IBM Support

PI05413: CPSM WUI JAVA POPUP WARNING ABOUT AN UNSIGNED APPLICATION AFTER APPLYING JAVA MAINTENANCE

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • After upgrading or applying Java maintenance to the Java JRE
    from Sun/Oracle, you begin getting popup warnings about an
    unsigned applet on each interaction with the CPSM WUI.
    
    In January, Oracle issued security bulletin CVE-2013-0422 which
    changed one of the defaults for the JRE. That bulletin can be
    found here
    
    http://www.oracle.com/technetwork/topics/security/alert-cve-2013
    -0422-1896849.html
    
    CPSM needs to address this issue so that a popup warning window
    is not constantly appearing.
    
    Additional Symptom(s) Search Keyword(s): KIXREVSVR
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All CICSPlex SM V5R1M0 Users                 *
    ****************************************************************
    * PROBLEM DESCRIPTION:    After upgrading or applying Java     *
    *                      maintenance to your Java JRE, you begin *
    *                      getting popup warnings about unsigned   *
    *                      applets on each interaction with the    *
    *                      CPSM Web User Interface (WUI).          *
    ****************************************************************
    * RECOMMENDATION:    After applying the PTF that resolves      *
    *                 this APAR, all MASes configured as CPSM      *
    *                 WUI servers must be recycled to pick up      *
    *                 the new code.  Note that regions do not      *
    *                 need to be brought down and restarted at     *
    *                 the same time.                               *
    ****************************************************************
       Oracle issued security bulletin CVE-2013-0422 which changed
    one of the defaults for the JRE.  That bulletin can be found
    here:
    
    http://www.oracle.com/technetwork/topics/security/alert-cve-2013
    -0422-1896849.html
    

Problem conclusion

  • Java applets EYUWUIWATCHDOG, which monitors browser sessions,
    and EYUWUILIGHT, which implements special display options like
    range bars and status lights, were distributed as unsigned CLASS
    files.  These applets have been repackaged in a signed JAR.
    

Temporary fix

  • FIX AVAILABLE BY PTF ONLY
    

Comments

APAR Information

  • APAR number

    PI05413

  • Reported component name

    CICS TS Z/OS V5

  • Reported component ID

    5655Y0400

  • Reported release

    80M

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2013-11-04

  • Closed date

    2013-11-21

  • Last modified date

    2015-03-05

  • APAR is sysrouted FROM one or more of the following:

    PI05340

  • APAR is sysrouted TO one or more of the following:

    UI12776

Modules/Macros

  • EYU0VHVA EYU0VHVQ EYU0VHVR EYU0VPAB EYU0VPAP EYU0VUHI EYUEVHVA
    EYUEVPAF EYUEVPNF EYUKVHVA EYUKVPAF EYUKVPNF EYUSVHVA EYUSVPAF
    EYUSVPNF EYUTVTJE EYUTVTJK EYUTVTJS
    

Fix information

  • Fixed component name

    CICS TS Z/OS V5

  • Fixed component ID

    5655Y0400

Applicable component levels

  • R80M PSY UI12776

       UP13/12/02 P F311

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSGMGV","label":"CICS Transaction Server"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"5.1","Edition":"","Line of Business":{"code":"LOB35","label":"Mainframe SW"}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG19M","label":"APARs - z\/OS environment"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"5.1","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
05 March 2015