IBM Support

IT30175: SMB SIGNING IS NOT REQUIRED ON VSNAP PORT 445

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • SMB is used for application log backups for Micorosft SQL and
    Exchange and listen on port 445 on vSnap. Because the SMB
    signing is not required, it may cause vulnerabilities scan
    failure.
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * IBM Spectrum Protect Plus level 10.1.4.                      *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * See Error Description.                                       *
    * For more information, refer to the security bulletin         *
    * published at this link:                                      *
    * https://www.ibm.com/support/pages/node/1107195               *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Apply fixing level when available. This problem is currently *
    * projected to be fixed in IBM Spectrum Protect Plus level     *
    * 10.1.5. Note that this is subject to change at the           *
    * discretion of IBM.                                           *
    ****************************************************************
    

Problem conclusion

  • The default SMB server configuration on vSnap was set to offer
    SMB signing but it was not mandatory. Clients servers had the
    option to skip signing. As of IBM Spectrum Protect Plus level
    10.1.5, the default configuration has been updated to ensure
    that SMB signing is now mandatory for any clients that attempt
    to connect to the vSnap server.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT30175

  • Reported component name

    SP PLUS

  • Reported component ID

    5737SPLUS

  • Reported release

    A14

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-09-04

  • Closed date

    2019-10-21

  • Last modified date

    2020-02-17

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    SP PLUS

  • Fixed component ID

    5737SPLUS

Applicable component levels

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSNQFQ","label":"IBM Spectrum Protect Plus"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"A14","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
30 January 2024