Skip to Main Content
Merative Ideas Portal

Shape the future of Merative!

We invite you to shape the future of Merative, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Post your ideas

Start by posting ideas and requests to enhance a product or service. Take a look at ideas others have posted and upvote them if they matter to you,

  1. Post an idea

  2. Upvote ideas that matter most to you

  3. Get feedback from the Merative team to refine your idea

Help Merative prioritize your ideas and requests

The Merative team may need your help to refine the ideas so they may ask for more information or feedback. The offering manager team will then decide if they can begin working on your idea. If they can start during the next development cycle, they will put the idea on the priority list. Each team at Merative works on a different schedule, where some ideas can be implemented right away, others may be placed on a different schedule.

Receive notification on the decision

Some ideas can be implemented at Merative, while others may not fit within the development plans for the product. In either case, the team will let you know as soon as possible. In some cases, we may be able to find alternatives for ideas which cannot be implemented in a reasonable time.


Merative External Privacy Statement: https://www.merative.com/privacy

Status Future consideration
Created by Guest
Created on Dec 5, 2018

BIRT report vulnerability

User has reported the BIRT report vulnerability for where User can generate the report for other User or Location.

The issue can be replicated for v7.0.2 on OOTB. Please find the replication steps as follows:
1. Login using caseworker - iwuser and navigate to home page and pods.
2. Using developer tools of the browser, inspect the element for the birt table and copy the url: https://localhost:9044/CuramBIRTViewer/run?__report=components/Intake/birt/AssignedApplicationReport.rptdesign&userName=iwuser&__locale=en_US
3. Change the username in the username to ewuser on the browser as per below url: https://localhost:9044/CuramBIRTViewer/run?__report=components/Intake/birt/AssignedApplicationReport.rptdesign&userName=ewuser&__locale=en_US
User can view the pod graphs for ewuser, by changing the username for iwuser. Let me know if there are any further queries.

Customer Name Singapore, MSF - Singapore
  • Attach files
  • Shantanu Agnihotri
    Reply
    |
    Apr 18, 2019

    Hi Shane,

    Apologies for the late reply, what sort of the details would you require for the the BIRT online reports which has "LocationID" and "OutcomeID" as parameters?

    Regards,
    Shantanu

  • Guest
    Reply
    |
    Feb 21, 2019

    Hi Shantanu,

    To help us progress this further can you please add more details here of the reports that contain the "LocationID" and "OutcomeID" parameters.

    Thank you,
    Shane McFadden, Cúram SPM Product Management team

  • Guest
    Reply
    |
    Dec 27, 2018

    Hi Shane,

    I would like to re-iterate that the issue was mainly raised that there are parameters like "LocationID" and "OutcomeID" , which users are able to manipulate to generate the report for different locations. The example of the OOTB cases which has "userName" parameter in the url was just shown as an example of the issue, so that PD team can replicate the same.

    With this, I want to draw the attention, that the main issue is the parameters like LocationID and Outcome Plan ID, which users are able to changes, and hence the focus of the fixture should be on any parameters present in the url should either be not displayed or should be not editable by the client.


    Please help to expedite the same. Thanks.

    Regards,
    Shantanu

  • Guest
    Reply
    |
    Dec 6, 2018

    Hi Fu (jasley),

    We acknowledge that this enhancement request has been accepted for consideration. It may not be delivered within the release currently under development however the theme is aligned with our current multi-year strategy and will be considered for a future release.

    IBM may consider and evaluate any RFE Community feedback for this request through activities such as voting.

    IBM will update this request in the future.

    Thank you for your interest in the Cúram product.
    Shane McFadden, Cúram SPM Product Management team

  • Guest
    Reply
    |
    Dec 6, 2018

    Hi Fu (jasley),

    Thank you for your enhancement request.
    We require some further analysis to determine whether or not this enhancement can be considered in a future release.
    I will provide another response when our investigation is complete.

    Thank you,
    Shane McFadden, Cúram SPM Product Management team