IBM Support

IT35920: TEMPORARY COOKIE FROM DASHBOARD UI DOES NOT HAVE HTTPONLY OR SECURE SET

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Dashboard UI creates a cookie called TEMP. It does not have
    httpOnly or secure set. The cookie does not have value so there
    is no security vulnerability but we should fix this to avoid
    false positive from scan.
    

Local fix

  • B2BISFG-56173
    

Problem summary

  • Users Affected:
    All
    
    
    
    
    Problem Description:
    Dashboard UI creates a cookie called TEMP. It does not have
    httpOnly or secure flag set.
    But the cookie value is empty so there is no security
    vulnerability.
    
    
     Platforms Affected:
    All
    

Problem conclusion

  • Resolution Summary:
    A code fix is provided.
    Fixed the problem so httpOnly and secure flags are set.
    
    Delivered in:
    6010002
    5020605_4
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT35920

  • Reported component name

    STR B2B INTEGRA

  • Reported component ID

    5725D0600

  • Reported release

    610

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-02-16

  • Closed date

    2021-03-11

  • Last modified date

    2021-05-17

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    STR B2B INTEGRA

  • Fixed component ID

    5725D0600

Applicable component levels

[{"Line of Business":{"code":"LOB02","label":"AI Applications"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS3JSW","label":"IBM Sterling B2B Integrator"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"610"}]

Document Information

Modified date:
18 May 2021