APAR status
Closed as program error.
Error description
Description - The application, after logout, is expected to clean all the cached information, especially sessionrelated information. The cleaning is expected both, from the server and client end, as a part of complete and secure logout. When the active session was logged out, it was observed that the user credential information persisted in the browser cache in plain text. Refer to the following steps to confirm the issue. 1. Log in to the application, using Firefox 2. Navigate to ensure that the session is active. 3. Logout from the active session. Ensure the log out from the browser UI. Do not close the browser application. 4. Start the task manager 5. Select the process firefox.exe and right-click it 6. Select the "Create dump file" option to create a dump file for Firefox. 7. Using any hex editor, open Firefox.DMP file. 8. Search for the password text. The password and username information are seen in plain text.
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: * * IBM Storage Insights users * * * **************************************************************** * PROBLEM DESCRIPTION: * * SECURITY APAR * * * **************************************************************** * RECOMMENDATION: * ****************************************************************
Problem conclusion
The fix for this APAR is contained in the following release: IBM Storage Insights 4Q25 [ 54X-IBM-SI ] ( release target 4Q 2025 / November ) To protect IBM Storage Insights against emerging security vulnerabilities, the service was updated to protected against vulnerabilities. No action is required, there is nothing that you need to do following the IBM Storage Insights upgrade.
Temporary fix
Comments
APAR Information
APAR number
IT48631
Reported component name
STORAGE INSIGHT
Reported component ID
5608TPCSI
Reported release
54X
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2025-10-05
Closed date
2025-11-13
Last modified date
2025-11-13
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
STORAGE INSIGHT
Fixed component ID
5608TPCSI
Applicable component levels
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSQRB8","label":"IBM Storage Insights"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"54X","Line of Business":{"code":"LOB69","label":"Storage TPS"}}]
Document Information
Modified date:
13 January 2026