Re: Struts 2.3.8 threads BLOCKED in com.opensymphony.xwork2.config.ConfigurationManager.getConfiguration

2013-01-16 Thread Lukasz Lenart
I think I found out the problem, could you register an issue and test it after all? https://issues.apache.org/jira/browse/WW Regards -- Łukasz + 48 606 323 122 http://www.lenart.org.pl/ 2013/1/16 Lukasz Lenart lukaszlen...@apache.org: Hi, What do you use to profile your application? Is it

Re: [2.3.8] Parameters interceptor tampering with file upload ?

2013-01-16 Thread Philippe Lagardere
Hello, The server was not a good track - apparently Tomcats can manage multipart/form-data natively. The only configuration I could find revolved around setting up the directory to send the file to, as well as restricting the allowed file size or type. I tried setting up a file upload form on a

Re: Different session handling between websphere and tomcat

2013-01-16 Thread Lukasz Lenart
Done, page updated! https://cwiki.apache.org/confluence/display/WW/WebSphere Thanks a lot! -- Łukasz + 48 606 323 122 http://www.lenart.org.pl/ 2013/1/11 Lukasz Lenart lukaszlen...@apache.org: Thanks a lot, can I add your note to the page regarding WebSphere in the docs [1] ? [1]

Java security issue vs. struts?

2013-01-16 Thread Emi Lu
Hello, Does someone know how this java security issue related to struts framework? http://www.oracle.com/technetwork/topics/security/alert-cve-2013-0422-1896849.html Thanks a lot! Emi - To unsubscribe, e-mail:

Re: Java security issue vs. struts?

2013-01-16 Thread Chris Pratt
I believe the description says it all. This Security Alert addresses security issues CVE-2013-0422 (US-CERT Alert TA13-010A - Oracle Java 7 Security Manager Bypass Vulnerability) and another vulnerability affecting Java running in web browsers. *These vulnerabilities are not applicable to Java

Re: Java security issue vs. struts?

2013-01-16 Thread Emi Lu
On 01/16/2013 04:54 PM, Emi Lu wrote: Hello, Does someone know how this java security issue related to struts framework? http://www.oracle.com/technetwork/topics/security/alert-cve-2013-0422-1896849.html One more link:

Re: Java security issue vs. struts?

2013-01-16 Thread Emi Lu
On 01/16/2013 05:02 PM, Chris Pratt wrote: I believe the description says it all. This Security Alert addresses security issues CVE-2013-0422 (US-CERT Alert TA13-010A - Oracle Java 7 Security Manager Bypass Vulnerability) and another vulnerability affecting Java running in web browsers. *These

RE: Java security issue vs. struts?

2013-01-16 Thread Martin Gainty
Hi Chris This issue came up on another apache users list I believe there was open access issue to Remote Context Object by OGNL (but i think Lukasz or Dave addressed the issue)..emi..did you see this in Struts Jira? Bon chance, Martin __ Note de

Re: Java security issue vs. struts?

2013-01-16 Thread Dave Newton
... Where does Struts 2 run? In the browser, or on a server? Dave On Wed, Jan 16, 2013 at 5:06 PM, Emi Lu em...@encs.concordia.ca wrote: On 01/16/2013 04:54 PM, Emi Lu wrote: Hello, Does someone know how this java security issue related to struts framework?

Re: Java security issue vs. struts?

2013-01-16 Thread Christian Grobmeier
On Wed, Jan 16, 2013 at 11:12 PM, Emi Lu em...@encs.concordia.ca wrote: On 01/16/2013 05:02 PM, Chris Pratt wrote: I believe the description says it all. This Security Alert addresses security issues CVE-2013-0422 (US-CERT Alert TA13-010A - Oracle Java 7 Security Manager Bypass