IBM Support

IJ16598: ALL SERVICES INDEPENDENTLY OF ITEM SET ARE VISIBLE IN THE LOOKUP OF SERVICES ON A SR.

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as fixed if next.

Error description

  • When selecting service using the lookup on a new SR, all the
    services are visible even though they belong to an item set
    (via connection to org and site) the user does not have
    security access to.
    
    Application
    =============
    SR and Commodities
    
    Steps to reproduce
    ===================
    
    1. Log in to demo env as MAXADMIN and goto the Security
    application.
    
    2. Create a new group called SASITES (South America sites).
    
    3. Goto the tab Sites and add the sites CHILEHDQ and CONCSITE.
    Do NOT check the alternative "Authorize Group for All Sites".
    
    4. Goto the tab Applications and give full access to the
    application Service Request.
    
    5. Goto the user application and create a new user TESTUSER &
    setup password
    
    6. Give the user TESTUSER access to the new group SASITES.
    
    7. Log in as the new user TESTUSER.
    
    8. Goto the Service request application and create a new
    Service Request.
    
    9. Click on the lookup for the service group field.
    
    The list is empty because there are no services groups (of type
    PROVIDER) for ITEMSET2 (which is the item set used for EAGLESA)
    --> This behaviour is correct
    
    10. Now Click on the lookup for the service field.
    
    RESULTS / PROBLEM
    ==================
    The list shows all 33 of the services even though they are not
    connected to ITEMSET2, this is a bug.
    
    TESTUSER, with access only to EAGLESA-sites should not be able
    to see records in the commodity table with an item set they in
    practice do not have access to.
    
    Expected Results
    ================
    The list should also be empty because there are no services (of
    type PROVIDER) for ITEMSET2 (which is the item set used for
    EAGLESA).
    
    Product Version
    ===============
    Tivoli's process automation engine 7.6.0.10 Build 20181212-1733
    DB Build V76010-17
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * YES                                                          *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * The fix for this APAR is contained in 7.6.0.10 and 7.6-CD    *
    * for the next release                                         *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    IJ16598

  • Reported component name

    ADMINISTRATION

  • Reported component ID

    5724R46A1

  • Reported release

    760

  • Status

    CLOSED FIN

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-06-05

  • Closed date

    2020-05-13

  • Last modified date

    2020-05-13

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Modules/Macros

  • MAXIMO
    

Fix information

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSCHPP5","label":"System Related"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
16 May 2020