Direct links to fixes
Closed as program error.
When you invoke a service by using the executeServiceByName URL, there is no access restriction based on the service type. Instead, services that were meant for internal use only are available for authenticated users.
No additional information is available.
A fix is available for all supported releases of IBM BPM and WebSphere Lombardi Edition. This fix validates the service type for invocations that are performed by using the executeServiceByName URL. With this fix installed, it is possible to start human services that are exposed to the logged-on user and to start AJAX Services. You will not be able to start other services unless all of the following requirements are met: - The request is processed on Process Center. - The request was issued by Process Designer in a playback session. - The user who issued this request is a member of the tw_authors group. - The user who issues this request is granted Read access to the process application. For backwards compatibility, a new configuration flag is introduced. By setting the following compatibility flag to false in the 100Custom.xml file, you can re-enable the previous behavior: <server merge=?mergeChildren?> <web-workflow-manager merge=?mergeChildren?> <enforce-correct-service-type-for-execute-service-by-name> false </enforce-correct-service-type-for-execute-service-by-name> </web-workflow-manager> </server> On Fix Central (http://www.ibm.com/support/fixcentral), search for JR52126 (IBM BPM) or search for IT06189 (WebSphere Lombardi Edition): 1. Select IBM Business Process Manager with your edition or IBM WebSphere Lombardi Edition from the product selector, the installed version to the fix pack level, and your platform, and then click Continue. 2. Select APAR or SPR, enter JR52126 (IBM BPM) or IT06189 (WebSphere Lombardi Edition), and click Continue. When you download fix packages, ensure that you also download the readme file for each fix. Review each readme file for additional installation instructions and information about the fix.
Reported component name
Reported component ID
Last modified date
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fixed component name
Fixed component ID
Applicable component levels
13 October 2021