IBM Support

PM10625: SENSITIVE INFORMATION IN DEFAULT_CREATE.LOG IF USING WEBSPHERE APPLICATION SERVER (NON-SAF) MANAGED SECURITY

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • When using the zPMT to create a profile using "WebSphere
    Application Server" managed security (as opposed to no security,
     or a z/OS security product), sensitive information might be in
    the default_create.log file that is produced on the target z/OS
    system when the BBOWWPFx job is run to create the profile
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  Users of WebSphere Application Server       *
    *                  for z/OS not using a z/OS security product  *
    ****************************************************************
    * PROBLEM DESCRIPTION: When using the zPMT to create a         *
    *                      profle using "WebSphere Application     *
    *                      Server managed security" (as opposed    *
    *                      to no security, or a z/OS security      *
    *                      product), sensitive information might   *
    *                      be in the default_create.log file       *
    *                      that is produced on the target z/OS     *
    *                      system when the BBOWWPFx job is run     *
    *                      to create the profile.                  *
    *                                                              *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    One of the panels within the zPMT is a panel on which a
    security type for the WebSphere Application Server profile is
    chosen.
    
    On this panel when using option "WebSphere Application Server
    security", sensitive information might be saved.
    
    After generating the customization jobs, uploading them, and
    running the BBOWWPFx job to create the profile, the
    information might be in the default_create.log log file that
    resides within the WAS_HOME directory containing the newly
    created profile.
    

Problem conclusion

  • APAR PM10625 is currently targeted for inclusion in
    Application Server Toolkit 6.1.1.10 ifix 1
    

Temporary fix

Comments

APAR Information

  • APAR number

    PM10625

  • Reported component name

    WEBS APP SERV N

  • Reported component ID

    5724H8800

  • Reported release

    61S

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2010-03-23

  • Closed date

    2010-05-17

  • Last modified date

    2010-05-17

  • APAR is sysrouted FROM one or more of the following:

    PM10454

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBS APP SERV N

  • Fixed component ID

    5724H8800

Applicable component levels

  • R61I PSY

       UP

  • R61W PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.1","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
10 February 2022