• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Heartbleed Exposes The Vulnerability Of An IBM i Mentality

    April 28, 2014 Alex Woodie

    When IBM recently patched the Heartbleed vulnerability that existed in the Power Systems firmware, it did more than issue a more secure piece of system code. IBM also demonstrated the fallibility of maintaining an IBM i mentality in an increasingly complex and interconnected world. As IT Jungle‘s PTF patch master and IBM business partner Doug Bidwell explains, we can ill afford to think of IBM i as an isolated entity anymore.

    “I just read your article, IBM Patches Heartbleed Vulnerability in Power Systems Firmware. Thank you for getting that out there,” Bidwell writes via email. Bidwell, who edits IT Jungle‘s System i PTF Guide, had alerted us to IBM’s April 18 security bulletin revealing the existence of Heartbleed vulnerability in the Power Systems firmware and the immediate availability of fixes.

    “But, there is something still not gelling with the client base,” Bidwell continues. “Reading your article, I see it there, also. There is no IBM i server. Just as there is no AIX server. Periodically, IBM will announce an OS-specific version of a Power server, such as PowerLinux. But there is only a Power box, and an OS that makes it a server.”

    “One of the legacy conceptions we are all guilty of is that we think of the AS/400 as one entity, a box with an OS that are tightly integrated and a single entity in conversation. That changed when they merged the i and p systems onto Power….”

    So much has changed since that day in April 2008 when IBM formally unveiled the Power Systems platform and did away with System i and System p forever. While the two platforms had shared hardware for some time, that was the day IBM attempted to permanently erase any lines separating those systems.

    Despite the merger of platforms, many in the IBM midrange community maintain the IBM i identity, just as they identified themselves as System/38, AS/400, iSeries, or System i guys or gals before April 2008. It’s a tempting security blanket to hold onto, but the irony is that it may actually hurt security.

    “The entire client base thinks of the one entity,” Bidwell writes. “And that’s the vulnerability, and, the challenge. Because there used to be one entity, when you put on the Cume, and IBM said there were no vulnerabilities, we tended to not touch the box for months, even years at a time. That changed when ‘the merge’ happened, and it’s taking a long time for people to wake up to the point your article both makes and misses, that IBM i is an OS that rides on a Power piece of hardware. Two entities, not one. And they are tightly integrated, but not so much that you can afford to watch only one entity.”

    Specifically, Bidwell points to PASE, the AIX runtime that IBM added to the platform as an option more a decade ago, but which has become a critical part of the infrastructure stack for applications running on IBM i and Power Systems. If you use Java, the Apache Web server, or the PHP runtime, you’re using PASE, whether you know it or not.

    “PASE added a great deal of functionality to the IBM i OS by allowing many varied licensed program products to be added to the OS/400 we all knew,” Bidwell writes. “But it also added another area of watchfulness. Each licensed program product that resides on PASE is susceptible to its own version schedule, and, its own vulnerabilities.”

    PASE is just one example of how the legacy “Fortress Rochester” AS/400 mentality is clashing with today’s modern and complex Power Systems platform. When IT Jungle attempted to ascertain the significance of the Heartbleed OpenSSL vulnerability that existed in the Power Systems firmware–to gauge whether this was a super-critical problem that could be easily exploited or an obscure flaw that a hacker would have a tough time doing anything with–the IBMer from Rochester punted, saying he didn’t handle the firmware and couldn’t speak to that. Whose responsibility is it? It’s tough to say.

    “The days of monitoring and administering one ‘system’ are gone,” Bidwell writes. “We all need to be watching the hardware, the OS, the licensed programs, and be aware of each of their differences and vulnerabilities. In the SMB marketplace, speaking from the ‘i’ point of view, virtually everyone thinks of their system as an IBM i. It was a great concept while it lasted, but that is not the horse we are riding today. Or, as Tim [Prickett Morgan] put it once, ‘This ain’t your daddy’s AS/400 anymore.'”

    RELATED STORIES

    IBM Patches Heartbleed Vulnerability in Power Systems Firmware

    Heartbleed Postmortem: Time to Rethink Open Source Security?

    Heartbleed, OpenSSL, and IBM i: What You Need to Know

    It’s Official: Now We’re Power Systems and i for Business



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    New Generation Software

    FREE Webinar:

    Creating Great Data for Enterprise AI

    Enterprise AI relies on many data sources and types, but every AI project needs a data quality, governance, and security plan.

    Wherever and however you want to analyze your data, adopting modern ETL and BI software like NGS-IQ is a great way to support your effort.

    Webinar: June 26, 2025

    RSVP today.

    www.ngsi.com – 800-824-1220

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Hotels Expand Agilysys Footprints As Vendor Sells UK Business Emulate sp_Help In DB2 For i

    Leave a Reply Cancel reply

Volume 24, Number 15 -- April 28, 2014
THIS ISSUE SPONSORED BY:

Infinite Corporation
Fresche Legacy
HiT Software
Manta Technologies
COMMON

Table of Contents

  • IBM i Runs On Two Of Five New Power8 Machines
  • A Real Open Power Server, Finally
  • Executing RPG: Pull The Plug, Kilner Says
  • As I See It: Old Hephaestus Had A Bot, A.I.A.I.O.
  • Heartbleed Exposes The Vulnerability Of An IBM i Mentality
  • Avnet To Resell SoftLayer Cloud, But No IBM i Slices
  • Big Deals Spark Q1 At Manhattan Associates
  • Avnet Sees IT Spending Slowdown March Draws To A Close
  • Manager And Programmer Ratios In IT Shops
  • Unions Criticize IBM’s Earning Per Share Focus

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Big Blue Raises IBM i License Transfer Fees, Other Prices
  • Keep The IBM i Youth Movement Going With More Training, Better Tools
  • Remain Begins Migrating DevOps Tools To VS Code
  • IBM Readies LTO-10 Tape Drives And Libraries
  • IBM i PTF Guide, Volume 27, Number 23
  • SEU’s Fate, An IBM i V8, And The Odds Of A Power13
  • Tandberg Bankruptcy Leaves A Hole In IBM Power Storage
  • RPG Code Generation And The Agentic Future Of IBM i
  • A Bunch Of IBM i-Power Systems Things To Be Aware Of
  • IBM i PTF Guide, Volume 27, Numbers 21 And 22

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle