IBM Support

IT40887: INBOUND HTTP REQUESTS WHOSE HEADERS EXCEED 8KB ARE SILENTLY REJECTED BY THE HTTPLISTENER IN ACE

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • If a HTTP request is made to the integration node HTTP listener
    or an integration server HTTP listener in ACE and the headers in
    that request are more than 8KB in size then the connection will
    be closed with no response and with no data reaching the message
    flows.
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    All users of inbound HTTP or HTTPS connections in IBM App
    Connect Enterprise
    
    
    Platforms affected:
    MultiPlatform
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    <div><div>If a HTTP request is made to the integration node HTTP
    listener or an integration server HTTP listener in ACE and the
    headers in that request are more than 8KB in size then the
    connection will be closed with no response and with no data
    reaching the message flows.</div></div>
    

Problem conclusion

  • A new "MaxHeaderSize" property has been introduced on the
    HTTPConnector and HTTPSConnector which controls the size of a
    per-request buffer used when parsing the incoming headers. If
    this buffer is exceeded then a 413 Payload Too Large error will
    be sent and the client will be disconnected. The default value
    for MaxHeaderSize is 8192 bytes (i.e. 8KB).
    
    ---------------------------------------------------------------
    The fix is targeted for delivery in the following PTFs:
    
    Version    Maintenance Level
    v11.0      11.0.0.20
    v12.0      12.0.7.0
    
    The latest available maintenance can be obtained from:
    http://www-01.ibm.com/support/docview.wss?rs=849&uid=swg27006041
    
    If the maintenance level is not yet available,information on
    its planned availability can be found on:
    http://www-1.ibm.com/support/docview.wss?rs=849&uid=swg27006308
    ---------------------------------------------------------------
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT40887

  • Reported component name

    APP CONNECT ENT

  • Reported component ID

    5724J0550

  • Reported release

    B00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2022-05-10

  • Closed date

    2022-10-25

  • Last modified date

    2022-10-25

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    APP CONNECT ENT

  • Fixed component ID

    5724J0550

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSDR5J","label":"IBM App Connect Enterprise"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"B00","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
26 October 2022