The information in this Readme contains fix list and other package information about the Hardware Management Console.
This package includes fixes for HMC Version 7 Release 7.3.0. You can also reference this package by APAR MB03524. This image must be installed on top of HMC Version 7 Release 7.3.0 Recovery installation (MH01255) or Update installation (MH01256), with or without efixes.
Package Name | Size | Checksum | APAR# | PTF# |
---|---|---|---|---|
HMC_Update_V7R730_SP1.iso | 2044319744 | 56595 | MB03524 | MH01265 |
Splash Panel information (or lshmc -V output) | ||||
Version: 7
Release: 7.3.0 Service Pack: 1 HMC Build level 20110818.1 HMC Driver APO_1133B (0818) Rev 1.0 ","base_version=V7R7.3.0 " |
This package provides the following new function and enhancements:
Form fields before authentication in the application have auto-complete enabled. Anyone using the same computer would be able to see information entered by a previous user. By not setting AutoComplete to OFF the users can purposely or accidentally save sensitive information into Browser Memory Space when saving informtion to their accounts. This situation can allow a malicious attacker to dump the clear text from memory and gain access to sensitive information.
Link Injection is the act of modifying the content of a site by embedding in it a URL to an external site, or to a script in the vulnerable site. By embedding a URL in the vulnerable site, an attacker is then able to use it as a platform to launch attacks against other sites, as well as against the vulnerable site itself. It is possible to cause a user's browser to issue automatic requests to virtually any site the attacker desires. As a result, the attacker may use this Link Injection vulnerability to launch several types of attacks.
Fixes for two vulnerabilities in which users with restricted rights could promote themselves to root access.
Closed a vulnerability in which an authorized user could create a link injection attack by using the man command.
Installation instructions for HMC Version 7 updates and fixes can be found here:
Update corrective services instructions for HMC Version 7
Recovery media upgrade and installation instructions for HMC Version 7 can be found here:
Recovery media upgrade and installation
Instructions and images for upgrading via a remote network install can be found here (for all HMC releases):
In all cases, the HMC application extracts the files needed to install the corrective service.