IBM Support

Security Bulletin: A security vulnerability has been identified in an IBM Tivoli Monitoring shared component shipped with IBM Application for Smart Business [IAMSB] / Tivoli Foundations Application Manager [TFAM] (CVE-2014-0963).

Created by Vijay S on

Security Bulletin


Summary

An IBM Tivoli Monitoring shared component is included as part of IBM Application for Smart Business [IAMSB] / Tivoli Foundations Application Manager [TFAM]. Information about a security vulnerability affecting an IBM Tivoli Monitoring shared component has been published in a security bulletin.

Vulnerability Details

Please consult the ITM Security bulletin for vulnerability details:
http://www-01.ibm.com/support/docview.wss?uid=swg21673715

Affected Products and Versions

Principal Product and Version(s)

Affected IBM Tivoli Monitoring Version
TFAM 1.2.0
IAMSB 1.2.1
IBM Tivoli Monitoring version 6.2.2 FP9

Remediation/Fixes


    Prerequisite :

    This fix can be applied on top of IAMSB 1.2.1 FP4 only.

    Please upgrade to IAMSB 1.2.1 FP4 before applying this fix.
    Refer the below URL for upgrading to IAMSB 1.2.1 FP4 http://www-01.ibm.com/support/docview.wss?uid=swg21640752

    Installation Instructions
    1. Back up the TFAM 1.2 /IAMSB 1.2.1
    2. Close any open Lotus Foundations Web Console, TEP, TCR and Welcome Page windows.
    3. Create a temporary directory and make it the current directory.
        1. mkdir /home/tfam-appliance_patch/Files/56302
        2. cd /home/tfam-appliance_patch/Files/56302
    4. Download 6.2.2-TIV-ITM-FP0009-IV56302.tar from the URL mentioned in the ITM Security Bulleting and un-tar it .
        1. Tar -xvf 6.2.2-TIV-ITM-FP0009-IV56302.tar
    5. Enter the NVS via "nvs" command and select "IBM Application Manager for Smart Business " or “IBM Tivoli Foundations Application Manager 1.2”
    6. Switch to /opt/patch/56302/6.2.2-TIV-ITM-FP0009-IV56302 and follow the install instructions for Linux/Unix platform as mentioned in the file 6.2.2-TIV-ITM-FP0009-IV56302.README

Get Notified about Future Security Bulletins

References

Off

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SS9KZM","label":"IBM Application Manager for Smart Business"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"--","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"Version Independent","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
17 June 2018

UID

swg21678336