IBM Support

IZ19918: USER CAN APPROVE PR WHEN SYNONYM STATUS IS USED WITHOUT SECURITYRIGHTS TO DO SO.

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • 1. Log into the Control Center as user sysadm.
    2. Go into the Application Setup, Purchasing module, PR
    application, and view the PRSTATUS APPROVE value list.
    3. Add a synonym status for a approve but do not set the synonym
    as the default.  Save changes.
    4. Go to the Signature Security application and bring up the
    default group and bring up Purchase Requisitions.
    5. Change access to N for "Approve Purchase Requisition".  Save
    changes.
    6. Log into Maximo as a member of the default group.
    7. Go to the PR application and find a PR in APPR status.
    8. Attempt to change the status of the PR, notice that the
    synonym status is available which is incorrect because the user
    does not have rights to approve PRs.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED: none                                         *
    ****************************************************************
    * PROBLEM DESCRIPTION: 1. Log into the Control Center as user  *
    *                      sysadm.                                 *
    *                                                              *
    *                      4. Go to the Signature Security         *
    *                      application and bring up the            *
    *                                                              *
    *                      default group and bring up Purchase     *
    *                      Requisitions.                           *
    *                                                              *
    *                      5. Change access to N for "Approve      *
    *                      Purchase Requisition".  Save            *
    *                                                              *
    *                      changes.                                *
    *                                                              *
    *                      6. Log into Maximo as a member of the   *
    *                      default group.                          *
    *                                                              *
    *                      7. Go to the PR application and find a  *
    *                      PR in APPR status.                      *
    *                                                              *
    *                      8. Attempt to change the status of the  *
    *                      PR, notice that the                     *
    *                                                              *
    *                      synonym status is available which is    *
    *                      incorrect because the user              *
    *                                                              *
    *                      does not have rights to approve PRs.    *
    *                                                              *
    ****************************************************************
    * RECOMMENDATION:                                              *
    *                                                              *
    *                                                              *
    *                                                              *
    ****************************************************************
    USER CAN APPROVE PR  WITHOUT SECURITY  RIGHTS TO DO SO.
    

Problem conclusion

  • This is already fixed in 5.2 Patch 8. In debug mode, I watched
    the code discard unauthorized potential new statuses.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IZ19918

  • Reported component name

    SECURITY

  • Reported component ID

    5724R46SC

  • Reported release

    520

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2008-04-11

  • Closed date

    2008-05-09

  • Last modified date

    2008-05-09

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Modules/Macros

  • MAXIMO
    

Fix information

  • Fixed component name

    SECURITY

  • Fixed component ID

    5724R46SC

Applicable component levels

  • R520 PSY

       UP

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSCHPNP","label":"Security Groups"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"520","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
09 May 2008