Readme File for IBM® Spectrum Symphony 7.3.1 Interim Fix 601120

Readme File for: IBM Spectrum Symphony

Product Release: 7.3.1

Update Name: Interim Fix 601120

Fix ID: sym-7.3.1-build601120

Publication Date: May 27, 2022

This interim fix upgrades Spring Framework to version 5.2.20 to resolve security vulnerability CVE-2022-22965 for IBM Spectrum Symphony 7.3.1 on Windows.

Contents

1. List of fixes

2. Download location

3. Product and components affected

4. Installation and configuration

5. Uninstallation

6. List of files

7. Product notifications

8. Copyright and trademark information

1.    List of fixes

APAR: P104643

2.    Download location

Download interim fix 601120 from the following location https://www.ibm.com/eserver/support/fixes/

3.    Products and components affected

Component name, Platform, Fix ID:

PMC and HostFactory, Windows x86_64, sym-7.3.1-build601120

4.    Installation and configuration

System requirements

Windows x86_64

Installation

a.     Log on to the primary host as the cluster administrator and stop the WEBGUI and HostFactory services:

> egosh service stop WEBGUI HostFactory

b.     Log on to each management host in the cluster, copy the sym-7.3.1.0-egomgmt-3.9.0.0_build601120.msp and sym-7.3.1.0-hfcore-1.1.0.0_build601120.msp packages, and complete one of the following steps:

o   To perform an interactive installation, double-click the .msp package.

o   To perform a silent installation from the IBM Spectrum Symphony command line, enter the following command:

C:\>msiexec /update C:\sym-7.3.1.0-egomgmt-3.9.0.0_build601120.msp /l*v updateSym.log /norestart /quiet REINSTALLMODE=omus

C:\>msiexec /update C:\sym-7.3.1.0-hfcore-1.1.0.0_build601120.msp /l*v updateSym.log /norestart /quiet REINSTALLMODE=omus

The command syntax is as follows:

C:\>msiexec /update sym_package_name_path /l*v sym_install_log /norestart /quiet REINSTALLMODE=omus

where:

o   sym_package_name_path> is the fully qualified path to the .msp package.

o   sym_install_log is the log file for the upgrade.

c.     Delete all subdirectories and files in the following directories:

%SOAM_HOME%\..\gui\work\*

%SOAM_HOME%\..\gui\workarea\*

d.     Clear your browser cache. 

e.     Start the WEBGUI and HostFactory services:

> egosh service start WEBGUI HostFactory

5.    Uninstallation

If required, follow the instructions in this section to uninstall this interim fix from your cluster:

a.     Log on to the primary host as the cluster administrator and stop the WEBGUI and HostFactory services:

> egosh service stop WEBGUI HostFactory

b.     Roll back to the previous version of IBM Spectrum Symphony either from the Windows Control Panel or from the IBM Spectrum Symphony command line:

o   To roll back from the Windows Control Panel, go to Control Panel > Programs and Features > View installed updates, click Update for Symphony 7.3.1.0 (build"601120") and click Uninstall.

o   To roll back from the IBM Spectrum Symphony command line, enter the following command:

C:\>msiexec /uninstall {BFA35217-E07D-43AC-A954-3152633A98A9} /package {3DF0C336-AE25-4C34-BCDE-CC3407244B49} /norestart /quiet /l*v sym_rollback.log

C:\>msiexec /uninstall {DDAE26A9-E331-4AF7-88A5-312E87E9F30F} /package {7B8E3BD1-7B63-4B11-A1F4-C9718062F1F8} /norestart /quiet /l*v sym_rollback.log

The command syntax is as follows:

C:\>msiexec /uninstall interim_fix_code /package product_code /norestart /quiet /l*v rollback_log

where:

o   interim_fix_code is the identifier of the .msp package for the interim fix; in this case, {BFA35217-E07D-43AC-A954-3152633A98A9} and {DDAE26A9-E331-4AF7-88A5-312E87E9F30F}.

o   product_code is the identifier of the .msi file in the product installation package; in this case, {3DF0C336-AE25-4C34-BCDE-CC3407244B49} and {7B8E3BD1-7B63-4B11-A1F4-C9718062F1F8}.

o   rollback_log is the name of the log file to capture details of the interim fix rollback; in this case, sym_rollback.log.

c.     Delete all subdirectories and files in the following directories:

%SOAM_HOME%\..\gui\work\*

%SOAM_HOME%\..\gui\workarea\*

d.     Clear your browser cache. 

e.     Start the WEBGUI and HostFactory services:

> egosh service start WEBGUI HostFactory

6.    List of fixes

gui\3.9\lib\spring-beans-5.2.20.RELEASE.jar

gui\3.9\lib\spring-context-5.2.20.RELEASE.jar

gui\3.9\lib\spring-core-5.2.20.RELEASE.jar

gui\3.9\lib\spring-expression-5.2.20.RELEASE.jar

gui\3.9\lib\spring-web-5.2.20.RELEASE.jar

gui\3.9\lib\spring-aop-5.2.20.RELEASE.jar

gui\3.9\lib\spring-context-support-5.2.20.RELEASE.jar

gui\3.9\lib\spring-jdbc-5.2.20.RELEASE.jar

gui\3.9\lib\spring-orm-5.2.20.RELEASE.jar

gui\3.9\lib\spring-test-5.2.20.RELEASE.jar

gui\3.9\lib\spring-tx-5.2.20.RELEASE.jar

gui\3.9\lib\spring-webmvc-5.2.20.RELEASE.jar

hostfactory\1.1\providerplugins\common\lib\spring-beans-5.2.20.RELEASE.jar

hostfactory\1.1\providerplugins\common\lib\spring-core-5.2.20.RELEASE.jar

7.    Product notifications

To receive information about product solution and patch updates automatically, subscribe to product notifications on the My Notifications page http://www.ibm.com/support/mynotifications/ on the IBM Support website (http://support.ibm.com). You can edit your subscription settings to choose the types of information you want to get notification about, for example, security bulletins, fixes, troubleshooting, and product enhancements or documentation changes. 

8.    Copyright and trademark information

© Copyright IBM Corporation 2022

U.S. Government Users Restricted Rights - Use, duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp.

IBM®, the IBM logo, and ibm.com® are trademarks of International Business Machines Corp., registered in many jurisdictions worldwide. Other product and service names might be trademarks of IBM or other companies. A current list of IBM trademarks is available on the Web at "Copyright and trademark information" at www.ibm.com/legal/copytrade.shtml.