Database/Firmware, BMC & network fabric

IBM PowerVM PKS and virtual TPM: persistent key seeds produce a reduced-strength AES key
Impact
The platform keystore and the virtual TPM derive their AES key from persistent storage key seeds, yielding a key of reduced strength. An attacker with access to the service processor or the HMC can derive the key and read the protected data — which is where partitions keep secure-boot key material, disk encryption keys and vTPM-sealed secrets. On Power-based accelerator nodes this means the vTPM's confidentiality guarantee is weaker than the guest was told, and the exposure is entirely from the management plane rather than from tenant partitions. IBM scores confidentiality impact only, with high privileges and user interaction required, and marks scope as changed.
Who can reach it
Someone with access to the service processor or the HMC — in practice, an administrator on the management VLAN holding credentials there. Adjacent network, high privileges, user interaction required. Not reachable from a tenant partition.
What to do
Apply the firmware levels IBM lists in support note 7283890 for your FW950, FW1060 or FW1110 stream. Power system firmware at this level means scheduling the frame out of service to flash. Because data protected under the weak key should be considered exposed, plan to reseal or re-provision vTPM-held secrets after the update rather than assuming the flash alone restores the guarantee.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.