IBM Support

LI80953: SECURITY VULNERABILITY: HTTP SECURITY HEADER NOT DETECTED

Direct links to fixes

7.5.2.0-WS-ACP-20190620-0958_H9_64-CUMUIFIX-015.32bit.studio
7.5.2.0-WS-ACP-20190620-0934_H15_64-CUMUIFIX-015.32bit.sc-win
7.5.2.0-WS-ACP-20190620-0934_H15_64-CUMUIFIX-015.32bit.sc-linux.sh
7.5.2.0-WS-ACP-20190620-0934_H15_64-CUMUIFIX-015.vcrypt2
7.5.2.0-WS-ACP-20190620-0934_H15_64-CUMUIFIX-015.sc-linux.sh
7.5.2.0-WS-ACP-20190620-0934_H15_64-CUMUIFIX-015.sc-win
7.5.2.0-WS-ACP-20190620-0958_H9_64-CUMUIFIX-015.studio
7.5.2.0-WS-ACP-20190620-0934_H15_64-CUMUIFIX-015.builtDockerImage
7.5.2.0-WS-ACP-20190620-0934_H15_64-CUMUIFIX-015.32bit.sc-linux.sh
7.5.2.0-WS-ACP-20190620-0934_H15_64-CUMUIFIX-015.sc-linux.sh
7.5.2.0-WS-ACP-20190620-0934_H15_64-CUMUIFIX-015.docker
7.5.2.0-WS-ACP-20190718-0858_H15_64-CUMUIFIX-016.sc-win
7.5.2.0-WS-ACP-20190718-0858_H15_64-CUMUIFIX-016.32bit.sc-win
7.5.2.0-WS-ACP-20190718-0858_H15_64-CUMUIFIX-016.vcrypt2
7.5.2.0-WS-ACP-20190718-0845_H9_64-CUMUIFIX-016.32bit.studio
7.5.2.0-WS-ACP-20190718-0845_H9_64-CUMUIFIX-016.studio
7.5.2.0-WS-ACP-20190718-0858_H15_64-CUMUIFIX-016.docker
7.5.2.0-WS-ACP-20190718-0858_H15_64-CUMUIFIX-016.sc-linux.sh
7.5.2.0-WS-ACP-20190718-0858_H15_64-CUMUIFIX-016.32bit.sc-linux.sh
7.5.2.0-WS-ACP-20190728-1413_H15_64-CUMUIFIX-017.32bit.sc-linux.sh
7.5.2.0-WS-ACP-20190728-1413_H15_64-CUMUIFIX-017.sc-linux.sh
7.5.2.0-WS-ACP-20191009-1107_H15_64-CUMUIFIX-018.32bit.sc-linux.sh
7.5.2.0-WS-ACP-20191009-1107_H15_64-CUMUIFIX-018.32bit.sc-win
7.5.2.0-WS-ACP-20191009-1107_H15_64-CUMUIFIX-018.sc-linux.sh
7.5.2.0-WS-ACP-20191009-1500_H8_64-CUMUIFIX-018.32bit.studio
7.5.2.0-WS-ACP-20191009-1107_H15_64-CUMUIFIX-018.sc-win
7.5.2.0-WS-ACP-20191009-1107_H15_64-CUMUIFIX-018.docker
7.5.2.0-WS-ACP-20191009-1500_H8_64-CUMUIFIX-018.studio
7.5.2.0-WS-ACP-20191009-1107_H15_64-CUMUIFIX-018.vcrypt2
7.5.2.0-WS-ACP-20191031-1217_H15_64-CUMUIFIX-019.32bit.sc-win
7.5.2.0-WS-ACP-20191031-1217_H15_64-CUMUIFIX-019.vcrypt2
7.5.2.0-WS-ACP-20191031-1217_H15_64-CUMUIFIX-019.docker
7.5.2.0-WS-ACP-20191031-1217_H15_64-CUMUIFIX-019.32bit.sc-linux
7.5.2.0-WS-ACP-20191031-1217_H15_64-CUMUIFIX-019.sc-win
7.5.2.0-WS-ACP-20191030-1839_H9_64-CUMUIFIX-019.32bit.studio
7.5.2.0-WS-ACP-20191031-1217_H15_64-CUMUIFIX-019.sc-linux
7.5.2.0-WS-ACP-20191030-1839_H9_64-CUMUIFIX-019.studio
7.5.2.0-WS-ACP-20191201-1341_H18_64-CUMUIFIX-019.32bit.sc-linux
7.5.2.0-WS-ACP-20191201-1341_H18_64-CUMUIFIX-019.sc-linux.sh
7.5.2.0-WS-ACP-20191201-1341_H18_64-CUMUIFIX-020.32bit.sc-linux.sh
7.5.2.0-WS-ACP-20191201-1341_H18_64-CUMUIFIX-020.sc-linux.sh
7.5.2.0-WS-ACP-20191201-1341_H18_64-CUMUIFIX-020.32bit.sc-win
7.5.2.0-WS-ACP-20191201-1341_H18_64-CUMUIFIX-020.sc-win
7.5.2.0-WS-ACP-20191203-0906_H8_64-CUMUIFIX-020.32bit.studio
7.5.2.0-WS-ACP-20191203-0906_H8_64-CUMUIFIX-020.studio
7.5.2.0-WS-ACP-20191201-1341_H18_64-CUMUIFIX-020.vcrypt2
7.5.2.0-WS-ACP-20191201-1341_H18_64-CUMUIFIX-020.docker
7.5.2.0-WS-ACP-20200117-0152_H18_64-CUMUIFIX-021.32bit.sc-linux.sh
7.5.2.0-WS-ACP-20200117-0152_H18_64-CUMUIFIX-021.sc-linux.sh
7.5.2.0-WS-ACP-20200117-0153_H9_64-CUMUIFIX-021.32bit.studio
7.5.2.0-WS-ACP-20200117-0153_H9_64-CUMUIFIX-021.studio
7.5.2.0-WS-ACP-20200117-0152_H18_64-CUMUIFIX-021.vcrypt2
7.5.2.0-WS-ACP-20200117-0152_H18_64-CUMUIFIX-021.32bit.sc-win
7.5.2.0-WS-ACP-20200117-0152_H18_64-CUMUIFIX-021.docker
7.5.2.0-WS-ACP-20200117-0152_H18_64-CUMUIFIX-021.sc-win
7.5.2.0-WS-ACP-20200128-1852_H8_64-CUMUIFIX-022.32bit.studio
7.5.2.0-WS-ACP-20200128-1930_H15_64-CUMUIFIX-022.32bit.sc-linux.sh
7.5.2.0-WS-ACP-20200128-1852_H8_64-CUMUIFIX-022.studio
7.5.2.0-WS-ACP-20200128-1930_H15_64-CUMUIFIX-022.32bit.sc-win
7.5.2.0-WS-ACP-20200128-1930_H15_64-CUMUIFIX-022.sc-linux.sh
7.5.2.0-WS-ACP-20200128-1930_H15_64-CUMUIFIX-022.sc-win
7.5.2.0-WS-ACP-20200128-1930_H15_64-CUMUIFIX-022.vcrypt2
7.5.2.0-WS-ACP-20200317-0337_H18_64-CUMUIFIX-023.vcrypt2
7.5.2.0-WS-ACP-20200317-0337_H18_64-CUMUIFIX-023.32bit.sc-linux.sh
7.5.2.0-WS-ACP-20200317-0337_H18_64-CUMUIFIX-023.sc-linux.sh
7.5.2.0-WS-ACP-20200317-0337_H18_64-CUMUIFIX-023.32bit.sc-win
7.5.2.0-WS-ACP-20200317-0337_H18_64-CUMUIFIX-023.sc-win
7.5.2.0-WS-ACP-20200317-0948_H8_64-CUMUIFIX-023.32bit.studio
7.5.2.0-WS-ACP-20200317-0948_H8_64-CUMUIFIX-023.studio
7.5.2.0-WS-ACP-20200408-0619_H18_64-CUMUIFIX-024.vcrypt2
7520-ifix-025-appliance.xml
7.5.2.0-WS-ACP-20200424-1857_H15_64-CUMUIFIX-025.32bit.sc-linux.sh
7.5.2.0-WS-ACP-20200424-1857_H15_64-CUMUIFIX-025.sc-linux.sh
7.5.2.0-WS-ACP-20200424-1857_H15_64-CUMUIFIX-025.32bit.sc-win
7.5.2.0-WS-ACP-20200424-1857_H15_64-CUMUIFIX-025.sc-win
7.5.2.0-WS-ACP-20200424-1858_H8_64-CUMUIFIX-025.studio
7.5.2.0-WS-ACP-20200424-1857_H15_64-CUMUIFIX-025.vcrypt2
7.5.2.0-WS-ACP-20200424-1858_H8_64-CUMUIFIX-025.32bit.studio
7.5.2.0-WS-ACP-20200601-0614_H9_64-CUMUIFIX-026.32bit.sc-linux.sh
7.5.2.0-WS-ACP-20200601-0614_H9_64-CUMUIFIX-026.sc-linux.sh
7.5.2.0-WS-ACP-20200601-0614_H9_64-CUMUIFIX-026.32bit.sc-win
7.5.2.0-WS-ACP-20200601-0614_H9_64-CUMUIFIX-026.sc-win
7.5.2.0-WS-ACP-20200601-0615_H8_64-CUMUIFIX-026.32bit.studio
7.5.2.0-WS-ACP-20200601-0615_H8_64-CUMUIFIX-026.studio
7.5.2.0-WS-ACP-20200601-0614_H9_64-CUMUIFIX-026.vcrypt2
App Connect Professional V7.5.2.0 cumulative ifix 027 for hypervisor upgrade file
App Connect Professional V7.5.2.0 cumulative ifix 027 for Secure connector 32-bit installer for Linux
App Connect Professional V7.5.2.0 cumulative ifix 027 for Secure connector 64-bit installer for Linux
App Connect Professional V7.5.2.0 cumulative ifix 027 for Secure connector 32-bit installer for Windows
App Connect Professional V7.5.2.0 cumulative ifix 027 for Secure connector 64-bit installer for Windows
App Connect Professional V7.5.2.0 cumulative ifix 026 for Studio 32-bit installer
App Connect Professional V7.5.2.0 cumulative ifix 026 for Studio 64-bit installer
7.5.2.0-WS-ACP-20201030-0736_H8_64-CUMUIFIX-028.32bit.sc-linux.sh
7.5.2.0-WS-ACP-20201030-0736_H8_64-CUMUIFIX-028.sc-linux.sh
7.5.2.0-WS-ACP-20201030-0736_H8_64-CUMUIFIX-028.32bit.sc-win
7.5.2.0-WS-ACP-20201030-0736_H8_64-CUMUIFIX-028.sc-win
7.5.2.0-WS-ACP-20201030-0736_H9_64-CUMUIFIX-028.32bit.studio
7.5.2.0-WS-ACP-20201030-0736_H9_64-CUMUIFIX-028.studio
7.5.2.0-WS-ACP-20201030-0736_H8_64-CUMUIFIX-028.vcrypt2
7.5.2.0-WS-ACP-20210504-1008_H15_64-CUMUIFIX-030.vcrypt2
7.5.2.0-WS-ACP-20210824-1823_H8_64-CUMUIFIX-031.32bit.studio
7.5.2.0-WS-ACP-20210824-1823_H8_64-CUMUIFIX-031.studio
7.5.2.0-WS-ACP-20210824-1823_H15_64-CUMUIFIX-031.sc-linux.sh
7.5.2.0-WS-ACP-20210824-1823_H15_64-CUMUIFIX-031.vcrypt2
7.5.2.0-WS-ACP-20210824-1823_H15_64-CUMUIFIX-031.32bit.sc-win
7.5.2.0-WS-ACP-20210824-1823_H15_64-CUMUIFIX-031.32bit.sc-linux.sh
7.5.2.0-WS-ACP-20210824-1823_H15_64-CUMUIFIX-031.sc-win

 

APAR status

  • Closed as program error.

Error description

  • As part of system security vulnerability scan, ACP port 443
    (management port):
    Results:
    X-XSS-Protection HTTP Header missing on port 443.GET / HTTP/1.1
    Host: wdvca99a0001.wellsfargo.com
    Connection: Keep-Alive
    X-Content-Type-Options HTTP Header missing on port 443.
    Content-Security-Policy HTTP Header missing on port 443.
    Strict-Transport-Security HTTP Header missing on port 443.
    

Local fix

  • Here are the response headers and values which were addressed .
    Content-Security-Policy: default-src 'self' 'unsafe-inline'
    'unsafe-eval'
    Server: Apache Tomcat
    Strict-Transport-Security: max-age=31536000;includeSubDomains
    X-Content-Type-Options: nosniff
    X-Frame-Options: SAMEORIGIN
    X-XSS-Protection: 1; mode=block
    

Problem summary

  • UPGRADED JAVA TO V8.0.5.37 AND V7.0.10.45 FOR PSIRT
    

Problem conclusion

  • Fixed the issue
    

Temporary fix

Comments

APAR Information

  • APAR number

    LI80953

  • Reported component name

    APP CONNECT PRO

  • Reported component ID

    5737B8200

  • Reported release

    752

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-06-23

  • Closed date

    2019-12-04

  • Last modified date

    2019-12-04

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    APP CONNECT PRO

  • Fixed component ID

    5737B8200

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS3LC4","label":"App Connect Professional"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"752","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
13 September 2023