CP-IMV-140100-0002 Release Notes

The following defects have been fixed in this Cumulative Patch:
cis141
Defects Fixed
The following defects have been fixed in this Cumulative Patch:
Support Ticket
Engineering Ticket
Problem Summary
Root Cause and Additional Deployment Instructions
Associated Risk
588678
DE329787
Regression of DE258115 - Policy Xpress policy fails to trigger when an account sync is set to task completion. 
The code that was over-written for account sync on task completion caused an issue.
HIGH
851192
DE318066
The Forgotten Password functionality in CA Identity Portal does not allow imLoginId attribute.
The imloginId attribute is not enabled for Forgotten Password authentication.
HIGH
Enhancement
Enhancement
In 14.1, the Policy Xpress date comparison functionality was changed so that it compares two different dates and returns the difference value in number of days and hours. Earlier, the Policy Xpress date comparison functionality used to compare and return the difference value as Earlier, Later or Equals. Existing customers wanted to backport the changes done to the Policy Xpress Date Comparison functionality in 14.1.
The existing Policy Xpress Date Comparison functionality was overwritten with new changes. 
Additional Deployment Instructions:
 
In Identity manager UI, Navigate to Policies --> Policy Xpress --> Create / Modify New Policy
In the Data tab, click Add Data Element --> Select the Category as Comparators --> Type as Comparator -->Function as Compare Dates
In the Return Value field, you can find the new Return Value format - Return the TimeSpan between two dates.
HIGH
Internal
DE327630
When you open the Provisioning Roles tab in the Modify User task screen, an error is thrown. 
The OR and AND operators were compounded in the SQL query which resulted in fetching Provisioning Roles from other environments.  
HIGH
886161
DE329014
On adding a group membership to an existing RACF account, the provisioning server crashes. 
The Provisioning Server crashes as it tries to access an invalid memory address.
HIGH
877295
DE325640
Exceptions are thrown when viewing the Archived Submitted Tasks.
Additional parameters are passed in the SQL preparedStatements when retrieving data from the archive table. 
MEDIUM
854314
DE320251
The Attribute Name is wrongly displayed in the View Submitted Task (VST).
Key is not defined for the Container Handle attribute in the Active Directory metadata.
MEDIUM
871544
DE323350
The task to Add/Remove accounts from the Active Directory group fails. 
The parentContainer name is appended to the uniqueName (SMVA managedObject), and hence fails to match the DistinguishedName in TEWS request.
MEDIUM
Internal
DE320433
When a user modifies an organization details using TEWS call, the  SmApiWrappedException(Unknown TabName) is thrown.
The LDAP query is getting created in the well-known attribute instead of the LDAP physical attribute. 
MEDIUM
858865
DE320276
CA Identity Manager authentication using Active Directory Authentication Module fails to disambiguate a user.
When Active Directory is configured in certain non-standard ways such as multiple forests in the domain, the CA Identity Manager authentication using Active Directory authentication module fails to disambiguate a user.
MEDIUM
841926
DE315883
Identity Theft: Any user can use a browser plugin to inject a header with SM_USER or SM_UNIVERSALID = superadmin (the admin user or any other user). The user then uses the standard login form to provide its own uid.
The user caching in the User Interface caused the problem.
MEDIUM
876386
DE327151
The Forgotten password task fails with the Active Directory Authentication module.
The temporary password generated by the Forgotten Password task cannot be validated against the Active Directory Authentication Module.
MEDIUM
892007
DE329341
NullPointerException on Active Directory Group Search screen.
Direct execution of "Create Active Directory Account Template" task causes a null pointer exception to be thrown.
MEDIUM
819298
DE313461
Unable to detect Skype when acquiring the Active Directory child domain. 
When you are upgrading from Communicator 2007 to Lync 2010 or Lync 2013 or Skype, the Active Directory connector looks for the Skype schema(pool) under "Configuration" naming context(default one) only but not under "Default Naming Context".
MEDIUM
884843
DE326564
Based on the configuration, CA Identity Manager must return the transaction id as TEWS Response before and after the validation or processing of tasks.
This is an enhancement as customers require faster response acknowledgements via TEWS
LOW
645694
DE277464
508 compliance on the Approver Tasks field shows "Select Value" instead of "Select Approver Tasks".
This is an enhancement for CA Identity Manager to be more 508 compliant.
LOW
769905
DE304791
The Date filter in the bulk tasks does not work. 
The date format (yyyyMMdd), which is mandatory, is not checked.
LOW
748176
DE304383
On modifying the Provisioning Role task, improper sync happens between the global users and endpoint accounts.
Improper sync happens because the synchronization is done based on "usersynchronization", and not "Account Synchronization".
LOW
796349
DE313552
Policy Xpress Action Rule condition fails and throws the NullPointerException.
The Null value check is skipped in the Policy Xpress Action Rule.
LOW
748418
DE301741
When you perform Create User or Modify User tasks, the Group tab takes a longer time to display.
This is an enhancement as customers require faster group tab display.
LOW
882108
DE329217
The Credential Provider does not display the Forgotten Password page properly.
Due to compatibility issues, Credential Provider is unable to load the Forgotten Password page properly.
LOW
800700
DE307308
In Siebel 8.1, the Occupied Positions do not populate in the connector.
Siebel 8.1 fetches the Occupied Position values from Business Objects and not from the Business component.
LOW
862307
DE323501
Unable to explore LDAP Devices, and LDAP groups from CA Privileged Access Manager. 
CA Identity Manager PAM connector does not support LDAP Devices and LDAP groups.
LOW
834866
DE314564
In the CA Identity Manager User Console and the Provisioning Server, the "Office" field in the Office365 Connector screen is labelled as "Office Number".
The "Office" field is labelled as "Office Number" in the Office 365 Connector screen. 
LOW