IBM Support

PH16598: QUALYS SCAN IS REPORTING A "QID 11827"

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Qualys scan is reporting a "QID 11827" indicating the following
    headers are missing
    X-XSS-Protection:
    X-Content-Type-Options
    Str
    ict-Transport-Security
    
    Distributed Operating Systems
    WebSphere
    ExtremeSacale V 8.6.1
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  Users of eXtreme Scale Liberty Deployment   *
    ****************************************************************
    * PROBLEM DESCRIPTION: Couple of security headers where        *
    *                      missing in Xsld UI and Rest Apis        *
    *                      Responses.                              *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    Qualys scan reported a "QID 11827" indicating that the below
    three headers are missing
    X-XSS-Protection:
    X-Content-Type-Options
    Strict-Transport-Security
    

Problem conclusion

  • XSLD UI and Rest api code has been
    modified to respond with above mentioned header included.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH16598

  • Reported component name

    WS EXTREME SCAL

  • Reported component ID

    5724X6702

  • Reported release

    861

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-09-09

  • Closed date

    2020-03-09

  • Last modified date

    2020-03-09

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WS EXTREME SCAL

  • Fixed component ID

    5724X6702

Applicable component levels

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSTVLU","label":"WebSphere eXtreme Scale"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"861","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
27 March 2020