A fix is available
APAR status
Closed as program error.
Error description
/usr/bin/fcstat is now a setuid program. This is required to view the statistics from the fcs adapter. You must be root to open the device. However it has a side effect of allowing any user to reset the statistics for the adapter. The reset function should check the uid of the id that called it. If it isn't 0 then it should not do the reset.
Local fix
change the permissions of /usr/bin/fcstat with the following command chmod 700 /usr/bin/fcstat this will make fcstat runable by root only.
Problem summary
A non-priviledged user can run fcstat command with the "-z" flag successfully on an FC adapter device which resets the FC related statistics.
Problem conclusion
Proper authorization checking introduced so that only priviledged users who are allowed device management capabilities can run fcstat command with "-z" flag. The user "root" by default has this capability.
Temporary fix
Comments
6100-07 - use AIX APAR IV58415 6100-08 - use AIX APAR IV53867 6100-09 - use AIX APAR IV55767 6100-09 - use AIX APAR IV55767 6100-09 - use AIX APAR IV55767 7100-01 - use AIX APAR IV57658 7100-02 - use AIX APAR IV57176 7100-03 - use AIX APAR IV55835 7100-04 - use AIX APAR IV55824
APAR Information
APAR number
IV58415
Reported component name
AIX 610 STD EDI
Reported component ID
5765G6200
Reported release
610
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Submitted date
2014-04-01
Closed date
2014-04-01
Last modified date
2016-05-10
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
AIX 610 STD EDI
Fixed component ID
5765G6200
Applicable component levels
R610 PSY U865633
UP14/08/11 I 1000
PTF to Fileset Mapping
U865633 devices.common.IBM.fc.rte 6.1.7.19
[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSLLZP","label":"AIX Standard Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSMV87","label":"AIX 6.1 Enterprise Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSMVAX","label":"AIX Express Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSAUMY","label":"IBM AIX Enterprise Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"","label":""}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG11Q","label":"AIX 6.1 HIPERS, APARs and Fixes"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"","label":""}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG11R","label":"APARs - AIX 7.1 environment"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610","Edition":"","Line of Business":{"code":"","label":""}}]
Document Information
Modified date:
10 May 2016