IBM Support

IJ11039: NETCOOL USER PASSWORD SHOWN IN PLAIN TEXT IN OBJECTSERVER LOG

Direct links to fixes

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Debug Log Message Shows Netcool User Password
    in Plain text when User is added or updated in
    Objectserver:
    
    2018-11-06T15:41:21: Debug: D-OBX-105-010: Client language
    command on connection ID 1: [root][Administrator][][hammer]
    [create user 'TEST1' id 2 full name 'TESTTEST' password 'STEVE'
    PAM false].
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * Users of the ObjectServer                                    *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * The ObjectServer would log all incoming SQL statements to    *
    * its debug log file. This would include any plaintext         *
    * passwords that were present in "alter user" or "create user" *
    * commands. The ObjectServer now attempts to scrub these       *
    * plaintext passwords so they are not logged. This is not      *
    * completely foolproof as syntax errors prevent knowing        *
    * whether a command contains a plaintext password or not, and  *
    * so the ObjectServer does this on a best effort basis. The    *
    * SQL generated by all of the standard shipped tools           *
    * (nco_confpack, nco_adduser, nco_config, etc) should have     *
    * plaintext passwords safely scrubbed when logged.             *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Apply the maintenance vehicles listed in the Problem         *
    * Conclusion.                                                  *
    ****************************************************************
    

Problem conclusion

  • The fix for this APAR is contained in the following maintenance
    packages:
    | fix pack | 8.1.0-TIV-NCOMNIbus-FP0022
    

Temporary fix

Comments

APAR Information

  • APAR number

    IJ11039

  • Reported component name

    NETCOOL/OMNIBUS

  • Reported component ID

    5724O4800

  • Reported release

    810

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-11-07

  • Closed date

    2019-10-04

  • Last modified date

    2019-10-04

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    NETCOOL/OMNIBUS

  • Fixed component ID

    5724O4800

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSSHTQ","label":"Tivoli Netcool\/OMNIbus"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"810","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
17 March 2023