============================================================================= Run Date: DEC 13, 2022 Designation: PSO*7*688 Package : PSO - OUTPATIENT PHARMACY Priority: Mandatory Version : 7 SEQ #574 Status: Released Compliance Date: JAN 13, 2023 ============================================================================= Subject: Inbound eRx - SwA Software Composition Analysis Updates Category: - Informational - Other Description: ============ The Inbound eRx JAVA application is a component of the PRE IEP program that provides the capability to receive inbound eRx's from an external provider. The JAVA application provides a user interface that allows end users to manage and monitor eRx processing from external sources. This patch provides resolutions for the following issues: 1 - Resolves issues reported by the Software Assurance (SwA) team with vulnerabilities detected within the libraries and frameworks used in the application. 2 - Addresses Long Delays in Rx delivery due to loads larger than the current design can process. Defect Tracking System Ticket(s) & Overview: ============================================ Problem 1: --------- 1 - Software Assurance (SwA) team detected vulnerabilities within several libraries and frameworks that were used by the application. Jira Defects: (EPRESCRIB-3560/EPRESCRIB-3561/EPRESCRIB-3562/EPRESCRIB-3563/EPRESCRIB-35 64) Resolution: ----------- 1 - The libraries and frameworks with known vulnerabilities were updated within the application to patched versions of the libraries and frameworks in question to eliminate the issues reported by the SwA team. Problem 2: --------- Current design of ERX application is incapable of processing the higher volumes of prescription orders quicky at the hub and in turn causing delays in delivering these prescription messages to VistA. Jira Defect: HDSO-238 Resolution: ----------- Long Delays in eRx orders delivery to VistA can be reduced by performing the below steps: a) Disabling Provider and Drug Check for ERX messages on the Inbound Erx Hub. b) Splitting MBM site by creating separate partition for MBM and Non-MBM sites for processing incoming prescription orders. Patient Safety Issues: ====================== N/A Participating Test Sites: ========================= VHA PBM Business Office Software and Documentation Retrieval Instructions: ------------------------------------------------- The PSO*7*688 Informational Patch is available in FORUM. Documentation can be found in the VA Documentation Library (VDL) at: https://www.domain.ext/vdl/ PSO*7*688 Documentation can also be obtained at: https://download.vista.domain.ext/index.html/SOFTWARE. Title File Name ------------------------------------------------------------------ Deployment, Installation, pso_7_0_p688_dibr.docx Back-out, and Rollback Guide pso_7_0_p688_dibr.pdf Installation Instructions: ------------------------- This is a Java Application, and it is deployed on the centralized Weblogic application server. No installation is required at Local sites. Routine Information: ==================== No routines included. ============================================================================= User Information: Entered By : Date Entered : JUN 01, 2022 Completed By: Date Completed: DEC 13, 2022 Released By : Date Released : DEC 13, 2022 ============================================================================= Packman Mail Message: ===================== No routines included