IBM Support

PH01781: IMPLEMENT ADDITIONAL HTTPS SECURITY HEADERS FOR WEBISPF.

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • IMPLEMENT ADDITIONAL HTTPS SECURITY HEADERS FOR WEBISPF.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    *  All users of IBM z/OSMF WebISPF task                        *
    *                 V2R2 and V2R3.                               *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    *  This APAR adds three additional http                        *
    *                      headers that are                        *
    *                      "X-Content-Type-Options",               *
    *                      "X-XSS-Protection" and                  *
    *                      "Strict-Transport-Security".            *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    This APAR adds three additional
    http headers that are
    "X-Content-Type-Options",
    "X-XSS-Protection" and
    "Strict-Transport-Security".
    

Problem conclusion

  • This APAR adds three additional http headers
    that are "X-Content-Type-Options", "X-XSS-Protection"
    and "Strict-Transport-Security".
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH01781

  • Reported component name

    Z/OSMF ISPF

  • Reported component ID

    5655S2801

  • Reported release

    221

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-08-16

  • Closed date

    2019-01-22

  • Last modified date

    2019-03-01

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UI60847 UI60855

Modules/Macros

  • IZUISAPP
    

Fix information

  • Fixed component name

    Z/OSMF ISPF

  • Fixed component ID

    5655S2801

Applicable component levels

  • R231 PSY UI60847

       UP19/02/06 P F902

  • R221 PSY UI60855

       UP19/02/06 P F902

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":null,"label":null},"Product":{"code":"SG19O","label":"APARs - MVS environment"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"221","Edition":"","Line of Business":{"code":"","label":""}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG19M","label":"APARs - z\/OS environment"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"221","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
01 March 2019