JESSPOOL ACCESS granted access for a user's high level qualifier even though they are not authorized.

book

Article ID: 48952

calendar_today

Updated On:

Products

Cleanup Datacom DATACOM - AD CIS COMMON SERVICES FOR Z/OS 90S SERVICES DATABASE MANAGEMENT SOLUTIONS FOR DB2 FOR Z/OS COMMON PRODUCT SERVICES COMPONENT Common Services CA ECOMETER SERVER COMPONENT FOC EASYTRIEVE REPORT GENERATOR FOR COMMON SERVICES INFOCAI MAINTENANCE IPC UNICENTER JCLCHECK COMMON COMPONENT Mainframe VM Product Manager CHORUS SOFTWARE MANAGER CA ON DEMAND PORTAL CA Service Desk Manager - Unified Self Service PAM CLIENT FOR LINUX ON MAINFRAME MAINFRAME CONNECTOR FOR LINUX ON MAINFRAME GRAPHICAL MANAGEMENT INTERFACE WEB ADMINISTRATOR FOR TOP SECRET Xpertware Top Secret Top Secret - LDAP Top Secret - VSE

Issue/Introduction

Description:

USERA has the following JESSPOOL permissions:

TSS PERMIT(USERA) JESSPOOL(xxxx.USERA) ACCESS(NONE) 

which should deny access, but it is still granted access to the resource.

Solution:

With the JESSPOOL resource class, if the second high level qualifier is the acid getting the security check, it will always be granted access regardless of what permissions are set.

This is not a bug, but how the code was written.

Users should always be able to get at their own JESSPOOL resources. Otherwise, abends could occur in JES.

This is not just done by CA Top Secret but other z/OS security products.



Environment

Release:
Component: AWAGNT

Resolution

Please Update This Required Field