-
Bug
-
Resolution: Won't Do
-
Major
-
None
-
None
-
None
-
Release Notes
-
-
-
-
-
The README file that's included in the zips didn't get updated for SP1. Here is the SP1 from 3.0.3 compared to 3.1.0's SP1 zips:
$ cat jws-application-servers-3.0.3-SP1-win6.x86_64.zip/jws-3.0/README In this patch zip: httpd: CVE-2016-5387 Apache HTTPD: sets environmental variable based on user supplied Proxy request header Tomcat7: CVE-2016-5388 Tomcat: CGI sets environmental variable based on user supplied Proxy request header Tomcat8: CVE-2016-5388 Tomcat: CGI sets environmental variable based on user supplied Proxy request header $ cat jws-application-servers-3.1.0-SP1_CR1-win6.x86_64.zip/jws-3.1/README In this patch zip: