{"id":490,"date":"2015-02-20T12:10:44","date_gmt":"2015-02-20T11:10:44","guid":{"rendered":"http:\/\/patrick4pitss.wordpress.com\/?p=162"},"modified":"2017-09-19T13:13:20","modified_gmt":"2017-09-19T11:13:20","slug":"how-to-prevent-unauthorized-users-from-viewing-the-reports-showjobs-in-rwservlet","status":"publish","type":"post","link":"https:\/\/pitss.org\/de\/how-to-prevent-unauthorized-users-from-viewing-the-reports-showjobs-in-rwservlet\/","title":{"rendered":"How to Prevent Unauthorized Users from Viewing the Reports Showjobs in Rwservlet"},"content":{"rendered":"<p>By default, anybody can view the showjobs within the rwservlet. The showjobs page shows a list of all of the reports that were run on the specific reports server (see example below):<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"https:\/\/i0.wp.com\/pitss.org\/us\/files\/2014\/07\/image.png\" alt=\"\" width=\"626\" height=\"648\" \/><\/p>\n<p>If you do not want unauthorized users from viewing this page, and you only wish to have users from a specific IP address to view this, you can control who can view the showjobs page within OHS. You can do so by following the steps below:<\/p>\n<ol>\n<li>Go to %ORACLE_INSTANCE%configOHSohs1moduleconf ($ORACLE_INSTANCE\/config\/OHS\/ohs1\/moduleconf) in Linux<\/li>\n<li>Make a backup of reports_ohs.conf<\/li>\n<li>Using either a text editor or EM FMW Control (Web Tier, right-click on ohs1, go to Administration \u2013&gt; Advanced Configuration, then select \u201creports_ohs.conf\u201d), open up reports_ohs.conf.<\/li>\n<li>Below the last &lt;\/Location&gt; tag, add the following:<\/li>\n<\/ol>\n<p>&lt;Location \/reports\/rwservlet\/<b><strong>showjobs<\/strong><\/b>&gt;<br \/>\nSetHandler weblogic-handler<br \/>\nWebLogicHost server.domain.com<br \/>\nWebLogicPort 9002<\/p>\n<p>Order deny,allow<br \/>\nDeny from all<br \/>\nAllow from 10.1.1.10 server.domain.com<\/p>\n<p>&lt;\/Location&gt;<\/p>\n<p>NOTE: Edit the WebLogicHost with your PC\/server name. Also, add the IP addresses or PC\/server hostnames in the \u201cAllow from\u201d which will have access to the showjobs page. Separate each IP address or hostname with spaces.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"https:\/\/i0.wp.com\/pitss.org\/us\/files\/2014\/07\/image1.png\" alt=\"\" width=\"717\" height=\"526\" \/><\/p>\n<ol start=\"5\">\n<li>If using a text editor, save and close the file. If you are using EM, click \u201cApply\u201d to save all changes.<\/li>\n<li>Restart OHS using either OPMNCTL or EM.<\/li>\n<\/ol>\n<p>After configuring the steps above, only the PCs or servers in the \u201cAllow from\u201d line will be allowed to view the showjobs. Here is what happens when a PC not in the \u201cAllow from\u201d exceptions list tries to access the showjobs page:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"https:\/\/i0.wp.com\/pitss.org\/us\/files\/2014\/07\/image_thumb2.png\" alt=\"image\" width=\"321\" height=\"187\" \/><\/p>\n<p><b><strong>NOTE: You are welcome to apply the same steps above for any of the other rwservlet commands such as showenv.<\/strong><\/b><\/p>\n<p><b><strong>IMPORTANT: This security only works when using OHS. Using port 9002 will NOT have this restriction.<\/strong><\/b><\/p>\n<p><b><strong>Source: Oracle Support note 261645.1<\/strong><\/b><\/p>\n<p>Created from:\u00a0http:\/\/pitss.org\/us\/2014\/07\/02\/how-to-prevent-unauthorized-users-from-viewing-the-reports-showjobs-in-rwservlet\/<\/p>\n<p><a href=\"http:\/\/feeds.wordpress.com\/1.0\/gocomments\/patrick4pitss.wordpress.com\/162\/\" rel=\"nofollow\"><img decoding=\"async\" src=\"http:\/\/feeds.wordpress.com\/1.0\/comments\/patrick4pitss.wordpress.com\/162\/\" alt=\"\" border=\"0\" \/><\/a> <img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/pixel.wp.com\/b.gif?host=patrick4pitss.wordpress.com&amp;blog=33916245&amp;post=162&amp;subd=patrick4pitss&amp;ref=&amp;feed=1\" alt=\"\" width=\"1\" height=\"1\" border=\"0\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By default, anybody can view the showjobs within the rwservlet. The showjobs page shows a list of all of the reports that were run on the specific reports server (see example below): If you do not want unauthorized users from &hellip; <a href=\"https:\/\/patrick4pitss.wordpress.com\/2015\/02\/20\/how-to-prevent-unauthorized-users-from-viewing-the-reports-showjobs-in-rwservlet\/\">Continue reading <span>&rarr;<\/span><\/a><img loading=\"lazy\" decoding=\"async\" alt=\"\" border=\"0\" src=\"https:\/\/pixel.wp.com\/b.gif?host=patrick4pitss.wordpress.com&amp;blog=33916245&amp;post=162&amp;subd=patrick4pitss&amp;ref=&amp;feed=1\" width=\"1\" height=\"1\" \/><\/p>\n","protected":false},"author":48,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[97,100,81],"tags":[119],"class_list":["post-490","post","type-post","status-publish","format-standard","hentry","category-forms_reports","category-general","category-tech-blog","tag-forms-reports"],"_links":{"self":[{"href":"https:\/\/pitss.org\/de\/wp-json\/wp\/v2\/posts\/490","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pitss.org\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pitss.org\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pitss.org\/de\/wp-json\/wp\/v2\/users\/48"}],"replies":[{"embeddable":true,"href":"https:\/\/pitss.org\/de\/wp-json\/wp\/v2\/comments?post=490"}],"version-history":[{"count":1,"href":"https:\/\/pitss.org\/de\/wp-json\/wp\/v2\/posts\/490\/revisions"}],"predecessor-version":[{"id":16997,"href":"https:\/\/pitss.org\/de\/wp-json\/wp\/v2\/posts\/490\/revisions\/16997"}],"wp:attachment":[{"href":"https:\/\/pitss.org\/de\/wp-json\/wp\/v2\/media?parent=490"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pitss.org\/de\/wp-json\/wp\/v2\/categories?post=490"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pitss.org\/de\/wp-json\/wp\/v2\/tags?post=490"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}