IBM Support

Announcing IBM Support Assistant Team Server 5.0.2.6 (Update)

News


Abstract

The IBM® Support Assistant Team Server 5.0.2.6 (Update) is now available for installation. This update contains fixes and notices to address security vulnerabilities

Content

Below is a list of highlights and installation directions for IBM Support Assistant Team Server 5.0.2.6 (Update). If you have questions or problems, please post them to the IBM Support Assistant forum.



System Requirements
With the introduction of 5.0.1.1 and above updates for IBM Support Assistant Team Server, you must be at a minimum of IBM Installation Manager 1.8 or higher in order to apply these updates to the IBM Support Assistant Team Server.

Back

Update List
IBM Support Assistant Team Server 5.0.2.6 provides updates and fixes multiple vulnerabilities

The "Memory Analyzer [Web]" tool has been removed beginning with the previous ISA 5.0.2.5 release. "Memory Analyzer [Report]" and "Memory Analyzer [Desktop]" can be used as an alternative to the Web edition of the tool.


IBM Support Assistant has addressed vulnerabilities in IBM® Runtime Environment Java™ Version 1.8.0 used by IBM Support Assistant Team Server.

The issues below were disclosed as part of the IBM Java SDK updates in October 2017.

Vulnerability (CVE-2017-10295) An unspecified vulnerability related to the Java SE Networking component could allow an unauthenticated attacker to cause no confidentiality impact, low integrity impact, and no availability impact.

Vulnerability (CVE-2017-10355) An unspecified vulnerability related to the Java SE Networking component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.

Vulnerability (CVE-2017-10356) An unspecified vulnerability related to the Java SE Security component could allow an unauthenticated attacker to obtain sensitive information resulting in a high confidentiality impact using unknown attack vectors.

The issues below were disclosed as part of the IBM Java SDK updates in January 2018.

Vulnerability (CVE-2018-2579) An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded, JRockit Libraries component could allow an unauthenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors.

Vulnerability (CVE-2018-2602) An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded I18n component could allow an unauthenticated attacker to cause low confidentiality impact, low integrity impact, and low availability impact.

Vulnerability (CVE-2018-2603) An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded, JRockit Libraries component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.

Vulnerability (CVE-2018-2633) An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded, JRockit JNDI component could allow an unauthenticated attacker to take control of the system.

Back

Applying this update
Updating IBM Support Assistant Team Server with Installation Manager:

*Important update: Please verify that you are using IBM Installation Manager 1.8 or higher before attempting to apply updates to IBM Support Assistant Team Server or its associated problem determination tools.
  1. Start IBM Installation Manager.
  2. Select Update from the IBM Installation Manager panel.
  3. Select the IBM Support Assistant package group, then click Next.
  4. Select the package and version you would like to update, then click Next.
  5. Read and accept the license terms then click Next.
  6. Confirm the problem determination tool or update you want to apply, then click Next.
  7. Review the update summary and click Update.
  8. After the update completes, click Finish and close IBM Installation Manager.

Note that only IBM Installation Manager installations of IBM Support Assistant Team Server will be able to apply fix packs and updates or install and update problem determination tools. For the stand-alone IBM Support Assistant Team Server repository and compressed all-in-one file installations, see the IBM Support Assistant Team Server page to download replacement file containing IBM Support Assistant Team Server 5.0.2.6 updates.
Back

[{"Product":{"code":"SSLLVC","label":"IBM Support Assistant"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"Team Server","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"5.0.2.4;5.0.2.3;5.0.2.2;5.0.2.1;5.0.2.0;5.0.1.1;5.0.1.0;5.0;5.0.2.5;5.0.2.6","Edition":"TeamServer","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
15 June 2018

UID

swg22015212