IBM Support

JR35940: USER WITH OPERATOR ROLE CAN MODIFY VARIABLES OF OTHER PROJECTS

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • a user with only operator role on a specific project, can modify
    environment variables of all projects in the system. this is
    considered not secure.
    

Local fix

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    Non-admin users can connect to projects they don't have access
    to
    ****************************************************************
    PROBLEM DESCRIPTION:
    Non-admin users can connect to projects they don't have access
    to.
    ****************************************************************
    RECOMMENDATION:
    Apply patch JR35940.
    ****************************************************************
    

Problem conclusion

  • The patch fixes the problem in the Administrator client, it
    will only allow non-admin users to connect to projects they have
    access to.
    Note that this patch addresses the issue for the Administrator
    client only.
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR35940

  • Reported component name

    WIS DATASTAGE

  • Reported component ID

    5724Q36DS

  • Reported release

    801

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2010-03-19

  • Closed date

    2010-04-16

  • Last modified date

    2011-08-17

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Modules/Macros

  • CLIENT
    

Fix information

  • Fixed component name

    WIS DATASTAGE

  • Fixed component ID

    5724Q36DS

Applicable component levels

  • R801 PSN

       UP

  • R810 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSVSEF","label":"InfoSphere DataStage"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.0.1","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
12 October 2021