============================================================================= Run Date: AUG 14, 2026 Designation: WEBP*1*64 Package : WEBP - PATIENT CENTERED MANAGEMENT Priority: Mandatory Version : 1 SEQ #61 Status: Released Compliance Date: SEP 14, 2026 ============================================================================= Subject: PCMM WEB DEFECT AND SECURITY SCAN REMEDIATION XXVIII Category: - Informational Description: ============ The purpose of the patch is to remediate security issues, correct defects, and perform adaptive maintenance. There are six issues, two are defects and four are adaptive maintenance issues. Defects: -------- 1.PCMMW-5056 - Adjust Selected Patients did not keep the selected patients when returning to the patient list. 2.PCMMW-5331 - The List All Teams page limited Rows per page to 100, so users could not view all teams on one page. Adaptive Maintenance: --------------------- 1.PCMMW-5064 - Add validation to room assignment logic to ensure that FTEs are appropriate for room type to prevent user's possible data manipulation bypassing UI validations. 2.PCMMW-5065 - Update outdated maven plugins. 3.PCMMW-5066 - Clean java code from joda references. 4.PCMMW-5067 - Remediate java code and maven build configuration security issues flagged by CodeQL and Fortify. EHRM Impact Statement: ---------------------- This patch can be installed at all sites, including EHRM converted sites. Patch Components: ----------------- Files & Fields Associated: File Name (Number) Field Name (Number) New/Modified/Deleted ------------------ ------------------- -------------------- N/A Forms Associated: Form Name File Number New/Modified/Deleted --------- ----------- -------------------- N/A Mail Groups Associated: Mail Group Name New/Modified/Deleted --------------- -------------------- N/A Options Associated: Option Name Type New/Modified/Deleted ----------- ---- -------------------- N/A Protocols Associated: Protocol Name New/Modified/Deleted ------------- -------------------- N/A Security Keys Associated: Security Key Name ----------------- N/A Templates Associated: Template Name Type File Name (Number) New/Modified/Deleted ------------- ---- ------------------ -------------------- N/A Remote Procedures Associated: Remote Procedure Name New/Modified/Deleted --------------------- -------------------- N/A Parameter Definitions Associated: Parameter Name New/Modified/Deleted -------------- -------------------- N/A Additional Information: ----------------------- N/A New Service Requests (NSRs): N/A Patient Safety Issues (PSIs): N/A Defect Tracking System Ticket(s) & Overview: -------------------------------------------- 1.PCMMW-5056 - Adjust Selected Patients did not keep the selected patients when returning to the patient list. Problem: -------- When a user chose Adjust Selected Patients for a large group of patients and returned to the patient list, the previously selected patients were no longer checked, so the selections were lost. Resolution: ----------- The application now keeps the previously selected patients checked when returning to the list, even when the list is large and takes longer to load. 2.PCMMW-5331 - The List All Teams page limited Rows per page to 100, so users could not view all teams on one page. Problem: -------- On the List All Teams page, the Rows per page option allowed a maximum of 100 rows, so users could not view all teams on a single page. Resolution: ----------- The Rows per page options now allow displaying up to 5,000 rows, so users can view many more teams, or all of them, on a single page. Adaptive Maintenance Tracking System Ticket(s) & Overview: ---------------------------------------------------------- 1.PCMMW-5064 - Add validation to room assignment logic to ensure that FTEs are appropriate for room type to prevent user's possible data manipulation bypassing UI validations. Problem: -------- The system did not re-check room assignment rules on the server, so a modified request could bypass the on-screen checks and assign staff time to a room type that should not be allowed. Resolution: ----------- Added server-side validation to confirm staff time assignments match the room type before saving, preventing assignments that get around the on-screen checks. 2.PCMMW-5065 - Update outdated maven plugins. Problem: -------- Some of the tools used to build and package the application were out of date. Resolution: ----------- Updated the build tools to current supported versions. 3.PCMMW-5066 - Clean java code from joda references. Problem: -------- The application still relied on an outdated date and time library. Resolution: ----------- Removed the outdated date and time library and replaced it with the current standard library. 4.PCMMW-5067 - Remediate java code and maven build configuration security issues flagged by CodeQL and Fortify. Problem: -------- Automated security scans flagged multiple code and build configuration issues for remediation. Resolution: ----------- Fixed the issues that represented true findings and annotated the false positives. Test Sites: ----------- Memphis VA Medical Center (Memphis, TN) Omaha VA Medical Center (Omaha, Nebraska) SNOW Change Order #: -------------------- CHG0762820 - Centralized Servers - Austin Information Technology Center, Austin, TX Software and Documentation Retrieval Instructions: -------------------------------------------------- PCMM Web patch, WEBP*1*64, is a centrally managed web-based application and will be implemented and deployed to a central web server. Sites do not need to download any file for the patch installation. Other Software Files: --------------------- This release also includes other software files. Other software files can be obtained by accessing the URL: https://download.vista.domain.ext/index.html/SOFTWARE File Name Description -------------------------------------------------------- pcmmr_ear-1.0-64-02.ear Installation file pcmmr_unattended_ear-1.0-64-02.ear Installation file cissUserManagement-1.0-64-01.ear Installation file Documentation describing the new functionality is included in this release. Documentation can be found on the VA Software Documentation Library at: https://www.domain.ext/vdl/. Documentation can also be obtained at https://download.vista.domain.ext/index.html/SOFTWARE. Documentation Title File Name --------------------------------------------------------------------- Deployment, Installation Back-Out, WEBP_1.0_64_DIBRG.DOCX and Rollback Guide WEBP_1.0_64_DIBRG.PDF Patch Installation: =================== PCMM Web patch, WEBP*1*64, is a centrally managed web-based application and will be implemented and deployed to a central web server. No installation is required by sites. Pre/Post Installation overview: --------------------------------------- N/A Pre-Installation Instructions: ------------------------------ Installation Instructions: ------------------------- ****************************************************************** ** PLEASE NOTE: THERE IS NO INSTALLATION FOR THIS PATCH. ** ****************************************************************** This informational patch, WEBP*1.0*64, is for PCMM Web. Installation is done on a centralized server. Please refer to the WEBP_1.0_64_DIBRG.PDF for more details. Post-Installation Instructions: ----------------------------- N/A Back-Out Plan: -------------------------- Backout plan is provided as part of deployment guide detailed in the Deployment, Installation Back-Out, and Rollback Guide. Routine Information: ==================== No routines included. ============================================================================= User Information: Entered By : Date Entered : JUL 10, 2026 Completed By: Date Completed: AUG 14, 2026 Released By : Date Released : AUG 14, 2026 ============================================================================= Packman Mail Message: ===================== No routines included