IBM Support

PI83656: SLO BASED ON CUSTOMCAMLOGOUTURL MAY FAIL DUE TO A RACE CONDITIONWHICH INCURS A SECURITY ISSUE (SESSION NOT PROPERLY ENDED)

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • In environments where some outer security is used to SSO into
    TM1Web->mode 5 -> CAM the use of SLO via CustomCAMLogoutURL can
    suffer from a race condition which prevents the outer session
    not to be ended in time, thus SLO failing. A different user can
    thereby gain access to another user's CAM/TM1Web session.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * All Users                                                    *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * See Error Description                                        *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Upgrade to Planning Analytics Release 2.0.5 or later         *
    ****************************************************************
    

Problem conclusion

  • Code Fix.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PI83656

  • Reported component name

    TM1 SERVER

  • Reported component ID

    5724W49SE

  • Reported release

    A22

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2017-06-27

  • Closed date

    2018-09-26

  • Last modified date

    2018-09-26

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Modules/Macros

  • UNKNOWN
    

Fix information

  • Fixed component name

    TM1 SERVER

  • Fixed component ID

    5724W49SE

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SS9RXT","label":"Cognos TM1"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"A22","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
21 September 2021