IBM Support

JR61612: CMIS QUERY IN CONTENT INTEGRATION SERVICE WILL RETURN CONTENT WHICH IS NOT ASSOCIATED TO CURRENT USER

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • CMIS query in content integration service can return the list of
    documents in the repository although the current user has no
    access to it.
    Even if they can not be downloaded an attacker
    might be able to see what is stored in the system when
    manipulating the CMIS query (e.g. by removing the WHERE clause).
    

Local fix

  • n/a
    

Problem summary

  • No additional information is available.
    

Problem conclusion

  • A fix that ensures a CMIS query with a BPD endpoint doesn't
    return more documents will be included in a future release of
    Business Automation Workflow.
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR61612

  • Reported component name

    BUS AUTO WORKFL

  • Reported component ID

    5737H4100

  • Reported release

    J00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-10-16

  • Closed date

    2020-02-26

  • Last modified date

    2020-02-26

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    BUS AUTO WORKFL

  • Fixed component ID

    5737H4100

Applicable component levels

[{"Line of Business":{"code":"LOB36","label":"IBM Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS8JB4","label":"IBM Business Automation Workflow"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"19.0.0.1"}]

Document Information

Modified date:
18 November 2020