Download
Abstract
The webcontainer incorrectly handles some requests for a Java™ Server Page (JSP) and, as a result, incorrectly displays the source code.
Download Description
PK32374 resolves the following problem:
ERROR DESCRIPTION:
The source code of a JSP is displayed for specific requests when servlet caching and file serving are
enabled.
LOCAL FIX:
PROBLEM SUMMARY
USERS AFFECTED:
IBM® WebSphere® Application Server version 6.0 users who use servlet caching and file serving.
PROBLEM DESCRIPTION:
The webcontainer incorrectly handles some requests for a JSP and, as a result, displays the source code.
RECOMMENDATION:
None
If a web application is enabled for file serving (fileServingEnabled="true" in the ibm-web-ext.xmi file),
servlet caching is enabled, and the application includes a JSP, it is possible for a request to be made
to access the JSP which will result in the source code of the associated .jsp file being displayed.
Details of the type of requests which will result in such an exposure are not described in order to reduce the exposure.
PROBLEM CONCLUSION:
The webcontainer has been corrected to return an error code (403 or 404) when such requests are made.
The fix for this APAR is currently targeted for inclusion in Fix Pack 6.0.2.17 and 6.1.0.5.
Refer to the recommended updates page for delivery information:
http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
Prerequisites
Download the UpdateInstaller below to install this fix.
Installation Instructions
Review the readme.txt for detailed installation instructions.
Technical Support
Contact IBM Support using SR (http://www.ibm.com/software/support/probsub.html), visit the WebSphere Application Server Support Web site (http://www.ibm.com/software/webservers/appserv/was/support/), or contact 1-800-IBM-SERV(U.S. only).
Problems (APARS) fixed
Was this topic helpful?
Document Information
Modified date:
15 June 2018
UID
swg24015155