Hi Karen,
Currently there is no solution for these vulnerability, and this vulnerability should not be an issue as well. These components comes as bundled with HSM and can't be individually updated. These will be updated in upcoming release of 5.5.4, but target release date is not yet out. So, we have to wait for 5.5.4.
The above is by IBM Support.
Thank You.
------------------------------
Sudhir BISHT
------------------------------
Original Message:
Sent: Wed August 25, 2021 01:49 PM
From: karen larson
Subject: HyperScale Manager Server (5.5.3) Security Vulnerabilities
Same issue, let me know if you find a solution that helped.
Regards,
Team Smokekitchen
------------------------------
karen larson
Original Message:
Sent: Mon August 23, 2021 01:43 PM
From: Sudhir BISHT
Subject: HyperScale Manager Server (5.5.3) Security Vulnerabilities
Our security vulnerability alerted us that we have vulnerabilities on our Hyperscale Manager Server(5.5.3). We upgraded the HSM to latest and greatest version 5.5.3 and a rescan of server shows vulnerabilities related to java and extended CLI.
They still find the vulnerabilities related to java and Extended XCLI. Note, XCLI installed is also latest installed available in Fix Central dated 2017. Does IBM has another latest version of XCLI available somewhere. Let us know.
The following vulnerable instance of Java is installed on the
remote host :
Path : /omaagent/agent_13.2.0.0.0/oracle_common/jdk
Installed version : 1.7.0_111
Fixed version : 1.6.0_141 / 1.7.0_131 / 1.8.0_121