PK31231: RESPONSE SPLITTING ADDRESSED IN PQ90505 DOESN'T SEEM TO WORK IN WEBSPHERE 5.0.2.13. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
![]() |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
![]() APAR status Closed as program error. Error description Response splitting addressed in PQ90505 doesn't seem to work in WebSphere 5.0.2.13. Customer's main concern is that a method response.setHeader() must always set only a single header. The http rfc (RFC 2616) is clear on the format of headers, cookies, locations etc., so the customer sees no reason for WebSphere not to check the correctness of the value to ensure compliancy to the RFC.Local fix N/AProblem summary **************************************************************** * USERS AFFECTED: WebSphere Application Server version 5 users * **************************************************************** * PROBLEM DESCRIPTION: Response headers with new lines are * * not handled. * **************************************************************** * RECOMMENDATION: * **************************************************************** Response headers with new lines were not handled properly. Checking was needed to ensure RFC 0822 3.1.1 is followed.Problem conclusion Added additional checking to ensure that RFC 0822 3.1.1 is fully followed by guaranteeing the presence of LWSP (linear white space) after an embedded newline or carriage return/line feed sequence. The fix for this APAR is currently targeted for inclusion in cumulative fix 5.1.1.14. Please refer to the recommended updates page for delivery information: http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980Temporary fix Comments
APAR is sysrouted FROM one or more of the following: APAR is sysrouted TO one or more of the following: Modules/Macros
Publications Referenced
|
Product categories: Software > Application Servers >
Distributed Application & Web Servers > WebSphere Application
Server > General
Operating system(s):
Software version: 10A
Software edition:
Reference #: PK31231
IBM Group: Software Group
Modified date: Mar 1, 2007
(C) Copyright IBM Corporation 2000, 2008. All Rights Reserved.