IBM Support

IT17363: INSTRUMENTATION LOG FILE DISPLAYS PASSWORD USED BY 'SET PASSWORD' CLIENT COMMAND

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • When running the client command "set password", the full text of
    the command and included password is written to the
    instrumentation log file if instrumentation tracing is enabled.
    For 7.1.6 and higher, instrumentation tracing is enabled by
    default but can be disabled by using the ENABLEINSTRUMENTATION
    NO setting.  Prior to 7.1.6, instrumentation tracing was enabled
    using the INSTRUMENT:* testflag.
    
    
    
    
    IBM Spectrum Protect versions affected:
    Client 6.3 and higher on all supported platforms
    
    
    
    
    Initial Impact: Medium
    
    Additional Keywords:  TSM instrumentation password display
    

Local fix

  • For 7.1.6 and higher, set the client option
    ENABLEINSTRUMENTATION to NO in dsm.opt (Windows) or dsm.sys
    (UNIX and Linux).  For versions lower than 7.1.6, remove the
    INSTRUMENT:* test flag from dsm.opt (Windows) or dsm.sys (UNIX
    and Linux).
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * Tivoli Storage Manager Backup-archive command line clients   *
    * of version 6.3 and higher running on all platforms           *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * See ERROR DESCRIPTION                                        *
    * For more information, refer to the security bulletin at this *
    * link:                                                        *
    * http://www.ibm.com/support/docview.wss?uid=swg21998166       *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Apply fixing level when available. This problem is currently *
    * projected to be fixed in level 7.1.6.5 and 6.4.3.5. Note     *
    * that this is subject to change at the discretion of IBM.     *
    ****************************************************************
    

Problem conclusion

  • The problem has been fixed: "set password" command is handled in
    a special way now so that password is not printed out to the
    instrumentation log file any more.
    

Temporary fix

Comments

  • *
    

APAR Information

  • APAR number

    IT17363

  • Reported component name

    TSM CLIENT

  • Reported component ID

    5698ISMCL

  • Reported release

    71W

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2016-10-05

  • Closed date

    2016-11-11

  • Last modified date

    2017-05-01

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Modules/Macros

  • dsmc
    

Fix information

  • Fixed component name

    TSM CLIENT

  • Fixed component ID

    5698ISMCL

Applicable component levels

  • R71A PSY

       UP

  • R71H PSY

       UP

  • R71L PSY

       UP

  • R71M PSY

       UP

  • R71S PSY

       UP

  • R71W PSY

       UP

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSGSG7","label":"Tivoli Storage Manager"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"71W","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
01 May 2017