IBM Support

IT26637: PASSWORD EXPOSURE IN IBM SPECTRUM PROTECT CLIENT TRACE FILE

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • When tracing is enabled, the IBM Spectrum Protect Client trace
    file may display the password in plain text.
    
    
    Products affected:
    IBM Spectrum Protect Backup-Archive Client version 7.1 and 8.1
    on all platforms. IBM Spectrum Protect for Virtual Environments:
    
    Data Protection for VMware version 7.1 and 8.1 on Microsoft
    Windows x64 and Linux x86_64 platforms.
    IBM Spectrum Protect for Virtual Environments: Data Protection
    for Microsoft Hyper-V version 7.1 and 8.1 on
    Microsoft Windows x64 platform.
    
    If you are using Backup-Archive Client 7.1 and 8.1, refer to
    APAR IT26637
    Note 1: The Backup-Archive Client is a prerequisite to using the
    
    Data Protection for VMware version 7.1. In Data Protection for
    VMware environments, the Backup-Archive Client is also known
    as the data mover.
    Note 2: The Backup-Archive Client is a prerequisite to using the
    
    Data Protection for Microsoft Hyper-V versions 7.1 till 8.1.2.
    In Data Protection for  Microsoft Hyper-V environments,
    the Backup-Archive Client is also known as the data mover.
    
    If you are using Data Protection for VMware 8.1, refer to APAR
    IT28132
    
    If you are using Data Protection for Microsoft Hyper-V
    8.1.4-8.1.6, refer to APAR IT28133
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * IBM Spectrum Protect Backup-Archive Client version 7.1 and   *
    * 8.1 on all platforms.                                        *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * see Error Description.                                       *
    * For more information, refer to the security bulletin         *
    * published at this link:                                      *
    * http://www.ibm.com/support/docview.wss?uid=ibm10869208       *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * This issue is projected to be fixed in the Backup-Archive    *
    * client version 8.1.7 and 7.1.8.5 for all platforms.          *
    *                                                              *
    * Note 1: The Backup-Archive Client is a prerequisite to using *
    * the Data Protection for VMware version 7.1.                  *
    * In Data Protection for VMware environments,                  *
    * the Backup-Archive Client is also known as the data mover.   *
    *                                                              *
    * Note 2: The Backup-Archive Client is a prerequisite to using *
    * the Data Protection for Microsoft Hyper-V versions 7.1 till  *
    * 8.1.2. In Data Protection for  Microsoft Hyper-V             *
    * environments, the Backup-Archive Client is also known        *
    * as the data mover.                                           *
    *                                                              *
    * Note 3: This is subject to change at the discretion of IBM.  *
    ****************************************************************
    

Problem conclusion

  • The offending trace message has been removed.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT26637

  • Reported component name

    TSM CLIENT

  • Reported component ID

    5698ISMCL

  • Reported release

    81W

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-10-16

  • Closed date

    2019-01-14

  • Last modified date

    2019-04-02

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    IT28132 IT28133

Fix information

  • Fixed component name

    TSM CLIENT

  • Fixed component ID

    5698ISMCL

Applicable component levels

  • R71A PSY

       UP

  • R71H PSY

       UP

  • R71L PSY

       UP

  • R71M PSY

       UP

  • R71S PSY

       UP

  • R71W PSY

       UP

  • R81A PSY

       UP

  • R81H PSY

       UP

  • R81L PSY

       UP

  • R81M PSY

       UP

  • R81S PSY

       UP

  • R81W PSY

       UP

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSGSG7","label":"Tivoli Storage Manager"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"81W","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
02 April 2019