SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 64159: The monitor.incidentComponentSecurity.ignored property in SAS® Enterprise GRC might not work as expected

DetailsHotfixAboutRate It

When you specify the following configuration property, SAS Enterprise GRC might enable a user with a lower security clearance to see an incident with a higher security classification:

monitor.incidentComponentSecurity.ignored = true

However, the web application might return an HTTP 500 error when the user tries to edit an incident with a higher security classification.

Below is an example of how to replicate this problem:

  1. In configdata.properties, set monitor.incidentComponentSecurity.ignored = true.
  2. Set the security clearance for the user X, such as "Available only to Senior Managers in Business Units."
  3. Log on as an administrator, and create an event that has higher security clearance, such as "Available only to Senior Managers in Head Quarters."
  4. Log on as user X, and try to edit the event. You see an HTTP 500 error.

Click the Hot Fix tab in this note to access the hot fix for this issue.

When you specify monitor.incidentComponentSecurity.ignored = true, you can prevent a user with a lower security clearance from seeing incidents containing a higher security classification by specifying the following new configuration property:

monitor.incidentQuery.confidentialityLevelEnabled = true


Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Enterprise GRCSolaris for x646.19.4 TS1M2
Linux for x646.19.4 TS1M2
HP-UX IPF6.19.4 TS1M2
64-bit Enabled Solaris6.19.4 TS1M2
64-bit Enabled AIX6.19.4 TS1M2
Windows 7 Ultimate x646.19.4 TS1M2
Windows 7 Ultimate 32 bit6.19.4 TS1M2
Windows 7 Professional x646.19.4 TS1M2
Windows 7 Professional 32 bit6.19.4 TS1M2
Windows 7 Home Premium x646.19.4 TS1M2
Windows 7 Home Premium 32 bit6.19.4 TS1M2
Windows 7 Enterprise x646.19.4 TS1M2
Windows 7 Enterprise 32 bit6.19.4 TS1M2
Microsoft Windows Server 2012 Std6.19.4 TS1M2
Microsoft Windows Server 2012 R2 Std6.19.4 TS1M2
Microsoft Windows Server 2012 R2 Datacenter6.19.4 TS1M2
Microsoft Windows Server 2012 Datacenter6.19.4 TS1M2
Microsoft Windows Server 2008 for x646.19.4 TS1M2
Microsoft Windows Server 2008 R26.19.4 TS1M2
Microsoft Windows Server 20086.19.4 TS1M2
Microsoft Windows 106.19.4 TS1M2
Microsoft Windows 8.1 Pro x646.19.4 TS1M2
Microsoft Windows 8.1 Pro 32-bit6.19.4 TS1M2
Microsoft Windows 8.1 Enterprise x646.19.4 TS1M2
Microsoft Windows 8.1 Enterprise 32-bit6.19.4 TS1M2
Microsoft Windows 8 Pro x646.19.4 TS1M2
Microsoft Windows 8 Pro 32-bit6.19.4 TS1M2
Microsoft Windows 8 Enterprise x646.19.4 TS1M2
Microsoft Windows 8 Enterprise 32-bit6.19.4 TS1M2
Microsoft® Windows® for x646.19.4 TS1M2
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.