Patches & Updates
Deploy and monitor updates to all of your systems through Sun from anywhere you have an Internet connection.
Start today with Knowledge-based software update services for Solaris and Linux.
Please review changes to Patch Access.
Patches:
Download Patch (27288617 bytes): HTTP 
Download Signed Patch (27375849 bytes): HTTP 
Signed Patch Documentation  Patch Finder

Obsoleted by: 121510-06 Sun ONE Web Server 6.1 SP9, HP-UX patch


Disclaimer: 

Please note: Although OBSOLETED patches are available on SunSolve, Sun recommends using the most recent patches and the most recent revision of those patches. OBSOLETED patches do not include the latest bug fixes and/or product enhancements, and may require the installation of additional patches as a corrective measure.

Status: OBSOLETE
Patch Id: 121510-05
***********************************************************************
READ THE TERMS OF THE AGREEMENT ("AGREEMENT") IN THE LEGAL_LICENSE.TXT
FILE CAREFULLY BEFORE USING THIS SOFTWARE. BY USING THE SOFTWARE, YOU
AGREE TO THE TERMS OF THIS AGREEMENT. IF YOU DO NOT AGREE TO ALL OF THE
TERMS, PROMPTLY DESTROY THE UNUSED SOFTWARE.
***********************************************************************
Summary: Obsoleted by: 121510-06 Sun ONE Web Server 6.1 SP9, HP-UX patch
Date:  Apr/14/2008
Installation Requirements:
None
Solaris Release: Note: HP-UX
Sun OS Release: Note: HP-UXB11.11.i
Unbundled Product: Sun ONE Web Server
Unbundled Release: 6.1
Xref: This patch is available for Solaris sparc as 116648, Solaris i386 as 116649, Linux as 118202, Windows as 121524
Topic: 
Sun ONE Web Server 6.1, HP-UX patch
Relevant Architecture: pa_risc
BugId's fixed with this patch:

4737204 4856895 4957123 4991884 6066230 6152655 6158040 6197731 6206179 6213097 6235473 6246214 6276594 6279790 6280778 6281323 6285129 6292582 6294743 6295325 6302377 6312702 6315783 6316262 6316387 6316881 6318003 6318200 6318406 6324034 6326965 6329109 6332442 6334248 6335483 6336309 6342394 6343584 6348395 6350122 6350502 6353988 6356179 6358858 6360180 6361485 6364678 6367672 6367812 6370001 6370089 6370259 6376035 6376082 6376278 6376634 6377343 6378473 6379347 6380777 6381747 6382704 6383377 6383971 6384456 6384640 6387080 6387189 6388092 6388230 6388243 6388766 6391505 6391515 6392159 6392644 6394888 6400307 6404983 6418529 6421617 6426382 6428199 6428403 6429293 6433752 6435723 6436535 6437635 6438408 6439519 6441402 6442651 6442778 6448255 6451182 6451285 6455812 6458771 6465691 6471213 6471388 6473494 6477953 6477981 6478972 6480026 6482272 6482560 6482816 6488468 6489275 6494886 6496892 6497487 6497690 6497870 6504581 6507264 6508015 6508084 6508092 6509590 6509623 6510001 6510957 6512624 6513358 6513362 6519021 6519551 6519839 6520528 6524399 6526460 6531111 6534216 6540248 6540788 6540809 6540817 6541955 6541968 6542731 6545817 6546233 6553963 6563615 6567841 6579852 6581407 6582644 6590039 6590893 6590899 6591471 6592886 6598092 6603070 6603088 6609457 6612344 6616612 6619655 6620677 6625264 6625764 6628376 6628914 6630037 6637709 6638185 6643558 6647151 6648161 6649439 6650214

Changes incorporated in this version:

6295325 6509590 6370259 6471213 6504581 6603070 6616612 6619655 6648161 6442778 6510001 6540788 6540817 6542731 6545817 6553963 6563615 6579852 6581407 6582644 6590039 6590893 6590899 6591471 6592886 6598092 6603088 6609457 6612344 6620677 6625264 6625764 6628376 6628914 6630037 6637709 6638185 6643558 6647151 6649439 6650214

Patches accumulated and obsoleted by this patch:

Patches which conflict with this patch: 

Required Patches:

Obsoleted by:
 
Files Included in this Patch: 
Problem Description: 
6295325 Web Server should implement a timeout parameter for it's LDAP connections pool. 
6509590 logger level is not getting from logger config file 
6370259 fastcgistub does not shutdown properly 
6471213 Remove error messages "stderr: Bind Timeout: Timed out" 
6504581 Memory leak in GAT select 1 due to ldap_result() call in LdapSession::bindAsDefault() 
6603070 Incorrect handling of cookie value with single (or double) quote character 
6616612 GAT certs will expire on Oct-16-2007 they need to be refreshed 
6619655 Reverse Proxy Plugin documentation should state that any AS is supported. 
6648161 Check-in hive scripts required to run the QA Stack 
6442778 Calling setContentLength(0) does not give the expected result 
6510001 web.xml's session-timeout is not getting precedence over sun-web.xml's timeOut 
6540788   Admin GUI unable to install SSL server certificate of 99 years and core dump in "security" program 
6540817   WS6.1 support for Windows 2003 SP2 and R2 
6542731   Cannot run schedulerd from JES4 based iWS 6.1 
6545817   Publish SIFT into GAT bundle 
6553963 search/htmlconv: pdf files created via scanning software by OmniPage Pro are not searchable 
6563615   Should not use anonymous bind when setting up distributed admin over LDAPS 
6579852   ws6.1sp7 and ws6.1sp8 is shipping debug jdk binaries 
6581407   Restricting Access to a File Type operation doesn't change the appropriate obj.conf file. 
6582644   Add description for fix for CR 2144943 in WS6.1sp9 Rel. Notes 
6590039   Integrate CAT framework into 6.1 
6590893 stand alone web server install bits should detect and warn if upgrading a JES web server install 
6590899   AIX webserver fails to startup with large java heap of java1.5. 
6591471   Server shutdown message missing in errorlog file when Java is disabled globally. 
6592886   race condition results in NullPointerException 
6598092   Forwarding via the RequestDispatcher fails first time when using the 'invoker' servlet 
6603088 Crash in ldap search LdapSession::search_dyngroup LdapValues::length is being passed null pointer 
6609457   postinstall script of SUNWwbsvr which does not handle the ABE case properly 
6612344   6.1 Tinderbox scripts need to be modified to ensure that countless mails are not sent to tb-daemon 
6620677 web server start script sed filter incorrect for Solaris 9 
6625264   Windows: WS6.1: acl/acl18 testcase fails 
6625764   Windows: WS 6.1: testcase getAttributeU6 passes, though reference.list expects it to fail 
6628376   The scheduler.pid file should be removed when it's stopped. 
6628914   6.1: removal of /usr/dist/share/sunstudio_sparc,v10.0 causes build failure on Solaris Sparc 8/9/10 
6630037   Cron log rotation can create invalid archive logs when instance name, sub string of another instance 
6637709   Update SP9 license file, version string, README, RPM spec and pkginfo file with SP9 release number. 
6638185 Possible cross-site scripting vulnerability in search 
6643558   WS 6.1: Client IP tag description and example is incorrect 
6647151 Possible cross-site scripting vulnerability in advance search 
6649439   Access and Error logs do not get updated while running Stress test. 
6650214   TestCert and TestCert4 still fails on HP (only) 
 
(from 121510-04)
6235473 Introduce the ability to change the permissions a directory is created with when using WebDAV.
6520528 WS 7.0: Problem with response.sendRedirect()
4737204 'wdeploy delete' improperly follows syslinks!!!
6152655 form-based auth webapp with file based session persistence suffers unexpected logouts
6379347   All Versions of WebServer6.1 crash on load, Access Manager deployed on the webserver
6497690 Problem having full URL for the search results , rather than relative  URL/URIs
6508015   getParameterNames() does not return non-parameterized names in query string
6509623   ws 6.1 sp7 : On Win XP/2003, the release notes from Release Notes shortcut doesn't open
6512624   GAT tests htaccess22, htaccess23, htaccess24 fails on windows for WS6.1sp7
6513358   Webserver RPP not handling chunked data
6513362   GAT test failures of webserver 6.1sp6 with JDK 6
6519021   6.1SP6: Admin server generated new virtual server class obj.conf has typo and errors inside
6519551 Issue in JDBC Connection Pool feature (may actually be in com.sun.enterprise.util.Utility.java)
6519839 Vulnerability with Web Server redirect functionality
6524399   ws 6.1 ldap servers needs to be changed to ws-ldap
6526460   ldap connection failure errors with WS6.1 SP7
6531111   htaccess AuthGroupFile should support empty files as equivalent to not specifying the directive
6534216   Update README,version string and License file for 6.1 SP8
6540248   Webserver 6.1 SP8 to be integrated with latest security bits
6540809   Checkin RPP testcases into ws6.1 RTM branch
6541955   Bringing HP-UX JES4 packaging from Porting Branch to RTM Branch
6541968   Bringing HP-UX JES4 patching from Porting Branch to ws6.1 RTM Branch
6546233   Update RPM spec and pkginfo file with SP8 release and version number.
6567841   Form auth bypass and JSP source code disclosure
 
(from 121510-03)
6358858 HTTP4352: zlib internal error. Return code from zlib is -5
6292582 SNMP MIB for "iwsFractionSysMemUsage" not showing correct results for iws6.0 sp9
6384640 Restart while previous restart is in progress kills the webserver processes
6376082 Needs to provide support for JNDI Simple name, e.g. "jdbc/sample" as in App Server
6387189 Java Logging issues in a deployed module
6276594 Request body of PUT requests sent with the Transfer-encoding:chunked header is not read.
6428403 Crash when filtering static content
6442651 If the URL (from browser) to a web app contains URI params, then it causes recursive redirection
6392644 Incorrect URL in README.txt file supplied with iWS 6.0SP10/6.1SP6 along with RPP and fast cgi README
4856895 uxwdog process crashes on multiple CPUs machine during shutting down.
6455812 magnus.conf directive thread safety
6439519 SEGV in service_plain_range
6388092 RFE: /ns-icons gif image files cannot be displayed properly in IE
6382704 iWS 6.0SP9: Admin server unable to turn off "Monitor Web Server Statistics" -Admin GUI still monitor
6473494 PKCS#1 signature DigestInfo parsing problems in NSS
6384456 Ill-behaved web apps can crash Web Server
6488468 installer should not bundle jdk for hp platforms
6066230   Displaying buggy page numbers on the search results screen
6158040   Problem with migration from 4.1 to 6.1:related to missing JAVA parameter in server.xml file
6206179   WS6.1sp2: Internal log rotation rotates files twice if the system time was changed.
6213097   ktsearch.jar is not getting migrated correctly on JES3
6315783   WS 6.1.5 point product: Links to search OLH lead to English pages on fr locale
6348395   sessionDestroyed is not called when session is invalidated with IWSSessionManager.
6350502 Pragma and Cache-control headers cause interoperability problems
6367672   Problem restarting the server with restart script having MaxProcs > 1
6376035 Problem finding the library files while executing the standlone jsp file ( not webapp)
6380777   type=magnus-internal/cgi in mime.types can not add pl file suffix properly
6381747   Use of 'HttpSessionBindingListener' causes session to be expired incorrectly
6388766   Adminserver treat the japanese backslash differently in manupilating cgi shell directory on windows.
6392159   Servlet container hang on restart
6400307   Cluster Control functionality of Admin GUI breaks after adding a variable
6418529 i18n search: search pages content have a mix of both English and the other language
6421617   Problem having server-parsed HTML (ParseHTML) and .htaccess with restricted group option
6426382   compression filter flush call doesnot flush all buffer data
6428199 search filter failing due to "," (comma) in userid when such users are a member of a group
6429293 Security Vulnerability in web server 6.1 sample apps
6433752   ssl-check is not working with NSAPI based plugin
6435723   High CPU usage in Reverese Proxy Plugin - DaemonChannel::unchunk()
6436535 Server hangs on stop/restart when a connection is in the connection queue
6437635   WS 6.1SP5:Users with Revoked Client certificate can access WS instance                                                                                
6438408   magt bundled with webserver 6.1sp5 leaks memory with each connection request
6441402   LDAP server configuration fails with iWS 6.1sp5 64 bit version
6448255   Windows 6.1sp5: file handle is not released by webservd process under certain conditions
6451182   high cpu utilization in parseParameters()
6451285   Failed assertion in 6.1 SP6 debug bits
6458771   watchdog can crash when ./start is executed before ./stop completes
6465691 Display problem with html page in <jsp:include> with tiles
6471388 Windows hidden shared network drives as document directories do not work                                                                                
6477953 windows: standalone web server modifies NSPR/NSS bits, breaking FIPS mode
6477981 FIPS140 mode is broken in standalone web server because chk files are missing
6478972   JDK shipped with WS 6.1SP6 not compatible with 2007 DST changes
6480026   some KA connections dont get closed after the specified time
6482272 SNMP master agent does not send traps when the web server instance operational status changes
6482560   web server crash with 1.4.2.09 + and 1.5.0.3+ HP JVMs
6482816 Web Server 6.1 SP5 Reverse Proxy Plugin replaces commas in a cookie header with semi-colons.
6489275   Integrate webserver 6.1 with latest NSS
6494886   low-latency/high concurrency mode sometimes doesn't get switched dynamically as release note mention
6496892   WS installer should not bundle jdk for AIX platform
6507264   finer log shows in startup step although the default log level is INFO
6508084   webserver 6.1 sp7 License text refers to SP6 on all the platforms
6508092   Server startup fails in ws6.1 sp7 on HPUX platform, when installed through express/silent mode.
6510957   pkginfo file on Solaris and RPM spec file point to old service pack(SP5).
 
(from 121510-02)
4957123 Search Query Operators are not documented in Web Server 6.1 Admin Guide
4991884 Indexing a collection of files requiring conversion fails if total size is great
6197731 Internal Error on accessing Admin Server.
6246214 Search indexing hangs on large files
6279790 Preserve .pdb files for Windows debugging
6280778 PDF files unable to be indexed with WS 6.1 search on HP-UX with OS patch PHSS_28871 installed
6281323  Request to add Windows 2003 SP1 in the supported platform.
6285129  Using % in the value of jsp:param fails in some circumstances
6294743 update JSP search collection creates new tmp files
6302377 Servlet container UTF-8 URI mapping vulnerability
6312702 HttpServletResponse.reset() doesn't work as expected.
6316262 Admin GUI does not reflect change to accesslog path change
6316387 Web server does not respond correctly when handling the "if-unmodified-since" header
6316881 Multibyte characters in headers can't be retrieved by req.getHeader().
 
6318003 webserver sends back the actual content with 412 code for request with if-unmodified-since and range
6318200 Buffer overflow when formatting installer error messages
6318406 redeploy the webapp will causes ownership change on files
6324034 http post limit:-(
6326965 admin password in plain text in a file readable by anyone
6329109 WS6.1: lock file conflict for multiple installs running on the same port (but diff. ips)
6332442 Web Server on Linux will crash when Init fn="stats-init" is in magnus.conf
6334248 Windows 2003 mapped network drive not readable as a document_root dir
6335483 6.1 HPUX builds are stripped of their symbols
6336309 Problem with rewriting the special character in server.xml
6342394 Cron log rotation can create invalid archive logs with a specific instance name.
6343584 deadlock in keepalive subsystem caused by NSS blocking
6350122 iWS6.1SP5 on Windows Cron based log rotation failed with garbage inside scheduler.conf file
6353988 6.1sp4/sp5: Cannot set client trust or server trust on some built in CAs
6356179 AdminServer of web6.1 doesn't change the id of USERDB tag in server.xml.
6360180 crash in select 3 webapps/qa_app/jsp/encodedurlforwarder
6361485 htaccess not working in Web Server 6.1 SP5 for User Document Directories.
6364678 Reference to Sun ONE Studio in the WebServer documents needs to be updated.
6367812 Doc RFE: add infodoc 76202 into online doc for iWS 6.1 SPx
6370001 Change service pack version number, README file, License File and Linux RPM version for new patches
6370089 Integrate Webserver 6.1 SP6 to NSS 3.11
6376278 HP-UX gat -setup fails.
6378473 validate-server-cert should be set to true in order to avoid MITM attacks.
6383377 Release note 64-bit Fast CGI, RPP and JWSDP support in 6.1 Sp6
6383971 Release note the requirement of AIX update patch 5100-09 for 6.1 SP6
6387080 GAT select 2 and 6 has failures
6388230 GAT search select 14 is hanging on solaris
6388243 Installing a CRL on WS 6.1SP4 (Windows) adds it to the CKLs section in the GUI
6391505 Document config file writability, root security risks, and Solaris net_privaddr privilege
6391515 JES4:win: WS Release note have typo and non releated information.
6394888 Memory leak
6404983 Searching of Users and Groups through LDAP server using AdminGUI is failing
6376634 magnus.conf directives SSL3SessionTimeout and SSLSessionTimeout broken
6377343 need to support newer critical extensions, e.g. PolicyConstraints, etc in RFC3280
6497487 HP-UX: Remove shared component dependency from patch psf for HP-UX for WS6.1SP6
6497870 HP-UX : Generation of Readme file based on Readme template for WS6.1 HP-UX Patch
Revision History: 

121510-03 121510-01 121510-04

Patch Installation Instructions: 
--------------------------------
 
To install this patch, run the command:
 
1) Stop all running instances of Webserver and AdministrationServer
2) Apply patch
swinstall -s <patch location> -x patch_match_target=true
 
<patch location> should be absolute path. The <patch location> should be the one under which "swagent.log" file, patch depot and catalog directory are present.
 
Refer swinstall man page for more details.
 
To remove/rollback this patch:
 
1) Stop all running instances of Webserver and AdministrationServer
2) Remove the patch
swremove <patch id>
 
Refer swremove man page for more details.
Special Install Instructions: 
-----------------------------
 
None.

README -- Last modified date:  Thursday, October 9, 2008

 
 
Login Required

You must login and have a valid contract to access Sun's Premium content which includes:

  • Sun Alerts
  • Bugs
  • Patches
  • Solutions
  • White Papers
  • Documentation
  • Support Knowledge

Login Required

You must login and have a valid contract to access Sun's contracted features

Access Legend:

(Login to access)   Sun Contracted Content
(Login to access)   Sun Contracted Feature

Please make use of SunSolve Feedback application by selecting the floating [+] to provide feedback about this specific document.

Search

Article Details
Article ID : 121510-05
Article Type : Patch Descriptions
Last reviewed : 2008-10-09
Audience : PUBLIC
Keywords : sun one web server java_es hpux security
Provide feedback  (help)
Page Tools
»  Print This Page
»  Email This Article
»  Bookmark This Article