IBM Support

IBM Cloud Orchestrator Fix Pack 6 (2.5.0.6) for 2.5

Download


Abstract

IBM Cloud Orchestrator 2.5.0.6 has been made generally available and contains fixes to version 2.5.

Download Description

Table of Contents
Sections Description

The Change history section provides an overview on what is new in this release with a description of any new functions or enhancements when applicable.

The How critical is this fix section provides information related to the impact of this release to allow you to assess how your environment may be affected.

The Prerequisites section provides important information to review prior to the installation of this release.

The Download package section provides the direct link to obtain the download package for installation in your environment.

The Installation instructions section provides the installation instructions necessary to apply this release into your environment.

The Known side effects section contains a link to the known problems (open defects) identified at the time of this release.

Supporting Documentation
Document Description

Click to review the detailed system requirements information for a complete list of hardware requirements, supported operating systems, prerequisites and optional supported software, with component-level details and operating system restrictions.

IBM Knowledge Center provides an entry point to product documentation. You can view, browse, and search online information related to the product.

Click to review a complete list of the defects (APARs) resolved in this release including a list of resolved defects for the entire version family.

Prerequisites

Prerequisites include:

Review the Software prerequisites page in the IBM Knowledge Center to ensure your environment meets the minimum hypervisor and operating system requirements, especially if you are upgrading from a previous release of IBM Cloud Orchestrator.

Review the Prerequisites tab in the system requirements report for supported versions of Data Protection and Recovery, Databases and Process Management tools.

Installation Instructions

This fix pack can be installed as a fresh installation or as an upgrade of an existing installation. Follow the instructions in the tabs below.


Fresh installation of IBM Cloud Orchestrator


Step 1: Review the Installing topic in the IBM Knowledge Center.

Upgrade of IBM Cloud Orchestrator from version 2.5 or later


The following upgrade scenarios are supported:

  • IBM Cloud Orchestrator V2.5 -> IBM Cloud Orchestrator V2.5 Fix Pack 6 (2.5.0.6)
  • IBM Cloud Orchestrator V2.5 Fix Pack 1 (2.5.0.1) -> IBM Cloud Orchestrator V2.5 Fix Pack 6
  • IBM Cloud Orchestrator V2.5.0.1 Interim Fix 1 -> IBM Cloud Orchestrator V2.5 Fix Pack 6
  • IBM Cloud Orchestrator V2.5.0.2 Fix Pack 2 (2.5.0.2) -> IBM Cloud Orchestrator V2.5 Fix Pack 6
  • IBM Cloud Orchestrator V2.5.0.2 LA0005 or LA0006 to -> IBM Cloud Orchestrator V2.5 Fix Pack 6
  • IBM Cloud Orchestrator V2.5.0.3 -> IBM Cloud Orchestrator V2.5.0.6
  • IBM Cloud Orchestrator V2.5.0.4 -> IBM Cloud Orchestrator V2.5.0.6
  • IBM Cloud Orchestrator V2.5.0.4 with DirectDriver LA -> IBM Cloud Orchestrator V2.5.0.6
  • IBM Cloud Orchestrator V2.5.0.5 -> IBM Cloud Orchestrator V2.5.0.6

Step 1: Review the Upgrading from IBM Cloud Orchestrator V2.5 topic in the IBM Knowledge Center.

Migration of IBM Cloud Orchestrator from version 2.4.0.2 or later


The following migration scenarios are supported:

  • IBM Cloud Orchestrator V2.4 Fix Pack 2 (2.4.0.2) -> IBM Cloud Orchestrator V2.5 Fix Pack 6 (2.5.0.6)
  • IBM Cloud Orchestrator V2.4 Fix Pack 3 (2.4.0.3) or later -> IBM Cloud Orchestrator V2.5 Fix Pack 6
  • IBM Cloud Orchestrator V2.4 Fix Pack 4 (2.4.0.4) -> IBM Cloud Orchestrator V2.5 Fix Pack 6


  • IBM Cloud Orchestrator V2.4 Fix Pack 5 (2.4.0.5) -> IBM Cloud Orchestrator V2.5 Fix Pack 6

  • Step 1: Review the Migrating from IBM Cloud Orchestrator V2.4.0.2 or later topic in the IBM Knowledge Center.


    Step 2: If you are migrating from an IBM Cloud Orchestrator 2.4.0.2 (or later) environment, review the During Migration and After Migration sections and apply the steps appropriate for your setup.

    Note: All references to version 2.4.0.4 also apply to version 2.4.0.5 or later.


    During Migration

    SQL0964C error message

    During migration the following message might be displayed:

    SQL0964C  The transaction log for the database is full.  SQLSTATE=57011

    To solve this problem, clear the transaction logs.


    After Migration

    Creating actions

    If you added an action to a predefined toolkit in the IBM Cloud Orchestrator 2.4.0.2 environment and the action was not migrated in the IBM Cloud Orchestrator 2.5.0.6 environment, create the action manually by following the procedure described in Creating an action.


    Download Package

    -->
    Download options
    Access type Description

    Passport Advantage and Passport Advantage Express clients are required to sign in to download the software package.

    If you are entitled for IBM Cloud Orchestrator Enterprise Edition and need to download your software from Passport Advantage, perform the following steps:

    1. Logon to Passport Advantage.
    2. Select Software Downloads and Media Access.
    3. Select the Download Finder.
    4. Select Find by description or part number.
    5. Select the Product Description and All radio buttons and enter IBM Cloud Orchestrator Enterprise Edition in the description field.
    6. Select Continue.
    7. Expand the eAssemblies and you will see your entitled software.

    Review eAssemblies Parts List for a list of part numbers you can download for this product.

    IBM Software Group OEM offerings are designed for partners who develop and sell business solutions with embedded or bundled IBM middleware software. Clients with Flexible Contract Type (FCT) license purchases and IBM Business Partners must sign in to download the software package.

    Click the HTTP link below to obtain the release from Fix Central.

    Image directory contents

    • 2.5.0-CSI-ICO-FP0006.tgz: IBM Cloud Orchestrator Version 2.5 Fix Pack 6 for Red Hat Enterprise Linux Multilingual
    • 2.1.0.6-SCCM-IFIX03.tar: IBM SmartCloud Cost Management 2.1 Fix Pack 6 ifix03

    How critical is this fix?

    Impact Assessment
    Impact Description

    Corrective

    This is a maintenance release. It contains fixes for client-reported and internally found defects.

    • CVE-2013-0340, CVE-2013-0341 - Open Source James Clark Expat Vulnerabilities
    • CVE-2016-8919 - WebSphere deserialization of untrusted data (SOAP Connector)
    • CVE-2017-3514, CVE-2017-3512, CVE-2017-3511, CVE-2017-3526, CVE-2017-3509, CVE-2017-3544, CVE-2017-3533, CVE-2017-3539, CVE-2017-1289, CVE-2016-9840, CVE-2016-9841, CVE-2016-9842, CVE-2016-9843, CVE-2017-1289, CVE-2017-3512, CVE-2017-3511 - Multiple vulnerabilities may affect IBM® SDK, Java™ Technology Edition April 2017
    • CVE-2017-1151 - Privilege escalation in WAS OIDC
    • CVE-2016-0360 - Deserialization RCE vulnerability in IBM WebSphere JMS Client
    • CVE-2017-3289 CVE-2017-3272 CVE-2017-3241 CVE-2017-3260 CVE-2016-5546 CVE-2017-3253 CVE-2016-5548 CVE-2016-5549 CVE-2017-3252 CVE-2016-5547 CVE-2016-5552 CVE-2017-3261 CVE-2017-3231 CVE-2017-3259 CVE-2016-2183 - IBM SDK, Java Technology Edition Quarterly CPU - Jan 2017 - Includes Oracle Jan 2017 CPU
    • CVE-2016-7103 - jquery-ui Vulnerabilities Web Services Client security Bindings could be weaker than expected in WAS
    • CVE-2017-1501 - Web Services Client security Bindings could be weaker than expected in WAS
    • CVE-2017-1425 - Cross-site scripting vulnerability in IBM Business Process Manager (BPM)
    • CVE-2017-7679, CVE-2017-7668, CVE-2017-3167 - Apache HTTP Server Vulnerabilities
    • CVE-2017-1382 - WAS may have insecure permissions when custom startup scripts are used
    • CVE-2016-2183 - IBM® DB2® LUW is vulnerable to Sweet32 Birthday Attack
    • CVE-2017-1150 - Information Disclosure vulnerability affects IBM® DB2® LUW
    • CVE-2017-1140 - Persistent cross-site scripting vulnerability in IBM Business Process Manager
    • CVE-2017-1121 - Cross-site scripting vulnerability in WebSphere Application Server Admin Console

    Test Results

    Definitions

    Regression: An error in the Maintenance Delivery Vehicle (MDV) that produces incorrect or unexpected behavior causing a supported feature to stop functioning as designed.
    This includes:

    • Coding errors that cause a regression
    • Documentation or packaging problems that cause a regression
    • Errors reported in a new function delivered in a MDV that cause a regression

    Incomplete: An error in the MDV has not regressed, but does not work as designed.
    This includes:

    • Fixed APARs which did not solve the original problem but did not break anything new
    • APARs reporting documentation errors, such as readme errors, that cause problems applying an MDV but do not lead to a regression


    Notes:
    • Regression and incomplete APARs are considered fix-in-error or MDV-in-error
    • Definitions above apply only to valid APARs that result in product fixes (APARs returned as working-as-designed are not assessed for being fix-in-error)
    • Issues in major releases due to new functionality do not apply in this definition

    There are no known regressions to report.

    Known Side Effects

    Review the following list of known issues and open defects:

    Review the Known errors and limitations section of the IBM Knowledge Center for issues related to this release.

    Open defects

    Review the following list of open defects for IBM Cloud Orchestrator on the IBM Support Portal.

    Change History

    <!-- EDIT TEXT IN BLUE --><a name="ABOUT"></a>]

    What's new

    For information about the new features and enhancements, review the What is new in this release topic in the IBM Knowledge Center.

    Click the link in the Download Options column:

    Off
    [{"DNLabel":"IBM Cloud Orchestrator 2.5 fixes","DNDate":"27 Apr 2018","DNLang":"English","DNSize":"20995473276","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7ETivoli&product=ibm/Tivoli/IBM+SmartCloud+Orchestrator&release=2.5.0&platform=All&function=all","DNURL_FTP":" ","DDURL":null}]
    [{"Product":{"code":"SS4KMC","label":"IBM SmartCloud Orchestrator"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"Installation","Platform":[{"code":"PF016","label":"Linux"}],"Version":"2.5.0.6","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

    Document Information

    Modified date:
    22 June 2018

    UID

    swg2C4000066