Readme file for 3.5.3.6 IBM TRIRIGA Application Platform
This fix pack updates the IBM® TRIRIGA® Application Platform product.
Copyright© International Business Machines Corporation 2019. All rights reserved. US Government Users Restricted Rights - Use, duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp.
Prerequisites and supported products
To install this fix pack, you must have TRIRIGA Application Platform 3.5.3 installed. Platform fix packs are cumulative. All previous 3.5.3 fix packs are included in this fix pack.
What's new in this fix pack
When the IBM TRIRIGA Application Platform 3.5.0 was released in late 2015, it introduced an MVC-based UX framework for Polymer-based applications, also known as the IBM TRIRIGA UX Framework. At the time, our UX release was based on Polymer 1. Our UX framework now supports both Polymer 3 and Polymer 1 UX apps. Both types of UX apps can coexist together in the same environment. If you are interested in converting your custom UX apps from Polymer 1 to Polymer 3, see "Converting UX to Polymer 3" at https://www.ibm.com/developerworks/community/wikis/home?lang=en#!/wiki/IBM%20TRIRIGA1/page/Converting UX to Polymer 3.
Information resources
IBM Knowledge Center
http://www.ibm.com/support/knowledgecenter/SSHEB3_3.5.3/com.ibm.tap.doc/product_landing.html
Access the Knowledge Center to view the product documentation. Topics include product overviews; installation and configuration tasks; instructions for using, administering, and troubleshooting the product; and security information.
Real Estate and Facilities Management community
Use the Real Estate and Facilities Management community to review information such as best practices, performance and tuning, and product integrations. You can also collaborate with IBM experts and the broader user community.
IBM TRIRIGA Application Platform support portal
https://www.ibm.com/support/home/product/B587581X76101M05/IBM_TRIRIGA_Application_Platform
The IBM support resources portal provides access to tools and resources to keep your systems, software, and applications running smoothly. From the support resources portal you can find fixes, service requests, useful links, and an enhanced search to help you find information quickly.
IBM TRIRIGA Information and Support Resources
http://www.ibm.com/support/docview.wss?uid=swg21611356
The IBM TRIRIGA Information and Support Resources page is a collection of links and other resources that provides information and assistance for IBM TRIRIGA products.
Installing the IBM TRIRIGA Application Platform 3.5.3.6 fix pack
To install the TRIRIGA Application Platform 3.5.3.6 fix pack, refer to the following general instructions.
Procedure
Known limitations
The following items are known limitations concerning the IBM TRIRIGA Application Platform 3.5.3.6 fix pack.
Area of Impact | Description |
---|---|
Reporting | Fixed columns within queries and reports do not work. The Fixed Column Count option in the Report Builder has no impact. (Tri-51509-IJ04506) |
UX Framework | Globalization of TRIRIGA UX apps created with Polymer 3 is scheduled for a future release. |
Resolved issues
The following issues were resolved in the TRIRIGA Application Platform 3.5.3.6 fix pack.
Security issues
Security issues are resolved in fix packs to ensure that the TRIRIGA Application Platform is secure.
CVSS
IBM does not intend to provide vulnerability details that might enable someone to craft an exploit. IBM uses the Common Vulnerability Scoring System (CVSS) as a standard for communicating the impact of security vulnerabilities in IBM products and solutions. CVSS is an industry open standard for assessing the severity or impact of computer system security vulnerabilities. This standard attempts to establish a numeric measure that represents how much concern or attention the vulnerability warrants. The resulting CVSS score is based on an assessment of a series of metrics. The CVSS Base Score represents the intrinsic and fundamental characteristics of the vulnerability that are typically constant over time and across user environments.
For more information, see http://www-03.ibm.com/security/secure-engineering/bulletins.html
CVE Score | Title | CVSS Base Score | CVSS Temporal Score | CVSS Vector |
---|---|---|---|---|
CVE-2018-2008 | Information Disclosure Vulnerability | 4.3 | For the current score see https://exchange.xforce.ibmcloud.com/vulnerabilities/155146 | (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) |
CVE-2018-15756 | Denial of Service Vulnerability | 7.5 | For the current score see https://exchange.xforce.ibmcloud.com/vulnerabilities/151641 | (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) |
CVE-2019-4207 | Information Disclosure Vulnerability | 4 | For the current score see https://exchange.xforce.ibmcloud.com/vulnerabilities/159128 | (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) |
CVE-2019-4208 | XML External Entity Injection (XXE) Vulnerability | 7.1 | For the current score see https://exchange.xforce.ibmcloud.com/vulnerabilities/159129 | (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L) |
General issues
APAR Number | Description |
---|---|
IJ12416 | The Excel spreadsheet that is created after you export a TRIRIGA report no longer has the word "null" in cells where the field value was empty in the TRIRIGA report. Each value in the Excel spreadsheet no longer has a blank space at the end of the value. Depending on data composition and the Excel client you are using, the data in a column may not wrap as expected. (Tri-57351) |
IJ12587 | If an extra white space is appended to a report header, it does not cause an error when the report is exported to an Excel file. (Tri-57602) |
IJ13137 | Improved the load time for the Report Manager landing pages (My Reports, Community, System Reports, Administration). When the forms in a Form Builder landing page have several revisions, improved the load time for the Form Builder landing page. The Object Label column on the Form Builder landing page now displays the In Progress object label for new but not yet published forms. (Tri-57603) |
IJ13987 | On a page that has a collapsed query section, if you expand the query section, the expected content now appears regardless of whether the query section is collapsed by default or expanded by default. (Tri-57962) |
The Field Services Named licenses for on premise (LICENSE_IBM_TRIRIGA_Field_Services_Named.properties) and SaaS (LICENSE_IBM_TRIRIGA_Facilities_and_Real_Estate_Management_on_Cloud_Field_Services_Named.properties) were updated. If you have the 'Named' Field Services license, you must contact IBM to obtain the corresponding new 'Authorized' Field Services license. The LICENSE_IBM_TRIRIGA_Field_Services_Authorized.properties file is available on Passport Advantage.
After you upgrade to 3.5.3.6, the 'Named' license no longer works. If your server.log contains a message such as the following, you must remove the LICENSE_IBM_TRIRIGA_Field_Services_Named.properties file and add the LICENSE_IBM_TRIRIGA_Field_Services_Authorized.properties file to each |
|
triplat-auth-check has a new property named model-name that you can use to check the permission for the specified model. It has two methods: getModelPermission checks the permission for a specified model and getActionPermission checks the permission for a specified action. (Tri-56528) | |
A new data source named WORK_PLANNER is added to the UX Framework model builder. A new Polymer 3 UX component named triplat-query-work-planner was created to support the usage to WORK_PLANNER datasources. For more information, read the documentation for the triplat-query-work-planner component in the UX Framework doc pages. (Tri-56544) | |
The following license BIRT reports are now part of the IBM TRIRIGA Application Platform. Do not edit these reports. If you do edit them, they are reloaded on the next application server startup.
|
|
The installation instructions in the fix pack installer and the readme are consistent and more accurate regarding required web server state during installation. (Tri-57533) | |
In the triplat-search-input component, you can now style placeholder text by using the new triplat-search-input-placeholder mixin. (Tri-57534) | |
In the triblock-table component, you use the new on-mouseover event to access the on-row-mouse-over attribute. (Tri-57573) | |
Automatic redeployment to WebLogic now occurs. You do not need to apply the xercesImpl.jar file. (Tri-57773) | |
The UX Framework documentation page (/p/web/doc) now displays the Polymer 3 components. (Tri-57783) | |
License table now supports the Work Planner UX application. triTaskAllocation->triTaskResourceAllocation is now a licensed object. (Tri-57838) | |
In the triplat-number-input component, you can now style with CSS mixins and hide the label of paper-input by using the noLabelFloat property. (Tri-58040) |