JESSPOOL ACCESS granted access for a user's high level qualifier even though they are not authorized.

book

Article ID: 48952

calendar_today

Updated On:

Products

CA Cleanup CA Datacom - DB CA Datacom CA Datacom - AD CA Datacom - Server CA CIS CA Common Services for z/OS CA 90s Services CA Database Management Solutions for DB2 for z/OS CA Common Product Services Component CA Common Services CA Datacom/AD CA ecoMeter Server Component FOC CA Easytrieve Report Generator for Common Services CA Infocai Maintenance CA IPC Unicenter CA-JCLCheck Common Component CA Mainframe VM Product Manager CA Chorus Software Manager CA On Demand Portal CA Service Desk Manager - Unified Self Service CA PAM Client for Linux for zSeries CA Mainframe Connector for Linux on System z CA Graphical Management Interface CA Web Administrator for Top Secret CA CA- Xpertware CA Top Secret CA Top Secret - LDAP CA Top Secret - VSE

Issue/Introduction

Description:

USERA has the following JESSPOOL permissions:

TSS PERMIT(USERA) JESSPOOL(xxxx.USERA) ACCESS(NONE) 

which should deny access, but it is still granted access to the resource.

Solution:

With the JESSPOOL resource class, if the second high level qualifier is the acid getting the security check, it will always be granted access regardless of what permissions are set.

This is not a bug, but how the code was written.

Users should always be able to get at their own JESSPOOL resources. Otherwise, abends could occur in JES.

This is not just done by CA Top Secret but other z/OS security products.



Environment

Release:
Component: AWAGNT

Resolution

Please Update This Required Field