of International Business Machines Corp., registered in many jurisdictions worldwide. Other product and service names might be trademarks of IBM or other companies. A current list of IBM trademarks is available on the Web at "Copyright and trademark information" at www.ibm.com/legal/copytrade.shtml.