APAR status
Closed as program error.
Error description
Typically, an XML document (SOAP request) with 10,000
attributes (70KB) would take few seconds to parse.
Consequently, an XML document with 100,000 attributes (700KB)
would take several minutes to process.
Local fix Problem summary
****************************************************************
* USERS AFFECTED: WebSphere Application Server users of Web *
* Services. *
****************************************************************
* PROBLEM DESCRIPTION: An XML element with a lot of *
* attributes would cause 100% CPU *
* consumption. *
****************************************************************
* RECOMMENDATION: *
****************************************************************
Typically, an XML document (SOAP request) with 10,000
attributes (70KB) would take few seconds to parse.
Consequently, an XML document with 100,000 attributes (700KB)
would take several minutes to process.
Here is a short example
<SOAP-ENV:Envelope
xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/">
<SOAP-ENV:Body>
<FooBar AAA='' AAB='' AAC='' AAD='' AAE='' AAF='' AAG=''
... [11000 of them] ...
... Dzv='' Dzw='' Dzx='' Dzy='' Dzz='' />
</SOAP-ENV:Body>
</SOAP-ENV:Envelope>
Problem conclusion
Install this APAR to correct the vulnerability.
Temporary fix Comments
APAR information |
APAR number |
PQ80828 |
Reported component name |
WAS BASE 5.0 |
Reported component ID |
5630A3600 |
Reported release |
00W |
Status |
CLOSED PER |
PE |
NoPE |
HIPER |
NoHIPER |
Special Attention |
NoSpecatt |
Submitted date |
2003-11-12 |
Closed date |
2003-12-03 |
Last modified date |
2003-12-03 |
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Modules/Macros
Publications Referenced
Applicable component levels |
R003 PSY |
UP |
R00A PSY |
UP |
R00H PSY |
UP |
R00I PSY |
UP |
R00P PSY |
UP |
R00S PSY |
UP |
R00W PSY |
UP |
R103 PSY |
UP |
R10A PSY |
UP |
R10H PSY |
UP |
R10I PSY |
UP |
R10P PSY |
UP |
R10S PSY |
UP |
R10W PSY |
UP |
|