IBM.支持

IT30175:VSNAP端口445不需要SMB签名

订阅

您可以跟踪此组件的所有活动APAR。

 

APAR状态

  • 作为程序错误关闭。

错误描述

  • SMB is used for application log backups for Micorosft SQL and
    Exchange and listen on port 445 on vSnap. Because the SMB
    signing is not required, it may cause vulnerabilities scan
    failure.
    

本地修复

  • N/A
    

问题摘要

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * IBM Spectrum Protect Plus level 10.1.4.                      *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * See Error Description.                                       *
    * For more information, refer to the security bulletin         *
    * published at this link:                                      *
    * //www.lovechugsblog.com/support/pages/node/1107195               *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Apply fixing level when available. This problem is currently *
    * projected to be fixed in IBM Spectrum Protect Plus level     *
    * 10.1.5. Note that this is subject to change at the           *
    * discretion of IBM.                                           *
    ****************************************************************
    

问题结论

  • The default SMB server configuration on vSnap was set to offer
    SMB signing but it was not mandatory. Clients servers had the
    option to skip signing. As of IBM Spectrum Protect Plus level
    10.1.5, the default configuration has been updated to ensure
    that SMB signing is now mandatory for any clients that attempt
    to connect to the vSnap server.
    

临时修复

评论

APAR信息

  • Apar号码

    IT30175

  • 报告的组件名称

    SP加

  • 报告的组件ID.

    5737Splus.

  • 报告释放

    A14

  • 状态

    关闭

  • PE.

    没有

  • 侯赛人

    no

  • 特别关注

    nospecatt / xsystem.

  • 提交日期

    2019-09-04

  • 关闭日期

    2019-10-21

  • 最后修改日期

    2020-02-17

  • APAR是由以下一个或多个中的SYSROUTED:

  • APAR被SISROUTED到以下一个或多个:

修复信息

  • 固定组件名称

    SP加

  • 固定组件ID

    5737Splus.

适用组件级别

[{"Line of Business":{"code":"LOB10","label":"Data and AI"},"Business Unit":{"code":"BU029","label":"Software"},"Product":{"code":"SSNQFQ","label":"IBM Spectrum Protect Plus"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"A14"}]

文件信息

修改日期:
07 February 2021