APAR status
Closed as program error.
Error description
SMB is used for application log backups for Micorosft SQL and Exchange and listen on port 445 on vSnap. Because the SMB signing is not required, it may cause vulnerabilities scan failure.
Local fix
N/A
Problem summary
**************************************************************** * USERS AFFECTED: * * IBM Spectrum Protect Plus level 10.1.4. * **************************************************************** * PROBLEM DESCRIPTION: * * See Error Description. * * For more information, refer to the security bulletin * * published at this link: * * https://www.ibm.com/support/pages/node/1107195 * **************************************************************** * RECOMMENDATION: * * Apply fixing level when available. This problem is currently * * projected to be fixed in IBM Spectrum Protect Plus level * * 10.1.5. Note that this is subject to change at the * * discretion of IBM. * ****************************************************************
Problem conclusion
The default SMB server configuration on vSnap was set to offer SMB signing but it was not mandatory. Clients servers had the option to skip signing. As of IBM Spectrum Protect Plus level 10.1.5, the default configuration has been updated to ensure that SMB signing is now mandatory for any clients that attempt to connect to the vSnap server.
Temporary fix
Comments
APAR Information
APAR number
IT30175
Reported component name
SP PLUS
Reported component ID
5737SPLUS
Reported release
A14
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2019-09-04
Closed date
2019-10-21
Last modified date
2020-02-17
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
SP PLUS
Fixed component ID
5737SPLUS
Applicable component levels
[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSNQFQ","label":"IBM Spectrum Protect Plus"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"A14","Line of Business":{"code":"LOB26","label":"Storage"}}]
Document Information
Modified date:
30 January 2024