IBM Support

PI54808: RewriteRule sees un-decoded characters in URL when mod_authnz_saf loaded

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Files that have a blank (%20) in their filename and the url
    accessed has been processed by a rewrite rule are not being
    served by the http server and throw a http error 404
    

Local fix

  • non
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  Users of IBM HTTP Server (powered by        *
    *                  Apache) on z/OS using mod_rewrite and       *
    *                  mod_authnz_saf.                             *
    ****************************************************************
    * PROBLEM DESCRIPTION: A 404 error is returned for some file   *
    *                      urls processed by RewriteRule when      *
    *                      mod_authnz_saf is loaded.               *
    ****************************************************************
    * RECOMMENDATION:  Apply this fix if using RewriteRule with    *
    *                  mod_authnz_saf loaded.                      *
    ****************************************************************
    mod_rewrite is running earlier than intended and seeing
    un-decoded URLs when mod_authnz_saf is loaded.
    This leads to files not being served and a 404 being returned.
    

Problem conclusion

  • mod_rewrite no longer runs early, so all characters will be
    decoded by the time RewriteRule processes a url.
    
    This fix is targeted for IBM HTTP Server updates:
     - 7.0.0.41
     - 8.0.0.13
     - 8.5.5.10
     - 9.0.0.0-PI54808
    

Temporary fix

Comments

APAR Information

  • APAR number

    PI54808

  • Reported component name

    WAS IHS ZOS

  • Reported component ID

    5655I3510

  • Reported release

    700

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2016-01-04

  • Closed date

    2016-02-09

  • Last modified date

    2016-02-09

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WAS IHS ZOS

  • Fixed component ID

    5655I3510

Applicable component levels

  • R700 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS7K4U","label":"WebSphere Application Server for z\/OS"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.0","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
28 April 2022