IBM Support

PM62623: Tools;DXL Library menu gives users without DXL run powers ability to run custom code

Subscribe

You can track all active APARs for this component.

APAR status

  • Closed as program error.

Error description

Local fix

Problem summary

  • By default, custom menus are created in
    DOORSHOME\lib\dxl\addins\. There is a sample in there which can
    be run by selecting the "User;Example user function" menu. It
    can also be run by selecting the Tools;DXL Library menu,
    expanding "User defined DXL library" and then either
    double-clicking or "User function" or by selecting it and
    clicking run.
    
    If DXL security is enabled, and the DXL home and addins paths
    are located elsewhere, the menu entry is correctly updated, but
    the DXL run via the DXL Library menu option is still the local
    version.
    
    Furthermore, if the user doesn't have "Edit DXL" powers, they
    can still run the code (the local version, which has now been
    potentially maliciously modified) by double-clicking it in the
    DXL Library.
    

Problem conclusion

  • The code has been changed so that the behaviour is as expected
    when the appropriate DXL powers are set
    

Temporary fix

Comments

  • This happens in versions of DOORS prior to DOORS 9.5.1.2
    

APAR Information

  • APAR number

    PM62623

  • Reported component name

    TLOGIC DOORS

  • Reported component ID

    5724V61DR

  • Reported release

    920

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2012-04-17

  • Closed date

    2013-11-07

  • Last modified date

    2013-11-07

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    TLOGIC DOORS

  • Fixed component ID

    5724V61DR

Applicable component levels

  • R951 PSY

       UP



Document information

More support for: Rational DOORS

Software version: 9.2

Reference #: PM62623

Modified date: 07 November 2013