Addendum
I noticed today, September 20, that the familiar "Update available" pop-up now displays that release 1.1.9.16 is the new release.
This is the third new release of IBM's Access Client Solutions, ACS, in the past two months. While my ACS does not alert for a new release (Help > Check for Updates), version 1.1.9.16 is mentioned on IBM's ACS webpage.
|
This version is to remedy the following, that has been an issue for all previous versions of ACS:
- STRPCCMD command sent from a compromised IBM i
- 5250 emulator macro that contains a malicious 'RunProgram' action
- 5250 multiple sessions file (.bch, .bchx) that contains a malicious 'Run' action
From this version each of the above actions will require user confirmation to run. A confirmation will be displayed, with "Yes" and "No" options. For the 5250 emulator macro 'RunProgram' action an additional "Cancel" option is offered to end the execution of the entire macro.
You will have to download the update from IBM's ACS website, http://ibm.biz/IBMi_ACS (the URL is case sensitive), for yourself.
When using the above link the "Login to IBM" page is opened. Don't worry if you don't have an IBMid, you can create one, for free, in a couple of minutes.
Confirm your agreement with IBM's license.
You will then be presented with the "IBM i Access Client Solutions" page. The download for ACS's latest version is the first download.
Click on the "Download" action. The file will be downloaded onto your computer.
Once you have downloaded the zip file, I recommend you read the "Getting Started" file. This will guide you through the install process depending upon which operating system you use.
I installed the new release without any issues.
I can then confirm that the new release was installed (Help > About):
To learn more about ACS 1.1.9.16 go to IBM's ACS webpage here.
The many recent updates suggest that IBM itself is making active use of the CVE_INFO function. :-)
ReplyDeleteWhat you'll notice when you use STRPCCMD is a new window asking the user for confirmation. Tested it, it is true. The same shall be true for macros using "Run", but i haven't tried that.
Some shops might have additional support effort telling their users they want to click "Yes" in *that* situation.
I was thinking the same thing about IBM making use of CVE_INFO
DeleteYes, but these CVEs have to be created (or discovered) - by whom?
DeleteNowadays it might be the question: is it their AI hardening their application or is it someone else's, trying to do nasty things and was caught?
Download site still only showing 1.1.9.15 for me
ReplyDeleteCould it be a caching issue with your browser?
DeleteGo to the page to download, and if it still have 1.1.9.15 there press Ctrl-F5 (this should upload directly from the server, no caching) to refresh.