IBM Support

JR56049: IBM BPM REST AND JAVASCRIPT APIS ALLOW GROUP MEMBERSHIP UPDATES INDEPENDENT OF GROUP TYPE

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • IBM Business Process Manager (BPM) provides REST and JavaScript
    APIs that you can use to update group membership information.
    There are multiple types of groups in IBM BPM and updates to
    some group types can lead to inconsistent data.
    

Local fix

Problem summary

  • No additional information is available.
    

Problem conclusion

  • A fix will be included in IBM BPM V8.5.7 cumulative fix 2016.09
    that validates group types before applying group membership
    updates, ensuring that IBM BPM APIs refuse group membership
    updates that might cause inconsistent data.
    
    The following table describes acceptable updates by group type.
    "Parent group" refers to the group that is updated.
    "Sub group" refers to a nested group that is either added to or
    removed from this parent group.
    
    parent group type: 0 (security group; replicated from user
    registry)
    add users: no
    remove users: no
    add sub-groups: no
    remove sub-groups: yes, groups of any type can be removed*
    
    parent group type: 1 (participant group; Teams using standard
    members)
    add users: yes
    remove users: yes
    add sub-groups: yes, but only of type 0 (security group) and 3
    (internal group)
    remove sub-groups: yes, groups of any type can be removed*
    
    parent group type: 2 (ad hoc group, also known as temporary
    group; for example Teams using filter services)
    add users: no
    remove users: no
    add sub-groups: no
    remove sub-groups: no
    
    parent group type: 3 (internal group; maintained in Process
    Admin Console)
    add users: yes
    remove users: yes
    add sub-groups: yes, but only of type 0 (security group) and 3
    (internal group)
    remove sub-groups: yes, groups of any type can be removed*
    
    parent group type: 4 (dynamic group; result of participant
    groups or task assignments using expressions)
    add users: no
    remove users: no
    add sub-groups: no
    remove sub-groups: no
    
    To determine whether the cumulative fix is available and
    download it if it is, complete the following steps on Fix
    Central (http://www.ibm.com/support/fixcentral):
    
    1. On the Select product tab, select WebSphere as the product
    group, IBM Business Process Manager with your edition from the
    WebSphere options, All as the installed version, and All as the
    platform, and then click Continue.
    2. In the Text field, enter "cumulative fix?, and click
    Continue.
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR56049

  • Reported component name

    BPM STANDARD

  • Reported component ID

    5725C9500

  • Reported release

    857

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2016-06-02

  • Closed date

    2016-08-15

  • Last modified date

    2016-08-15

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    BPM STANDARD

  • Fixed component ID

    5725C9500

Applicable component levels

  • R857 PSY

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSFTDH","label":"IBM Business Process Manager Standard"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"857","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
15 August 2016