IBM Support

Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Platform Cluster Manager Standard Edition, IBM Platform Cluster Manager Advanced Edition, Platform HPC, and Spectrum Cluster Foundation.

Security Bulletin


Summary

There are multiple vulnerabilities in IBM®Runtime Environment Java™Version 7 used by IBM Platform Cluster Manager Standard Edition, IBM Platform Cluster Manager Advanced Edition, Platform HPC, and Spectrum Cluster Foundation. IBM Platform Cluster Manager Standard Edition, IBM Platform Cluster Manager Advanced Edition, Platform HPC, and Spectrum Cluster Foundation have addressed the applicable CVEs.

Vulnerability Details

Refer to the security bulletins(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s)Version(s)
IBM Platform Cluster Manager Advanced Edition4.2.0, 4.2.0.1, 4.2.0.2, 4.2.1
IBM Platform Cluster Manager Standard Edition4.2.0, 4.2.0.1, 4.2.0.2, 4.2.1
IBM Platform HPC4.2.0, 4.2.1

Remediation/Fixes

Product

VRMF

APAR

Remediation/First Fix

Platform Cluster Manager Standard Edition

4.2.0, 4.2.0.1, 4.2.0.2, 4.2.1

None

  1. Download IBM JRE 7.0 x86_64 from the following location: http://www.ibm.com/support/fixcentral by keyword ‘Runtimes for Java Technology’. (For POWER platform, download ppc64 version JRE tar package. The followings steps are using x86_64 as an example.)
  2. Copy the tar package into the management node.  If high availability is enabled, copy the JRE tar package to standby management node, as well.
  3. If high availability is enabled, shutdown standby management node to avoid triggering high availability.
  4. On the management node, stop GUI and PERF services

# pcmadmin service stop --group ALL

  1. On management node, extract new JRE files and replace some old folders with new ones.

# chmod +x ibm-java-x86_64-jre-7.0-10.55.bin

# ./ibm-java-x86_64-jre-7.0-10.55.bin
# mv /opt/pcm/jre/bin /opt/pcm/jre/bin-old
# mv /opt/pcm/jre/lib /opt/pcm/jre/lib-old
# mv /opt/pcm/jre/plugin /opt/pcm/jre/plugin-old
# cp -r ibm-java-x86_64-70/jre/bin /opt/pcm/jre/
# cp -r ibm-java-x86_64-70/jre/lib /opt/pcm/jre/
# cp -r ibm-java-x86_64-70/jre/plugin /opt/pcm/jre/
# mv /opt/pcm/web-portal/jre/linux-x86_64/bin /opt/pcm/web-portal/jre/linux-x86_64/bin-old
# mv /opt/pcm/web-portal/jre/linux-x86_64/lib /opt/pcm/web-portal/jre/linux-x86_64/lib-old
# mv /opt/pcm/web-portal/jre/linux-x86_64/plugin /opt/pcm/web-portal/jre/linux-x86_64/plugin-old
# cp -r ibm-java-x86_64-70/jre/bin /opt/pcm/web-portal/jre/linux-x86_64/
# cp -r ibm-java-x86_64-70/jre/lib /opt/pcm/web-portal/jre/linux-x86_64/
# cp -r ibm-java-x86_64-70/jre/plugin /opt/pcm/web-portal/jre/linux-x86_64/

  1. On management node, start GUI and PERF services

# pcmadmin service start --group ALL

  1. If high availability is enabled, start up standby management node, and replace bin, lib, plugin folders under /opt/pcm/web-portal/jre/linux-x86_64, on standby management node.

Platform Cluster Manager Advanced Edition

4.2.0, 4.2.0.1, 4.2.0.2, 4.2.1

None

Platform HPC 

4.2.0, 4.2.1

None

Spectrum Cluster Foundation

 

 

 

 

 

 

 

 

4.2.2

 

 

 

 

 

 

 

 

None

 

 

 

 

 

 

 

 

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

21 Nov 2019: Initial Publication

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSDV85","label":"Platform Cluster Manager"},"Component":"All","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"4.2.0, 4.2.0.1, 4.2.0.2, 4.2.1","Edition":"All","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
20 December 2019

Initial Publish date:
21 November 2019

UID

ibm11125081