APAR status
Closed as program error.
Error description
Using wsadmin.sh with jython, the engine uses a cache directory (WAS_HOME/temp/cachedir) to store PKC files during jyton initialization. In WAS 9.0.5.15 and 9.0.5.16, the files created in WAS_HOME/temp/cachedir/packages/ have permission bits rw------- (600) permissions. An example of this is: -rw------- 1 MSTONE1 WSCFG1 23718 Aug 21 09:49 packages.idx -rw------- 1 MSTONE1 WSCFG1 56 Aug 21 09:49 pc-appext.pkc If a user runs wsadmin.sh that doesn't own these files, you may see these ICH408I messages: ICH408I USER(GUEST1 ) GROUP(WASUSER ) NAME(GUEST ) /WebSphere/ND/DeploymentManager/profiles/default/temp/cachedi r/packages/packages.idx CL(FSOBJ ) FID(C3D7C4D3C2F0102F000000007E8E5A55) INSUFFICIENT AUTHORITY TO OPEN ACCESS INTENT(R--) ACCESS ALLOWED(GROUP ---) EFFECTIVE UID(0000001001) EFFECTIVE GID(0000000100) ICH408I USER(GUEST1 ) GROUP(WASUSER ) NAME(GUEST ) /WebSphere/ND/DeploymentManager/profiles/default/temp/cachedi r/packages/packages.idx CL(FSOBJ ) FID(C3D7C4D3C2F0102F000000007E8E5A55) INSUFFICIENT AUTHORITY TO OPEN ACCESS INTENT(-W-) ACCESS ALLOWED(GROUP ---) EFFECTIVE UID(0000001001) EFFECTIVE GID(0000000100) wsadmin will still load jython. You may also see $py.class with these same permission bits.
Local fix
delete the files in WAS_HOME/temp/cachedir/packages/ and invoke wsadmin.sh
Problem summary
**************************************************************** * USERS AFFECTED: All users of IBM WebSphere Application * * Server * * V9.0.5.15 or later * **************************************************************** * PROBLEM DESCRIPTION: The compile files permission was change * * to * * -rw------- as a result of Jython fixing * * CVE-2013-2027 in jython 2.7.2. * **************************************************************** * RECOMMENDATION: * **************************************************************** The compile files permission was change to -rw------- as a result of Jython fixing CVE-2013-2027 in jython 2.7.2.
Problem conclusion
The code is changed to put back read permission for all. The fix for this APAR is targeted for inclusion in fix pack 9.0.5.18. For more information, see 'Recommended Updates for WebSphere Application Server': https://www.ibm.com/support/pages/node/715553
Temporary fix
Comments
APAR Information
APAR number
PH56518
Reported component name
WEBSPHERE FOR Z
Reported component ID
5655I3500
Reported release
900
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2023-08-24
Closed date
2023-08-29
Last modified date
2023-08-29
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
WEBSPHERE FOR Z
Fixed component ID
5655I3500
Applicable component levels
[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS7K4U","label":"WebSphere Application Server for z\/OS"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"900","Line of Business":{"code":"LOB45","label":"Automation"}}]
Document Information
Modified date:
30 August 2023