IBM Support

PK52702: Z/OS IBM HTTP SERVER FOR WEBSPHERE (POWERED BY APACHE) FIX PACK 6.1.0.13

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • z/OS IBM HTTP Server for WebSphere (powered by Apache) Fix Pack
    6.1.0.13
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All users of IBM HTTP Server for WebSphere   *
    *                 (powered by Apache) V6.1.0 for z/OS          *
    *                                                              *
    ****************************************************************
    * PROBLEM DESCRIPTION: APAR PK52702 addresses various defects  *
    *                      in IBM HTTP Server for WebSphere        *
    *                      (powered by Apache) on z/OS             *
    *                                                              *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    APAR PK52702 fixes the following defects in IBM HTTP Server for
    WebSphere (powered by Apache) V6.1.0 for z/OS:
    
    APAR    Description
    ------- --------------------------------------------------------
    PK49295 CVE-2006-5752 mod_status cross-site scripting
    vulnerability
    PK49355 CVE-2007-1863 mod_cache crash with malicious request
    PK50460 mod_deflate with vary headers doesn't work
    PK50469 CVE-2007-3847 proxy buffer over-read vulnerability
    PK50467 CVE-2007-3304 MPM signalling vulnerability
    PK48505 HTTP status codes are changed to HTTP 500 when
    mod_deflate added and SetOutputFilter directive specified
    PK48412 IBM HTTP Server logs bad date when certificate has
    expired
    
    *** NOTE ***
    Additional information about the APARs listed above can be found
    in RETAIN or by using the APAR search facility located at URL:
    
    http://www.ibm.com/software/webservers/appserv/was/support/
    
    Once at this web page, the APAR search facility can be found in
    the "Self help" section under "Solve a problem". Click on
    "-> APARs" to access the APAR search faciltiy.
    
    Once the APAR search utility is accessed, APAR numbers from
    the above list can be used as "Additional search terms" to
    locate an APAR's associated documentation.
    

Problem conclusion

  • APAR PK52702 fixes various defects in IBM HTTP Server for
    WebSphere (powered by Apache) V6.1.0 for z/OS.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PK52702

  • Reported component name

    WAS IHS ZOS

  • Reported component ID

    5655I3510

  • Reported release

    610

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2007-09-11

  • Closed date

    2007-09-26

  • Last modified date

    2007-12-03

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UK30625

Fix information

  • Fixed component name

    WAS IHS ZOS

  • Fixed component ID

    5655I3510

Applicable component levels

  • R038 PSN

       UP

  • R610 PSN UK30625

       UP07/11/24 P F711

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS7K4U","label":"WebSphere Application Server for z\/OS"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.1"}]

Document Information

Modified date:
08 March 2021