IBM Support

IV50751: WHEN SECURITY MANAGER IS ENABLED JAVA.SECURITY.ACCESSCONTROLEXCE PTION IS SEEN

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Error Message: When Security Manager is enabled
    java.security.AccessControlException is seen while loading
    application class
    .
    Stack Trace: java.security.AccessControlException: Access denied
    (java.lang.RuntimePermission getClassLoader) \
    at
    java.security.AccessController.throwACE(AccessController.java:10
    0) \
    at
    java.security.AccessController.checkPermission(AccessController.
    java:174) \
    at
    java.lang.SecurityManager.checkPermission(SecurityManager.java:5
    44) \
    at
    com.ibm.ws.security.core.SecurityManager.checkPermission(Securit
    yManager.java:208) \
    at com.ibm.rmi.util.ClassCache.checkAccess(ClassCache.java:65) \
    at com.ibm.rmi.util.ClassCache.get(ClassCache.java:71) \
    at
    com.ibm.CORBA.iiop.UtilDelegateImpl.loadClass(UtilDelegateImpl.j
    ava:673) \
    at javax.rmi.CORBA.Util.loadClass(Util.java:252) \
    at com.ibm.rmi.util.Utility.loadClassOfType(Utility.java:847) \
    at
    com.ibm.rmi.util.RepositoryId.loadClass(RepositoryId.java:693) \
    at
    com.ibm.rmi.util.RepositoryId.checkClassCache(RepositoryId.java:
    667) \
    at
    com.ibm.rmi.util.RepositoryId.getClassFromType(RepositoryId.java
    :656) \
    at
    com.ibm.rmi.iiop.CDRReader.fast_read_value(CDRReader.java:2044)
    \
    at
    com.ibm.rmi.iiop.CDRReader.fast_read_abstract_interface(CDRReade
    r.java:2231) \
    at
    com.ibm.rmi.iiop.CDRReader.fast_read_abstract_interface(CDRReade
    r.java:2217) \
    .
    NA
    

Local fix

  • Add following permission in
    <WAS_InstallRoot>\java\jre\lib\security\java.policy.
    grant{
    ...
    permission java.lang.RuntimePermission 'getClassLoader','read';
    ...
    }
    

Problem summary

  • Incorrect security checks resulted in
    java.security.AccessControlException
    

Problem conclusion

  • This defect will be fixed in:
    6.0.1 SR7
    7.0.0 SR6
    6.0.0 SR15
    5.0.0 SR16_FP4
    .
    Corrected the security check logic
    

Temporary fix

Comments

APAR Information

  • APAR number

    IV50751

  • Reported component name

    JAVA 5 ORB

  • Reported component ID

    620500123

  • Reported release

    500

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2013-10-11

  • Closed date

    2013-10-11

  • Last modified date

    2013-10-11

  • APAR is sysrouted FROM one or more of the following:

    IX90129

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    JAVA 5 ORB

  • Fixed component ID

    620500123

Applicable component levels

  • R500 PSY

       UP

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSC9HBB","label":"ORB"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"5.0","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
11 October 2013