IBM Support

IJ50209: SET HSTS HEADER FOR INTERNAL PERFMON REST HTTPS SERVER ON 9980

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Setting security header as suggested by RFC 6797
    

Local fix

Problem summary

  • Setting security header as suggested by RFC 6797
    

Problem conclusion

  • This problem is fixed in 5.1.9.3
    To see all Spectrum Scale APARs and their respective
    Fix solutions refer to page:
    https://public.dhe.ibm.com/storage/spectrumscale/spectrum_scale_
    apars.html
    
    Benefits of the solution:
    Setting Security header to help security stance and prevent
    findings from port scanners.
    
    Work Around:
    None
    
    Problem trigger:
    Running Scale 5.1.2 or later
    
    Symptom:
    Unexpected Results/Behavior  [not really, unless one really
    looks at the returned header fields of the HTTP response - body
    data is not affected]
    
    Platforms affected:
    ALL Linux OS environments
    
    Functional Area affected:
    perfmon (Zimon)
    
    Customer Impact:
    Suggested
    

Temporary fix

Comments

APAR Information

  • APAR number

    IJ50209

  • Reported component name

    SPEC SCALE STD

  • Reported component ID

    5737F33AP

  • Reported release

    519

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2024-02-22

  • Closed date

    2024-02-22

  • Last modified date

    2024-02-22

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    SPEC SCALE STD

  • Fixed component ID

    5737F33AP

Applicable component levels

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"STXKQY"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"519","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
22 February 2024