Patch-ID# 116292-14


Download this patch from My Oracle Support

Your use of the firmware, software and any other materials contained in this update is subject to My Oracle Support Terms of Use, which may be viewed at My Oracle Support.
For further information on patching best practices and resources, please see the following links:
Copyright (c) 2012, Oracle and/or its affiliates. All rights reserved.

Keywords: security solaris
Synopsis: Sun One Application Server 7.0: Proxy Plugin Patch
Date: Oct/08/2004


Install Requirements: NA

Solaris Release: 8 9

SunOS Release: 5.8 5.9

Unbundled Product: Sun One Application Server

Unbundled Release: 7.0

Xref: This patch available for x86 as patch 116293

Topic: Sun One Application Server 7.0: Proxy Plugin Patch

Relevant Architectures: sparc

Bugs fixed with this patch:

Sun CR # Bug #
209298212071146
210382512077107
472472812009851
473433712008575
474412811954098
476115112004655
477609112002259
481143112000682
481885311998552
481941211999429
4830338
484032411943619
484936811957455
484951311995572
485121811994463
485354311994308
486040011993363
486176711992957
486194811955613
486299411993126
486966411991870
487023311952200
487294811989611
487667211989749
488455211988997
488625311989432
488668311987696
488861211987765
489061311987935
489258711988180
489395411987480
489581411986585
490221011987052
490410011985911
4904764
490728311985270
490938011985298
490979611985027
491068611948849
491329011984634
491345811984525
491436211947472
491720611982557
492155111982312
492288411947475
492323011983169
492554811981915
492658111982226
492697211952799
492834111981911
493002711980145
493098611980653
493137911980265
493399711961531
493741611979467
493766711979253
493831911978769
494204411979726
4942341
494238111979451
494723111977728
494775611977340
494924511959910
494931811977693
495003511978515
495460911977252
495540411976768
495716211955782
495839311976182
495839511958778
496222511948486
496241811974999
496571311954672
496581511975735
496903611940515
496942511973845
497243211957058
497279611974313
497602511960843
497640111974518
497650211952019
497806811973399
497836911944736
497864711944739
498013612055130
498066011973475
498252511973488
498721711972298
498727411972241
499119811971412
499165911945485
499227511971889
499436611971965
499611111970844
499711311955944
500330911971085
500440611970566
500564311971094
500565311971095
501376711969357
501763011968063
501789512068514
502158511968509
502171211948687
502290411968114
502297611967938
502480411967163
502901411967525
504915912067555
505691711964656
608859312074685
609247512075056
609249912075075
615274212075940
615515412076579
615544612076914
615686912077758


Changes incorporated in this version: 5043376 5057723 5022976 5049159 5056917 6088593 6092475 6092499 6152742 6155154 6155446 6156869

Patches accumulated and obsoleted by this patch: 116790-04

Patches which conflict with this patch:

Patches required with this patch:

Obsoleted by:

Files included with this patch:

/opt/$ASINSTDIR/lib/webserver-plugin/solaris/iws/libpassthrough.so

Problem Description:

5043376 unwanted and conflicting Cache-control headers are generated
5057723 templates of asenv.conf and server.xml have hardcoded location specific to Solar
5022976 Error while creating auth-realm using sun-appserv-admin
5049159 app svr should reconnect to directory svr if directory svr goes down and then co
5056917 Neither the CNCtxFactory or S1ASCtxFactory can be used to programmatically reconn
6088593 cts testsuite : ContainsHeaderTestServlet test FAILED
6092475 DOC: web server crash when running high load and app server reverse proxy plugin
6092499 REG:GAT resulting LDAP Server crash
6152742 JDBC connection pool does not properly release connections
6155154 client authentication not working with IIS 5.0 sun-passthrough plugin
6155446 Corrupted transaction log files hang appserver
6156869 DOC: No documentation on how to use MQ3.5SP1 with AS7 UR4
 
(from 116292-13)
 
4734337 IWS: Listing of groups/users in ACL UI is broken.
4744128 EJB compiler failed to generate valid java code for inner classes
4761151 Persistency of proxy-to-container connections is not maintained(out of box).
4840324 Security : Cross-site scripting in sample applications
4849368 "Use Existing JDK" text field accepts blank space
4872948 circular path in jar manifest causes 'error received from mbean null' error
4876672 request.getAttribute("javax.servlet.error.request_uri") is not working ..
4921551 JDOQL does not work when contains a non trivial, proper filter with boolean expr
4923230 CMP Oracle boolean field problem in finder
4926581 Appserver asadmin utility always requests a password for SSL startup
4930027 Appserver performance problem with jsp:useBean
4947756 Reg: Not able to setup Log Rotation - A blank page is loaded
4949245 App Server crashes during deployment of a WAR file
4955404 appclient does not honor -mainclass option
4957162 NMTOKEN/NMTOKENS values must be XML name tokens : Failed Message during deployment
4962418 a typo in JMS SessionWrapperWeb.rollback prevent the method from working
4965815 DOC::Logging/simple sample doesn't work
4969425 SNMP doesn't work when the instance is stopped and started (restart).
4972432 Not able to create a new domain using asant
4972796 Changes in j2ee application role mappings are lost during deployment
4976025 RPP:WebServer crashes when more one instance is defined in  obj.conf
4976401 iwsInstanceDeathCount is not being updated.
4976502 RN: perfdump for appserver does not work as in documentation
4978068 No information is displayed about the errors occurred while running ejbc.
4982525 Admin Tool works improperly in AS7.0UR1 Japanese version
4987274 S1AS7: Deployment fails if remote interface for the bean is named Util
4991198 S1AS7SE/Appserver logs user passwords in CLEAR TEXT in the log file
4991659 Appserver RPMs for 7.0.0_02 are not compatible with NSPR 4.1.6 in JES2
4992275 Need to modify the README file
4994366 RN: S1AS7 - deploy error with  ejb-local-ref and ejb-link.
4997113 appservd.exe crashed when  application is accessed using  passthrough plug-in wi
5003309 DOCS: URL wrong in AG Deployment chapter under static deployment
5004406 --passwordfile does not work with mix of upper/lowercase characters
5005643 Need to modify the README file for CD
5005653 There is a warning message when deploy jdbc/simple sample
5013767 Plugin truncating XML stream
5017630 RN: AS7U3: can not upgrade on XP
5017895 NPE when running NileApp in x86 platform
5021585 REG:  Monitoring iiop-listener not working
5021712 REG: Error while running ejbc
5022904 RN: DB2 Server has connection growing after idle time out with DB2 Type II Drive
5024804 error in 7.0 performance tuning doc
5029014 package-appclient script needs updating to be compatible with new NSS path(s)
 
(from 116292-12)
 
This patch revision was reserved but not used.
 
(from 116292-11)
 
This patch revision was reserved but not used.
 
(from 116292-10)
 
This patch revision created to address patch construction issues.
 
(from 116292-09)
 
This patch revision created to address patch construction issues.
 
(from 116790-04)
 
This patch revision created to address patch construction issues.
 
(from 116790-03)
 
5004406 --passwordfile does not work with mix of upper/lowercase characters
 
(from 116790-02)
 
4761151 Persistency of proxy-to-container connections is not maintained(out of b
ox).
4969425 SNMP doesn't work when the instance is stopped and started (restart).
4976401 iwsInstanceDeathCount is not being updated.
 
(from 116790-01)
 
(from 116292-08)
 
4996111 webcore memory growth
 
(from 116292-07)
 
4978647 Petstore: org.apache.jasper.JasperException: Unable to compile class for JSPNote
4987217 REG in UR3 JSP compiler
 
(from 116292-06)
 
4724728	Redefined finder methods in spr/subclass home intfs duplicated
	in generated code
4776091	MSTR: CLI -License key with leading and trailing spaces not
	honored (Problems exists in RMT)
4811431	Cannot access a web module if the location attribute in server.xml
	ends in /
4818853	LocalTransaction association with ManagedConnection not preserved
	between EJBs
4819412	i18n "is not valid entry" is hardcoded
4830338	korean characters in cookie not working
4849513	dynamic reloading does not pick up changes to sun-application.xml
	after the firs
4851218	DOC: unable to install self signed certificate
4853543	MODEL: Should allow for PK class to have inherited fields
4860400	EJB Classloader returns null when calling Class.getPackaged()
4861767	SECURITY BUG FIX:Accept language issue (SB)
4861948	getEJBMetaDATA0 fails with exception after context
	re-initialized
4862994	Domain Creation fails on RedHat 9 (New Linux version support)
4869664	two byte characters cause problems in the http GET URLs
4870233	JSP with page directive "buffer=none" does not work when using
	s1as7.0
4884552	SECURITY BUG FIX:
	auth-method=CLIENT-CERT forces the SSL client auth regardless
	of uri-pattern in
4886253	Unable to retrieve X509 Client Certificate behind a passthrough
	proxy listener
4886683	S1AS7:UR2 installation on Win2003 enterprise throughs
	"Unsupported platform (New Windows OS Version support)
4888612	Failed to start server instance after installing eval build
	on X86 (New Eval installer for X86)
4890613	UR2 Linux installer not upgrading existing jdk
4892587	SECURITY BUG FIX:
	S1AS7 does not enforce "grant signed by" policy
4893954	Rotatelogs script causes watchdog process to die,
	and all other appserver processes
4895814	request getRequestUR1() returning inconsistent values.
4902210	REG: Incorrect support jdk version provided in java config page
4904100 At S1AS7 SE, rich Client always see an exception
4904764	Could not stop the admin-server when running Redhat 8.0
	(New Red Hat OS version support)
4907283	CodeFix as in lWs60SP5 for Bugid 4846815 to S1AS7
4909380	Orion Uninstall of unbundled AS7 pkg-based product
	removes shared components
4909796	UR2: Upgrade installer fails if JDK used by S1AS is at non-default
	location
4910686	app-server does lazy auth even if http port is not cleint auth
	enabled
4913290	Form Based Authentication does not provide the same
	functionality as in iAS6.x
4913458	Web container thread names are not unique
4914362	SECURITY BUG FIX:
	Enabling WebPub or Remote File Manipulation allows any user to
	obtain a director (SB)
4917206	Unable to set ACL for anything but entire server through admin GUI
4922884	Web Service invocation from JAXRPC client throws Internal Server
	Error
4925548	ExceptionininitializerError with JDK 1.4.2
4926972	S1AS-UR2-Bld3: eval upgrade: error about lmissing archive file
	during upgrade
4928341	using chunk data causes endless loop/high CPU in appserver (SB)
4930027	Appserver performance problem with jsp:useBean
4930986	Throw appropriate errormsg when Abrupt termination of
	upgrade corrupts pkgs
4931379	SECURITY BUG FIX:
	S1AS 7.0 U1 crashes when AS_NSS points to /usr/lib/mps/secv1
	in Orion1_B09 +
4933997	Appserver startup problems after upgrade on Linux (iMQ upgrade)
4937667	Upgrade script to use the same packages that complete install
4937416	SECURITY BUG FIX:
	User Principle class throws ClassCastException
4938319	RN: Online doc: Need to document the workaround for
	escalation 548517
4942044	Migrating NSS/NSPR from 3.3.4 t0 3.3.6
4942341	Code generated for <jsp:useBean> differs based on class
	or beanName attr usage
4942381	Could not initialize ORB monitoring
4947231	libpassthrough.so(AS7.0-UR3) causes WS6.1 to crash on x86
	Solaris Keywords:
4949318	Reg: Petstore sample deployment failed on Windows 2000
	advanced server
4950035	Performance Tuning doc refers to both obj.conf and
	<instance_name>-obj.conf
4954609	-passwordfile doesn't work on Appserver 7.0MU1 create-domain
4958393	ServletContext.getContex(String) does not return other
	contexts when...
4958395	Reg: Not able to install mainstream build if an eval build
	pre-installed on windows
4962225	RN: We should remove Smartticket sample on X86.
4965713	SECURITY BUG FIX:
	LDAP: user can enter wildcard '*' for UID in basic
	auth(WEbserver:4957829)
4969036	SECURITY BUG FIX:
	Regression: After entering username/password appserver changing
	URI
4978369	SECURITY BUG FIX:flex log buffer overflow
4980136 SolSparc: 7.0.0_03 UR3 B02-Upgrade script fails
	while adding SUNWpr package
4980660 SOAP server array DoS
 
(from 116292-05)
(from 116292-04)
(from 116292-03)
(from 116292-02)
(from 116292-01)
 
Revisions skipped.


Patch Installation Instructions:
--------------------------------
 
Refer to the man pages for instructions on using 'patchadd' and
'patchrm' scripts provided with Solaris, to install and remove patches.


Special Install Instructions:
-----------------------------
 
None.


README -- Last modified date: Saturday, November 10, 2012