IBM Support

IT35507: IBM SPECTRUM PROTECT PLUS NEEDS TO HAVE MEDIUM STRENGTH CIPHERS LIKE TRIPLE DES (3DES) DISABLED.

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Starting with version 10.1.6, IBM Spectrum
    Protect Plus is
    running a Kubernetes (K8s) environment that uses ports allowing
    medium strength ciphers like Triple DES (3DES).
    
    Affected ports are :
    
    6443/tcp
    2379-2380/tcp
    10250/tcp
    10251/tcp
    10252/tcp
    10255/tcp
    8472/udp
    30000-32767/tcp
    
    These need to be disabled.
    IBM Spectrum Protect Plus Versions Affected:
    IBM Spectrum Protect Plus 10.1.6 and 10.1.7
    
    Initial Impact: Medium
    
    Additional Keywords: SPP, SPPLUS, TS004198583, CVE-2018-1785,
                         ssl
    

Local fix

  • Disable the K8s services if Amazon EC2 backups are not used
    or planned with the following commands :
        sudo systemctl stop k8s-plugins
        sudo systemctl disable k8s-plugins
        sudo touch /opt/SPP/spp-k8s/reset_cluster
        sudo kubeadm reset -fIf needing to enable these again, use:
        sudo rm /opt/SPP/spp-k8s/reset_cluster
        sudo systemctl enable k8s-plugins
        sudo systemctl start k8s-plugin
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * IBM Spectrum Protect Plus levels 10.1.6 and 10.1.7.          *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * See Error Description.                                       *
    * For more information, refer to the security bulletin         *
    * published at this link:                                      *
    * https://www.ibm.com/support/pages/node/6445735               *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Apply the fixing level when available. This problem is       *
    * projected to be fixed in in IBM Spectrum Protect Plus level  *
    * 10.1.8. Note that this is subject to change at the           *
    * discretion of IBM.                                           *
    ****************************************************************
    

Problem conclusion

  • Three ports associated with embedded IBM Spectrum Protect Plus
    container services were identified as open. These ports were not
    needed. Appliance fixes were applied to close these ports. Aside
    from resolving security vulnerabilities, there are no observable
    product behavior changes.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT35507

  • Reported component name

    SP PLUS

  • Reported component ID

    5737SPLUS

  • Reported release

    A16

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-01-13

  • Closed date

    2021-05-05

  • Last modified date

    2021-05-05

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    SP PLUS

  • Fixed component ID

    5737SPLUS

Applicable component levels

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSNQFQ","label":"IBM Spectrum Protect Plus"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"A16","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
31 January 2024