IBM Support

OA65839: SDSFVARYDEV SENSITIVITY REPORTED INCORRECTLY FOR READ ACCESS

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • SDSFVaryDev sensitivity reported incorrectly for READ access.
    
    CONTROL access is required to ISFDEV.volser to be able to issue
    V and VF from the DEV panel so reporting the SDSFVaryDev
    sensitivity with READ access is incorrect.
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: Users of zSecure Audit exploiting the        *
    *                 "SENSTRUS - Sensitive Data Trustees" report  *
    *                 (newlist type TRUSTED).                      *
    ****************************************************************
    * PROBLEM DESCRIPTION: zSecure Audit might incorrectly report  *
    *                      an audit concern for the SDSFVaryDev    *
    *                      sensitivity type.                       *
    ****************************************************************
    * RECOMMENDATION: Apply the PTF provided.                      *
    ****************************************************************
    When a RACF resource covered by the ISFDEV.** profiles has READ
    access allowed, the zSecure Audit reports an audit concern for
    that resource (SDSFVaryDev sensitivity) which is incorrect for
    z/OS V2R4 and later.
    

Problem conclusion

  • zSecure Audit has been modified, so that the the audit concern
    for the SDSFVaryDev sensitivity is reported only in cases where
    a RACF resource covered by the ISFDEV.** profiles has CONTROL
    access allowed for z/OS V2R4 and later.
    

Temporary fix

Comments

APAR Information

  • APAR number

    OA65839

  • Reported component name

    ZSEC BASE,ADMIN

  • Reported component ID

    5655T0100

  • Reported release

    250

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2023-11-27

  • Closed date

    2023-12-06

  • Last modified date

    2024-01-02

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UJ94239 UJ94240

Modules/Macros

  • CKASERI  GKRSERI
    

Fix information

  • Fixed component name

    ZSEC BASE,ADMIN

  • Fixed component ID

    5655T0100

Applicable component levels

  • R250 PSY UJ94240

       UP23/12/08 P F312

  • R310 PSY UJ94239

       UP23/12/08 P F312

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSPQTM","label":"IBM Security zSecure Admin"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"250","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
02 January 2024