A fix is available
APAR status
Closed as program error.
Error description
PROBLEM DESCRIPTION: the ITM web server responds to nonexistent web page requests with the default return page. This can be viewed as a security exposure. RECREATE INSTRUCTIONS: This can be demonstrated by attempting to attach to sites such as http://servername:PORT/kdh/bigBanana http://servername:PORT/kdh/hotDogs
Local fix
N/A
Problem summary
**************************************************************** * USERS AFFECTED: All ITMS/ENGINE users. * **************************************************************** * PROBLEM DESCRIPTION: HTTP: KDH RESPONDING TO NONEXISTENT WEB * * PAGE. * **************************************************************** * RECOMMENDATION: Apply the PTF. * **************************************************************** The IBM Tivoli Monitoring Tivoli Enterprise Basic Services (TEBS) web server responds to nonexistent web page requests with the default return page. This can be viewed as a security exposure.
Problem conclusion
Code changed to recognize nonexistent web pages and return the standard HTTP 404 NOT FOUND status code.
Temporary fix
Comments
APAR Information
APAR number
OA38973
Reported component name
MGMT SERVER DS
Reported component ID
5608A2800
Reported release
623
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt
Submitted date
2012-03-02
Closed date
2012-03-05
Last modified date
2012-04-03
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Modules/Macros
KDELIB
Fix information
Fixed component name
CT/ENGINE
Fixed component ID
5608A41CE
Applicable component levels
R623 PSY UA64470
UP12/03/09 P F203
Fix is available
Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSC6ML7","label":"IBM Tivoli OMEGAMON CT\/ENGINE"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"623","Edition":"","Line of Business":{"code":"","label":""}}]
Document Information
Modified date:
03 April 2012