Role Package Administration prone to introduce inconsistencies in 6.10.101
search cancel

Role Package Administration prone to introduce inconsistencies in 6.10.101

book

Article ID: 267732

calendar_today

Updated On:

Products

CA Automic Dollar Universe

Issue/Introduction

A UVMS user that has only a group 'UVMS Package administration' assigned is able to 

- Access to node settings of UVMS 
- Create User with admin rights
- Modify the password of the user admin

 

Environment

UVMS 6.10.101, UVC 6.10.101

Cause

This a defect of the UVMS application in the handling of the security handling.

 

Resolution

This bug is now fixed, and the correction will come with version 6.10.111 and 7.00.21.

Both UVMS Service Packs are expected to be delivered mid of July 2023.

Code change was done to handle package administration logic, giving limited access to user with this role and no security features. 

Additional Information

Bug ID: DU_AS-7104
Bug Title: The Role Package Administration is DANGEROUS