IBM Support

JR62380: IIDR SYBASE DMSUPPORTINFO COMMAND MAY COLLECT THE DB USERNAME AND PASSWORD IN PLAINTEXT.

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Dmsupportinfo command  for IIDR Sybase ASE engine included DB
    User and password in trace output extracted  when running ddlgen
    to collect db table ddl as part of collection details.
    
    Fix will prevent tracing these details needed for executing the
    command and avoid exposing the db User /password in other files.
    

Local fix

  • No Local fix to prevent issue.
    
    Remove un-needed dmsupportinfo collections to avoid exposure of
    sensitive  user/login details.
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * This issue might affect you if you are using CDC for Sybase  *
    * 11.3.3.3-109 or earlier.                                     *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * The dmsupportinfo utility used for collecting                *
    * troubleshooting information was collecting the configured    *
    * database username and password.                              *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    

Problem conclusion

  • Upgrading to IDR 11.3.3.3-113 or newer for Sybase resolves the
    issue.
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR62380

  • Reported component name

    IS CDC SYBASE

  • Reported component ID

    5725E30SY

  • Reported release

    B33

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-06-18

  • Closed date

    2020-08-27

  • Last modified date

    2020-08-27

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    IS CDC SYBASE

  • Fixed component ID

    5725E30SY

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSTRGZ","label":"InfoSphere Data Replication"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"B33","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
14 December 2020