I saw something that may be related with ITSM 7.6.4 SP1 and IE8 - When I log in more than one user on browser clients, the last user logged in takes over all sessions. So if I login Michel, open a new browser and log in Allen (the test data accounts), then go back to Michel's browser session and open a ticket or a console, it will say "Welcome Allen" and will list Allen as the user in the bottom left status bar. It will also save with Allen's user information. It doesn't give Michel Allen's admin list of forms, but it does let Michel create and update entries as if he was Allen.
(Not only is this a serious security issue, but it significantly hampers my ability as an administrator if I can no longer have multiple user sessions running from one workstation for testing and troubleshooting.) I haven't tried this with Firefox. Kelly Logan, Sr. Systems Administrator (Remedy), GMS ProQuest | 789 E. Eisenhower Parkway, P.O. Box 1346 | Ann Arbor MI 48106-1346 USA | 734.997.4777 kelly.lo...@proquest.com<mailto:kelly.lo...@proquest.com> www.proquest.com ProQuest...Start here. 2010 InformationWeek 500 Top Innovator P Please consider the environment before printing this email. This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the sender, and delete the message from your computer. -----Original Message----- From: Action Request System discussion list(ARSList) [mailto:arslist@ARSLIST.ORG] On Behalf Of Raido Oja Sent: Monday, June 13, 2011 11:14 AM To: arslist@ARSLIST.ORG Subject: ITSM 7.6.04 and IE 6 - overview console picking up incorrect user Hi All, We are experiencing some strange behaviour with ITSM 7.6.04 and IE 6 (we don't have this issue with Firefox). When logging in, overview console opens. The hello at the top states my name however while the console is loading I can see that the login name in the status bar switches to some other recently logged in user and the tickets displayed are that other user's tickets. Selecting My Selected Groups I can also see the other user's groups. Looks like a caching issue, right? We cleared local cache, disabled proxy, released that other user from the server, restarted IIS and still the other user's details are being picked up. BMC is saying IE 6 is not supported on 7.6.04 anymore (according to the current compatibility matrix it still is!). We tracked the http packages and can see that the cookie returnd contains the incorrect login ID. Can anyone suggest what is happening here? It is consistent, happens on all platforms, PCs. The only common nominator seems to be IE 6. Thanks, Raido _______________________________________________________________________________ UNSUBSCRIBE or access ARSlist Archives at www.arslist.org<http://www.arslist.org> attend wwrug11 www.wwrug.com<http://www.wwrug.com> ARSList: "Where the Answers Are" _______________________________________________________________________________ UNSUBSCRIBE or access ARSlist Archives at www.arslist.org attend wwrug11 www.wwrug.com ARSList: "Where the Answers Are"