IBM Support

IT23523: WEB SERVER FILE DOWNLOAD AND REMOTE COMMAND EXECUTION - VULNERABILITY

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Test Requests and Responses:
    
    GET /mailbox/alibaba.pl HTTP/1.1
    Cookie: JSESSIONID=193ro4lhn8gy1lm2erwvd7v1;
    SCI_DLSSO=U2Vzc2lvbklEMTkzcm80bGhuOGd5MWxtMmVyd3ZkN3Yx
    Accept-Language: en-US Accept:
    text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
    Referer: https://10.252.138.54:8081/mailbox
    Host: 10.252.138.54:8081
    User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0;
    rv:11.0)
    like Gecko
    
    HTTP/1.1 200 OK
    X-FRAME-OPTIONS: SAMEORIGIN
    X-Content-Type-Options: nosniff
    Content-Type: text/html; charset=utf-8
    Expires: Thu, 01-Jan-1970 00:00:00 GMT
    Cache-Control: no-cache, must-revalidate
    Pragma: no-cache
    Content-Length: 8987
    Set-Cookie:
    JSESSIONID=huyso56s9d0k1oqemflxfrmgf;Path=/mailbox/;Secure;HttpO
    nly
    Set-Cookie: hideSplash=true
    charset: UTF-8
    

Local fix

  • RTC -  549723
    

Problem summary

  • Users Affected:
    All
    
    Problem Description:
    Web Server File Download and Remote Command Execution-
    Vulnerability.
    
    Platforms Affected:
    All
    

Problem conclusion

  • Resolution Summary:
    A code fix is provided.
    
    Delivered In:
    5020603_6
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT23523

  • Reported component name

    STR B2B INTEGRA

  • Reported component ID

    5725D0600

  • Reported release

    526

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2017-12-16

  • Closed date

    2018-07-09

  • Last modified date

    2018-07-12

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    STR B2B INTEGRA

  • Fixed component ID

    5725D0600

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SS3JSW","label":"Sterling B2B Integrator"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"5.2.6","Line of Business":{"code":"LOB59","label":"Sustainability Software"}}]

Document Information

Modified date:
11 September 2024