APAR status
Closed as program error.
Error description
Log into the portal, go to applications -> credentials so the browser invokes the URL https://<portal-domain>/<provider-org>/ <catalog>/application/credentials Check http request and response in the browser developer tools and you will see, that the cookie value is also contained in the X-Speed-Cache-Uid response header. Pen tester recommends to not disclose the value of the session cookie in other http headers. It is not possible for the customer to remove this header
Local fix
Problem summary
The sessionid was present in a cookie that was not related to managing the session.
Problem conclusion
The cookie that cointained the sessionid has been removed. Fixed in API Connect 10.0.5.6 and 10.0.8.0
Temporary fix
Comments
APAR Information
APAR number
LI83109
Reported component name
API CONNECT ENT
Reported component ID
5725Z2201
Reported release
A0X
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2023-12-21
Closed date
2024-02-20
Last modified date
2024-02-20
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
API CONNECT ENT
Fixed component ID
5725Z2201
Applicable component levels
[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSMNED","label":"IBM API Connect"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"A0X","Line of Business":{"code":"LOB67","label":"IT Automation \u0026 App Modernization"}}]
Document Information
Modified date:
20 February 2024