IBM Support

IT24768: USER LOGIN CREDENTIALS CAN BE ACCESSED USING THE BACK BUTTON

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • All POST requests
    containing authentication credentials must be followed by a
    HTTP 302
    redirect not a HTTP 200 or browsers will be able to replay the
    request
    with the login credentials. This allows the credentials to be
    discovered.
    
    - Reproduce the issue like :
    1- login to the dashboard
    2- hit back button Confirm that the username is visible  in the
    login box ( using IE , you should not see it with chrome )
    3- hit forwad button &  go back to dashboard
    4- Click on logout  to fall on the login page
    5- Hit forward button and get a part of the dashboard header ,
    with login page displayed
    6- Hit Refresh button and resubmit the request , then confirm
    you are  logged in the dashboard without entering any password .
    

Local fix

  • RTC : 552864
    EJ/EJ
    None
    

Problem summary

  • Users Affected:
    All
    
    Problem Description:
    User login credentials can be accessed using the back button.
    
    Platforms Affected:
    All
    

Problem conclusion

  • Resolution Summary:
    
    A code fix is provided.
    
    Delivered In:
    5020603_6
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT24768

  • Reported component name

    STR B2B INTEGRA

  • Reported component ID

    5725D0600

  • Reported release

    526

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-04-18

  • Closed date

    2018-07-10

  • Last modified date

    2018-07-11

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    STR B2B INTEGRA

  • Fixed component ID

    5725D0600

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS3JSW","label":"Sterling B2B Integrator"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"5.2.6","Line of Business":{"code":"LOB59","label":"Sustainability Software"}}]

Document Information

Modified date:
11 September 2023