Fixes are available
7.0.0.39: WebSphere Application Server V7.0 Fix Pack 39
8.5.5.8: WebSphere Application Server V8.5.5 Fix Pack 8
8.0.0.12: WebSphere Application Server V8.0 Fix Pack 12
8.5.5.9: WebSphere Application Server V8.5.5 Fix Pack 9
7.0.0.41: WebSphere Application Server V7.0 Fix Pack 41
8.5.5.10: WebSphere Application Server V8.5.5 Fix Pack 10
8.5.5.11: WebSphere Application Server V8.5.5 Fix Pack 11
8.0.0.13: WebSphere Application Server V8.0 Fix Pack 13
7.0.0.43: WebSphere Application Server V7.0 Fix Pack 43
8.5.5.12: WebSphere Application Server V8.5.5 Fix Pack 12
8.0.0.14: WebSphere Application Server V8.0 Fix Pack 14
8.5.5.13: WebSphere Application Server V8.5.5 Fix Pack 13
7.0.0.45: WebSphere Application Server V7.0 Fix Pack 45
8.0.0.15: WebSphere Application Server V8.0 Fix Pack 15
7.0.0.45: Java SDK 1.6 SR16 FP60 Cumulative Fix for WebSphere Application Server
7.0.0.39: Java SDK 1.6 SR16 FP7 Cumulative Fix for WebSphere Application Server
7.0.0.41: Java SDK 1.6 SR16 FP20 Cumulative Fix for WebSphere Application Server
7.0.0.43: Java SDK 1.6 SR16 FP41 Cumulative Fix for WebSphere Application Server
8.5.5.14: WebSphere Application Server V8.5.5 Fix Pack 14
8.5.5.15: WebSphere Application Server V8.5.5 Fix Pack 15
8.5.5.17: WebSphere Application Server V8.5.5 Fix Pack 17
8.5.5.20: WebSphere Application Server V8.5.5.20
8.5.5.18: WebSphere Application Server V8.5.5 Fix Pack 18
8.5.5.19: WebSphere Application Server V8.5.5 Fix Pack 19
8.5.5.16: WebSphere Application Server V8.5.5 Fix Pack 16
APAR status
Closed as program error.
Error description
The RewriteRule [B] flag doesn't escape characters as it did in earlier versions and as in Apache 2.2.12 and later.
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: IBM HTTP Server users of the RewriteRule * * [B] flag. * **************************************************************** * PROBLEM DESCRIPTION: URL-sensitive characters are not * * being escaped with use of the [B] * * flag. * **************************************************************** * RECOMMENDATION: Apply this fix if using rewriteRule with * * the [B] flag. * **************************************************************** Apache between 2.2.6 and 2.2.11 had a regression where the [B] flag stopped escaping most URL-sensitive characters. A new BFlagEscapeAllNonAlnum option has been added to restore the behavior of escaping all non-alphanumeric characters.
Problem conclusion
To opt-in to the updated 'B' flag handling, the customer will need to add the following to each context with 'RewriteEngine ON': RewriteOptions BFlagEscapeAllNonAlnum This fix is targeted for IBM HTTP Server fix packs: - 7.0.0.39 - 8.0.0.12 - 8.5.5.8
Temporary fix
Comments
APAR Information
APAR number
PI45740
Reported component name
WEBS APP SERV N
Reported component ID
5724H8800
Reported release
700
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2015-07-27
Closed date
2015-09-23
Last modified date
2015-09-23
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
IBM HTTP SERVER
Fixed component ID
5724J0801
Applicable component levels
R700 PSY
UP
R800 PSY
UP
R850 PSY
UP
Document Information
Modified date:
07 September 2022