IBM Support

PI91052: SET X-CONTENT-TYPE-OPTIONS "NOSNIFF" ON ADMINISTRATIVE CONSOLE

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • This APAR is open to allow to set X-Content-Type-Options
    "nosniff" on Administrative console.
    

Local fix

  • N.A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server using the administrative console.    *
    ****************************************************************
    * PROBLEM DESCRIPTION: The administrative console did not      *
    *                      set X-CONTENT-TYPE-OPTIONS in the       *
    *                      console response headers.               *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    
    The administrative console did not set
    X-CONTENT-TYPE-OPTIONS in the
    console http response headers.
    

Problem conclusion

  • The administrative console code was modified to add the
    X-CONTENT-TYPE-OPTIONS "NOSNIFF" to the response headers.
    
    The fix for this APAR is currently targeted for inclusion in
    fix pack 7.0.0.45, 8.0.0.15, 8.5.5.13, 9.0.0.7.  Please refer
    to the Recommended Updates
    page for delivery information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    

Temporary fix

Comments

APAR Information

  • APAR number

    PI91052

  • Reported component name

    WEBSPHERE APP S

  • Reported component ID

    5724J0800

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2017-12-04

  • Closed date

    2018-01-26

  • Last modified date

    2018-01-26

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE APP S

  • Fixed component ID

    5724J0800

Applicable component levels

  • R700 PSY

       UP

  • R800 PSY

       UP

  • R850 PSY

       UP

  • R900 PSY

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud \u0026 Data Platform"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"850","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
18 October 2021