This document contains important security information for SBM . This document is only available to registered customers who log in to the Support site. Last updated on 2019-02-25.
: A serious security issue affecting SBM , RCE 0-day exploit, has been found for log4j 2.0 – 2.14.1. For further information on the vulnerability, you can follow the Apache Log4j site . See the resolution below to eliminate the vulnerability in SBM.
SBM makes connections to the database server from Windows (Internet Information Service) and from Java. It will make as many connections as it needs to simultaneously service requests. Idle connections should be reused as needed.
IMPORTANT: The steps to enable NTCR with SSO have changed slightly beginning in SBM 10.1.3. Please refer to the Installation and Configuration Guide in the section called "Configuring SSO and Windows Domain Authentication" for complete details.
The user logs onto Windows The user starts a web browser (IE, Firefox...) and opens up the SBM User Workspace and is presented with a login page After signing in to SBM, the user launches another web browser (IE, Firefox... must be the same browser program as in 2) and goes to the Dimensions CM web page.