CLM/ELM extensions stopped working after appliance of newer iFix?


 

Complications

So you have applied the latest iFix as that is the best praticse for your CLM/ELM environment just to find out your widgets have stopped working and you cannot find what could be the cause of the problem?

 
Error: The OpenSocial gadget was not loaded (ID CRJAZ5037E)

1.) Widget Error

With the new iFixes starting from versions ELM 7.0.2 iFix004, ELM 7.0.1 iFix009, CLM 6.0.6.1 iFix018, and CLM 6.0.6 iFix022 the IBM has implemented new security measures to prevent Server-Side Request Forgery (SSRF) vulnerabilities.

This measure has changed the behavior of all OpenSocial gadgets and RSS feeds that fetch content from an external service or location which results in errors when trying to add widgets to your side-panel or dashboard that worked flawlessly before.

Solution?

In order to fix this issue and get your widgets working again you need to add the location (URLs) of your extension hosting servers into jazz "allowlist" first.

You can find the allowlist in JTS application in Admin menu. Navigate to "Advanced properties" and search for "allowlist". 

Here add all URLs resolving to your hosting servers separated by comma without space. (You can type in an asterisk "*" instead to allow all traffic.)

advanced properties is between themes and serviceability, the property is external resources allowlist

2.) Allow list

After this step you need to also add required URLs to the whitelist of CLM/ELM application that you are using your widgets with.

For example if you want to add your widgets to RM applications, navigate to https://yourdomainame.com/rm/admin.
At the bottom of the side-menu click on "Whitelist" and add the required URLs here one by one.

Whitelist is under Communication, you can whitelist a URL by entering the base URL

3.) Whitelist

Now you may continue working with your widgets.

*It may take up to 10 minutes to take changes into effect.

* If you want more information regarding this measure, visit https://www.ibm.com/support/pages/node/6466981

Softacus Services

We, in Softacus, are experts when it comes to consulting and service delivery of IBM software products and solutions in your business. We help our clients to improve visibility and transparency when licensing and managing commercial software, providing measurable value while increasing efficiency and accountability and we are providing services in different areas (see Softacus Services).
IBM ELM extensions developed by Softacus are free of charge for the customers who ordered IBM ELM licenses via Softacus or for the customers who ordered any of our services. If you are interested in any of our IBM ELM extensions, you found a bug or you have any enhancement request, please let us know at This email address is being protected from spambots. You need JavaScript enabled to view it..