============================================================================= Run Date: DEC 19, 2024 Designation: PRED*3*7 Package : PRED - PHARMACY DATA UPDATE (DATUP) Priority: Mandatory Version : 3 SEQ #7 Status: Released Compliance Date: JAN 19, 2025 ============================================================================= Subject: DATUP 3.3.01 TECHNICAL REFERENCE MODEL (TRM) COMPLIANCE Category: - Informational - Input Template Description: ============ Data and Table Update Process (DATUP) is a utility that runs an automated process to maintain the First Data Bank Drug Information Framework (FDB-DIF) and VA custom data used by Medication Order Check Healthcare Application (MOCHA) servers. It is also used at the National level by Pharmacy Enterprise Customization System (PECS) and Pharmacy Product System - National (PPS-N). The purpose of this patch is to upgrade Log4j version from log4j-api-2.20.0 to 2.23.1, upgrade jsch version from 0.1.51 to 0.2.19 and upgrade esapi from esapi-2.5.2.0 to 2.5.5.0 to comply with the VA Technical Reference Model (TRM). Patch Components: ----------------- Files & Fields Associated: File Name (Number) Field Name (Number) New/Modified/Deleted ------------------ ------------------- -------------------- N/A Forms Associated: Form Name File Number New/Modified/Deleted --------- ----------- -------------------- N/A Mail Groups Associated: Mail Group Name New/Modified/Deleted --------------- -------------------- N/A Options Associated: Option Name Type New/Modified/Deleted ----------- ---- -------------------- N/A Protocols Associated: Protocol Name New/Modified/Deleted ------------- -------------------- N/A Security Keys Associated: Security Key Name ----------------- N/A Templates Associated: Template Name Type File Name (Number) New/Modified/Deleted ------------- ---- ------------------ -------------------- N/A Remote Procedures Associated: Remote Procedure Name New/Modified/Deleted --------------------- -------------------- N/A Parameter Definitions Associated: Parameter Name New/Modified/Deleted -------------- -------------------- N/A New Service Requests (NSRs): --------------------------- N/A Patient Safety Issues (PSIs): ---------------------------- N/A Defect Tracking System Ticket(s) & Overview: ============================================ JIRA Code Task Id: HDSO-8663 JIRA Documentation Task Id: HDSO-8664 Problem: -------- DATUP application contains Java Enterprise components which are subject to Technical Reference Model (TRM) to maintain authority to operate (ATO). Routine Fortify scanning and remediation is performed to maintain compliance. Resolution: ----------- DATUP patch PRED*3.0*7 upgraded Log4j version from log4j-api-2.20.0 to 2.23.1, upgraded to jsch version from 0.1.51 to 0.2.19 and upgraded esapi from esapi-2.5.2.0 to 2.5.5.0 to be compliant with Technical Reference Model (TRM). Participating Test Sites: ------------------------ User acceptance testing completed by the Business Office. SNOW Change Order #: --------------------- N/A Software and Documentation Retrieval Instructions: ------------------------------------------------- The software for this patch is being released using a host file provided to the centralized site. Documentation describing the new functionality is included in this release. Documentation can be found on the VA Software Documentation Library at: https://www.domain.ext/vdl/. Documentation can also be obtained at https://download.vista.domain.ext/index.html/SOFTWARE Documentation Title File Name --------------------------------------------------------------------- Deployment, Installation PRED_3_3_01_P7_DIBR.DOCX Back-Out, and Rollback Guide PRED_3_3_01_P7_DIBR.PDF Patch Installation: ------------------- Pre-Installation Instructions: ------------------------------ N/A Installation Instructions: Patch will be installed by AITC. No action is needed at the sites. For further information on installation of the patch, refer to the section 2 (Deployment) in the PRED_3_3_01_P7_DIBR.DOCX. Post-Installation Instructions: ------------------------------- N/A Back-Out/Roll Back Plan: ------------------------ Patch will be backed out by AITC. For further information on the back out of the patch, refer to the section 4 (Back-Out Procedure) in the PRED_3_3_01_P7_DIBR.DOCX. Validation of Back-out Procedure --------------------------------- Patch will be installed by AITC. For further information, refer to the section 4.2 (Back-Out Verification Procedure) in the PRED_3_3_01_P7_DIBR.DOCX document. Routine Information: ==================== No routines included. Routine Information: ==================== No routines included. ============================================================================= User Information: Entered By : Date Entered : SEP 19, 2024 Completed By: Date Completed: DEC 18, 2024 Released By : Date Released : DEC 19, 2024 ============================================================================= Packman Mail Message: ===================== No routines included