Download
Downloadable File
File link | File size | File description |
---|---|---|
Abstract
This test fix contains enhancement and solves issue mentioned in IJ21014, IJ20621, IJ20787, IJ22327, IJ21675, IJ21734 and IJ22783.
Prerequisites
This Test Fix requires the WebGUI V8.1.0 Fix Pack 17 release.
Installation Instructions
The included fix is based on the WebGUI V8.1.0 Fix Pack 17 and should only be used with this release.
The included ZIP file contains modified versions of the following files:
$JazzSMHOME/profile/installedApps/${jazzsm.was.cell}/isc.ear/OMNIbusWebGUI.war/
styles/jsel_idl_carbon.css
eventviewer/eventViewer.jsp
eventviewer/eventViewer.jsp
WEB-INF/lib/version.jar
WEB-INF/lib/server.jar
WEB-INF/lib/icu4j-54_1_1.jar - removed
WEB-INF/lib/icu4j-65_1.jar - added
WEB-INF/web.xml
WEB-INF/lib/server.jar
WEB-INF/lib/icu4j-54_1_1.jar - removed
WEB-INF/lib/icu4j-65_1.jar - added
WEB-INF/web.xml
client-assets/*
classes/version.jar
classes/applets.jar
classes/map-ws.jar
classes/ncw/nl/raapi.properties
classes/icu4j-54_1_1.jar - removed
classes/icu4j-65_1.jar - added
classes/applets.jar
classes/map-ws.jar
classes/ncw/nl/raapi.properties
classes/icu4j-54_1_1.jar - removed
classes/icu4j-65_1.jar - added
portletpages/analytics/scopeBasedGroupingView.jsp
portletpages/metricView.jsp
portletpages/relationshipsView.jsp
portletpages/metricView.jsp
portletpages/relationshipsView.jsp
scripts/datasourceHandler.jsp
scripts/promptsHandler.jsp
scripts/promptsHandler.jsp
scripts/dt/ibm/tivoli/ncw/ev/EventProperties.js
scripts/dt/ibm/tivoli/ncw/EventPropertiesAll.js.uncompressed.js
scripts/dt/ibm/tivoli/ncw/EventPropertiesAll.js
scripts/dt/ibm/tivoli/ncw/EventPropertiesAll.js.uncompressed.js
scripts/dt/ibm/tivoli/ncw/EventPropertiesAll.js
scripts/dt/ibm/tivoli/ncw/prompts/PromptBuilder.js
scripts/dt/ibm/tivoli/ncw/EventViewerAll.js.uncompressed.js
scripts/dt/ibm/tivoli/ncw/EventViewerAll.js
scripts/dt/ibm/tivoli/ncw/EventViewerAll.js.uncompressed.js
scripts/dt/ibm/tivoli/ncw/EventViewerAll.js
where $JazzSMHOME is the root JazzSM installation directory and ${jazzsm.was.cell} is the cell name, namely JazzSMNode01Cell.
Installation Instructions
The steps for installing the fix on a Unix platform are listed below:
1. Stop the JazzSM server
eg. $JazzSMHOME/profile/bin/stopServer.sh server1
eg. $JazzSMHOME/profile/bin/stopServer.sh server1
2. Unzip the test fix file
eg. unzip WebGUI-81017-TestFix003_APAR_IJ21014_IJ20621_IJ20787_IJ22327_IJ21675_IJ21734_IJ22783_2020-03-01.zip.zip
3. Execute the install_IF script
eg. ./install_IF.sh -dash $JazzSMHOME/ui -webgui $WEBGUI_HOME
4. Start the JazzSM server
eg. $JazzSMHOME/profile/bin/startServer.sh server1
Note: The original files are backed-up to $WEBGUI_HOME/backup where $WEBGUI_HOME is the root OMNIbus Web GUI installation directory.
Uninstallation Instructions
1. Move to the backup directory
eg. cd $WEBGUI_HOME/backup
eg. cd $WEBGUI_HOME/backup
2. Execute the install_IF script
eg. ./uninstall_IF.sh -dash $JazzSMHOME/ui -webgui $WEBGUI_HOME
Problems Solved
Enhancements
Enable integration between Cloud Native Events Analytics and existing onPrem NOI
Defects
IJ21014: ACKD ENTRIES "DISAPPEAR" IN EV WHEN USING 'IBM DESIGN' UI (APAR=IJ21014)
Description:
Using the 'IBM Design' Theme, defect with Event Viewer row coloring behavior when WebGUI FP17 is deployed.
Design reflects new icons and such. Rows are not colored regardless of the setting.
Due to the colors employed on row test (black for unacknowledged, white for acknowledged), acknowledged
events appear as blank rows in Event Viewer displays.
Using the 'IBM Design' Theme, defect with Event Viewer row coloring behavior when WebGUI FP17 is deployed.
Design reflects new icons and such. Rows are not colored regardless of the setting.
Due to the colors employed on row test (black for unacknowledged, white for acknowledged), acknowledged
events appear as blank rows in Event Viewer displays.
IJ20621: FILTERS FROM GROUPS WITH SPACES USED UNDER THE PERSONALIZE OPTION FROM EVENT VIEWER CAUSES HEMDP0119E ERROR
Description:
A user, who has group filters, myGroupFilter that belong to a group, with its group name contains space(s). If he logs in and try to personalise the Event Viewer with myGroupFilter, error would be displayed.
A user, who has group filters, myGroupFilter that belong to a group, with its group name contains space(s). If he logs in and try to personalise the Event Viewer with myGroupFilter, error would be displayed.
IJ20787: OMNIBUS/WEBGUI - AMERICA/SAO_PAULO SHOWING EVENT WITH ONE HOUR AHEAD IN WEBGUI (AEL AND EV), EVEN AFTER APPLY JTZU UPDATE
Description:
The ICU4 JAR file used by WebGUI is out of date and must be updated with current definition of America/Sao_Paulo. Repackage Web GUI and make use of the new ICU4J v65.1 to resolve the issue.
The ICU4 JAR file used by WebGUI is out of date and must be updated with current definition of America/Sao_Paulo. Repackage Web GUI and make use of the new ICU4J v65.1 to resolve the issue.
IJ22327: HALF OF CHECKBOX "APPLY TO <NUM> ALL" IN JOURNAL IS UNRESPONSIVE TO CLICKS
Description:
The buttons at the bottom of the Journal panel is missing since FP17
The buttons at the bottom of the Journal panel is missing since FP17
IJ21675: IMPLEMENT CSRF PREVENTION TOKEN FOR RELATIONSHIPS ADMIN PAGE (CVE-2020-4199)
Description:
Cross-Site Request Forgery (CSRF) vulnerabilities were identified and verified as executing code on Tivoli Netcool/OMNIbus WebGUI Relationship admin page.
Cross-Site Request Forgery (CSRF) vulnerabilities were identified and verified as executing code on Tivoli Netcool/OMNIbus WebGUI Relationship admin page.
IJ21734: NON-PERSISTENT CROSS-SITE SCRIPTING (XSS) VULNERABILITY (CVE-2020-4198)
Description:
The Relationship admin page in Tivoli Netcool/OMNIbus WebGUI is vulnerable to Cross Site Scripting attack via error messages returned by the server. The application does not properly encode error message returned from server and executes code.
The Relationship admin page in Tivoli Netcool/OMNIbus WebGUI is vulnerable to Cross Site Scripting attack via error messages returned by the server. The application does not properly encode error message returned from server and executes code.
IJ22783: SECURITY FIXES FOR WEBGUI 810 FP18 SECURITY SCANS (CVE-2020-4196, CVE-2020-4197)
Description:
CVE-2020-4196 - Cross-Site Scripting (XSS) vulnerability have been identified on Tool Prompt Configuration page of Tivoli Netcool/OMNIbus WebGUI.
CVE-2020-4196 - Cross-Site Scripting (XSS) vulnerability have been identified on Tool Prompt Configuration page of Tivoli Netcool/OMNIbus WebGUI.
CVE-2020-4197 - The following Tivoli Netcool/OMNIbus WebGUI pages have been identified not have Cache-control set that may cause browser to cache data from web server response:-
- WebGUI Datasource admin page
- WebGUI Metrics admin page
- WebGUI Tool Prompts admin page
- WebGUI Relationship admin page
- SessionService
- WebGUI Datasource admin page
- WebGUI Metrics admin page
- WebGUI Tool Prompts admin page
- WebGUI Relationship admin page
- SessionService
On
[{"DNLabel":"8.1.0-TIV-NCOMNIbus_GUI-FP0017-TF0003","DNDate":"02 Mar 2020","DNLang":"English","DNSize":"40813446 B","DNPlat":{"label":"Linux","code":"PF016"},"DNURL":"http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Tivoli&product=ibm/Tivoli/Tivoli+Netcool+OMNIbus&release=All&platform=All&function=fixId&fixids=8.1.0-TIV-NCOMNIbus_GUI-FP0017-TF0003&includeSupersedes=0","DNURL_FTP":"","DDURL":null}]
Document Location
Worldwide
[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSSHTQ","label":"Tivoli Netcool\/OMNIbus"},"Component":"WebGUI","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"8.1.0 FP17","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]
Product Synonym
OMNIbus_GUI 8.1.0 FP0017 TF0003; OMNIbus_GUI 8.1.0 Fix Pack 17 Test Fix TF0003; OMNIbus_GUI 8.1.0.17.TF0003; 8.1.0.17.TF0003; Web GUI 8.1.0.17.TF0003; Web GUI 8.1.0 Fix Pack 17 Test Fix TF0003; Web GUI 8.1.0 FP0017 TF0003
Problems (APARS) fixed
Was this topic helpful?
Document Information
Modified date:
02 March 2020
UID
ibm15690505