IBM Support

IT29489: RESTORE ONLY RBAC USER IS ABLE TO REMOVE ASSIGNED SLA

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • An IBM Spectrum Protect Plus RBAC user configured for restore
    only abilityis able to remove an SLA defined to a resource.
    Steps to recreate:
    
    
    1. Created a new SPP integrated user
    2. Created a new Resource Group, which contains a complete MSSQL
    instance
    3. Created the assignment to allow the newly created user using
    the build-in role "Restore only" for the resources of the newly
    created Resource Group
    4. Logged into the SPP GUI using the newly created user
    5. Browsed to Manage Protection -> Applications -> SQL -> Backup
    6. Select one of the databases
    7. Select "Select SLA Policy"
    Because the role "Restore only" does not contain any
    permission's on SLA policies, there is no SLA Policy displayed,
    but the "Save" button is active and not greyed out for
    selection.
    8. Select the "Save" Button
    The previously selected database now has no SLA Policy assigned.
    Note: While the above steps are for an Application (SQL), this
    problem can occur on other applications andhypervisors.
    Versions affected: 10.1.X
    Keywords: TS002234820
    

Local fix

  • Add the SLA back to the resource
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * IBM Spectrum Protect Plus level 10.1.3 and 10.1.4            *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * See ERROR DESCRIPTION                                        *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Apply fixing level when available. This problem is currently *
    * projected to be fixed IBM Spectrum Protect Plus levels       *
    * 10.1.4.179 and 10.1.5. Note that this is subject to change   *
    * at the discretion of IBM.                                    *
    ****************************************************************
    

Problem conclusion

  • IBM Spectrum Protect Plus has been enhanced to prevent
    assignment of Service Level Agreement (SLA) policies by users
    with insufficient permission.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT29489

  • Reported component name

    SP PLUS

  • Reported component ID

    5737SPLUS

  • Reported release

    A13

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-06-18

  • Closed date

    2019-07-18

  • Last modified date

    2019-07-18

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Modules/Macros

  • UI
    

Fix information

  • Fixed component name

    SP PLUS

  • Fixed component ID

    5737SPLUS

Applicable component levels

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSNQFQ","label":"IBM Spectrum Protect Plus"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"A13","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
30 January 2024