IBM Support

IT07314: FIX TPC 5.X SECURITY VULNERABILITY FOR OPENSSL - CVE-2014-3513, CVE-2014-3567, CVE-2014-3568

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Tivoli Storage Productivity Center is affected by
    vulnerabilities in OpenSSL (CVE-2014-3513, CVE-2014-3567,
    CVE-2014-3568)
    
    TPC versions affected include:
    Tivoli Storage Productivity Center 5.2.0 through 5.2.4.1
    Tivoli Storage Productivity Center 5.1.0 through 5.1.1.5
    Tivoli Storage Productivity Center 4.2.0 through 4.2.2.184
    Tivoli Storage Productivity Center 4.1.x
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * Tivoli Storage Productivity Center 5.2.0 through 5.2.4.1     *
    * Tivoli Storage Productivity Center 5.1.0 through 5.1.1.5     *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * Tivoli Storage Productivity Center is affected by            *
    * vulnerabilities in OpenSSL (CVE-2014-3513, CVE-2014-3567,    *
    * CVE-2014-3568)                                               *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Refer to details in the security bulletin.                   *
    ****************************************************************
    

Problem conclusion

  • Read and follow directions from the security bulletin.
    Security Bulletin: Tivoli Storage Productivity Center is
    affected by vulnerabilities in OpenSSL (CVE-2014-3513,
    CVE-2014-3567, CVE-2014-3568)
    http://www.ibm.com/support/docview.wss?uid=swg21694996
    
    The fix for this APAR is targeted for the following maintenance
    package:
    
    | refresh pack | 5.2-TIV-TPC-RP0005 - March 2015
    | fix pack | 5.1.1-TIV-TPC-FP0006 - March 2015
    
    http://www-01.ibm.com/support/docview.wss?&uid=swg21320822
    
    See APAR IT07318 for TPC 4.x.
    The target dates for future refresh packs do not represent a
    formal commitment by IBM. The dates are subject to change
    without notice.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT07314

  • Reported component name

    TPC

  • Reported component ID

    5608TPC00

  • Reported release

    520

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2015-02-26

  • Closed date

    2015-03-30

  • Last modified date

    2015-03-30

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    IT07318

Modules/Macros

  • SSL
    

Fix information

  • Fixed component name

    TPC

  • Fixed component ID

    5608TPC00

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSWFB4","label":"IBM Spectrum Control Standard Edition"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"520","Line of Business":{"code":"LOB69","label":"Storage TPS"}}]

Document Information

Modified date:
11 September 2024