IBM Support

PH44051: SECURITY VIOLATION AGAINST DEFAULT USER IN CICS DURING TERMINAL SIGNOFF AFTER XCMD SECURITY ENABLED

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • You turn XCMD security on in your CICS region and find that you
    may now receive security violations when a terminal is signed
    off. A dump with trace shows EXEC CICS INQUIRE SYSTEM and EXEC
    CICS SET TERMINAL commands may be issued from DFHSFP after a
    valid user has been signed off. Those commands then run under
    the region default user, and may experience violations.
    

Local fix

  • temporarily allow access until fixing PTF is applied
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All CICS users.                              *
    ****************************************************************
    * PROBLEM DESCRIPTION: CESF Security violations reported when  *
    *                      the DFHSIT options CMDSEC=ALWAYS and    *
    *                      XCMD other than NO are specified.       *
    ****************************************************************
    DFHSIT options CMDSEC=ALWAYS and XCMD other than NO are
    specified so command security checking is active for all
    transactions.
    
    As well as signing off a userid, CESF issues EXEC CICS INQUIRE
    SYSTEM, INQUIRE TERMINAL and SET TERMINAL commands to reset the
    terminal for future use. If the userid does not have authority
    to issue these requests then a security violation occurs.
    

Problem conclusion

  • CICS is changed so that running CESF does not require authority
    to issue any system programmer interface (SPI) commands. The fix
    of APAR PH45347 is contained within this APAR.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH44051

  • Reported component name

    CICS TS Z/OS V5

  • Reported component ID

    5655Y0400

  • Reported release

    200

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2022-02-10

  • Closed date

    2022-05-04

  • Last modified date

    2022-06-01

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UI80405

Modules/Macros

  • DFHSFP
    

Fix information

  • Fixed component name

    CICS TS Z/OS V5

  • Fixed component ID

    5655Y0400

Applicable component levels

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSGMGV","label":"CICS Transaction Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"5.5","Line of Business":{"code":"LOB35","label":"Mainframe SW"}}]

Document Information

Modified date:
06 July 2022