IBM Support

IJ34996: USER CAN MODIFY AVAILABILITY DATA DESPITE READ-ONLY ACCESS TO GRV

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • STEPS TO REPRODUCE:
    - Log in as user maxadmin.
    - In Security Groups, create a new Group (eg, 'GRV-R' with
    description = GVR Read only) with Default Application =
    GRESOURCE.
    - Set access to All Sites and save. On Labor tab, grant the
    option "Authorize Group for all Labor?" and save.
    - On the Applications tab, find Graphical Resource View and in
    Options, only grant access for 'Read' option.
    - In Users tab, add a User that does not belong to another
    Security Group with more extensive access to Graphical Resource
    View (eg, user ALVIN with alvin/alvin) and save.
    - Still logged in as maxadmin, open the Graphical Resource View
    application.
    - Select an existing record and go to Graphical View tab.
    - The Labor record and their Day shifts are showing in
    Graphical View.
    - Select a category in the drop-down menu (eg, VAC), Full Day
    and then click on a shift in the calendar view.
    - The box changes from a green Day shift to a purple VAC shift.
    This is expected.
    - Log out and log in as the User that was added to the new
    Security Group GRV-R (eg, user ALVIN).
    - Go to the Graphical Resource View application.
    - Select the same record GRV-W and try to modify the
    Description field: it is read-only, which is normal.
    - Go to Graphical View tab.
    - The Labor rows are showing and their shifts are showing.
    - Select a category in the drop-down menu (eg, VAC), Full Day
    and then click on a shift in the calendar view: the box changes
    from a green Day shift) to a purple VAC shift.
    - This should not be occurring because only Read access was
    granted for the Graphical Resource View application.
    RESULTS:
    If you access the Graphical Resource View application as a
    Maximo user belonging to a Security Group with Read-only access
    to that GRV application, you can actually modify the shifts in
    the Graphical View tab, such as adding non-work time.
    EXPECTED RESULTS:
    You should not be able to modify the shifts in the Graphical
    View tab if you access the Graphical Resource View application
    as a Maximo user belonging to a Security Group with Read-only
    access to that GRV application.
    
    REPORTED IN VERSION:
    Maximo TPAE 7.6.1.2 with Scheduler 7.6.8.0
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * Scheduler users                                              *
    ****************************************************************
    

Problem conclusion

  • The fix for this APAR is contained in the following maintenance
    package: | Release 7.6.1.3 of Base Services
    

Temporary fix

Comments

APAR Information

  • APAR number

    IJ34996

  • Reported component name

    MAXIMO SCHEDULE

  • Reported component ID

    5724R46SE

  • Reported release

    768

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-09-14

  • Closed date

    2021-09-29

  • Last modified date

    2021-09-29

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    MAXIMO SCHEDULE

  • Fixed component ID

    5724R46SE

Applicable component levels

[{"Line of Business":{"code":"LOB59","label":"Sustainability Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS9NUN","label":"Maximo Asset Management Scheduler"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"768"}]

Document Information

Modified date:
30 September 2021