A fix is available
APAR status
Closed as program error.
Error description
The Connector Migration Toolkit (CMT) uses a deprecated internal API that performs Authentication but not Authorization. Thus it will confirm that the user login credentials are valid, but it does not then confirm that the project-role of user (i.e. Developer, Operator, Super-Operator, etc) is one that is authorized to modify job designs.
Local fix
Problem summary
The Connector Migration Toolkit (CMT) uses an internal API that performs Authentication but not Authorization. Thus it will confirm that the user login credentials are valid, but it does not then confirm that the project-role of user (i.e. Developer, Operator, Super-Operator, etc) is one that is authorized to modify job designs.
Problem conclusion
APAR Recommendation: Apply the patch after reading the security bulletin located here: http://www.ibm.com/support/docview.wss?uid=swg21697306 After applying this patch, the user should not be able to logon to CMT unless they have the following role combinations: a) SuiteUser + DataStageAdmin b) SuiteUser + DataStageDeveloper c) SuiteUser + DataStageProductionManager Where DataStageDeveloper and DataStageProductionManager are PROJECT roles.
Temporary fix
Comments
APAR Information
APAR number
JR51665
Reported component name
INFO SRVR PLATF
Reported component ID
5724Q3612
Reported release
B30
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt
Submitted date
2014-10-28
Closed date
2015-04-07
Last modified date
2015-04-07
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
INFO SRVR PLATF
Fixed component ID
5724Q3612
Applicable component levels
R850 PSY
UP
R870 PSY
UP
R910 PSY
UP
R912 PSY
UP
RB30 PSY
UP
RB31 PSY
UP
[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSZJPZ","label":"InfoSphere Information Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"11.3","Line of Business":{"code":"LOB10","label":"Data and AI"}}]
Document Information
Modified date:
16 October 2021