ADSM-L

New TSM (Server) Flash #10254

2003-10-31 19:34:38
Subject: New TSM (Server) Flash #10254
From: Sam Giallanza <giallanz AT US.IBM DOT COM>
To: ADSM-L AT VM.MARIST DOT EDU
Date: Fri, 31 Oct 2003 17:33:57 -0700
TSM Community,

Please see the new Flash text below.

Registration to "My Support page"  will automate the Flash notification
information you are now receiving.

Flash 10254 Text:





  Abstract: Users can view the server console without authentication with
  the server.







 Problem: Users can view the server console without authentication with the
 server.

 Who is Affected: Tivoli Storage Manager servers prior to version 5.1.8.0
 and 5.2.1.2 on all platforms.

 Recommendation: Update the server to the patch or PTF level which includes
 APAR IC37554 for your server version when it is available. This APAR is
 included in 5.1.8.0 and 5.2.1.2 (all supported server platforms), 4.2.4.2
 for MVS, and 3.1.2.111 for VM. VM customers will need to call IBM for the
 password to the FTP site as the password in the previous README is no
 longer correct.

 Conclusion: Under limited circumstance, the server may allow a user to
 view the server console without requesting user's credentials. Please
 follow the above recommendations to protect your server.






 Security Flash #10254

 http://www.ibm.com/support/techdocs/atsmastr.nsf/WebIndex/FLASH10254

 http://partners.boulder.ibm.com/src/atsmastr.nsf/WebIndex/FLASH10254







Cordially,

Sam J. Giallanza
Tivoli Certified Consultant
Field Issues Manager
Field Input Communications (FIC)
giallanz AT us.ibm DOT com
520.799.5512 - T/L 321.5512

Our new web Support site and KB is at :

http://www-3.ibm.com/software/sysmgmt/products/support/IBMTivoliStorageManager.html

<Prev in Thread] Current Thread [Next in Thread>
  • New TSM (Server) Flash #10254, Sam Giallanza <=