Last updated on NOVEMBER 05, 2016
Applies to:Oracle iPlanet Web Server - Version 7.0 and later
Information in this document applies to any platform.
***Checked for relevance on 02-Dec-2013***
On Oracle iPlanet Web Server 7.0u8 and older, an intermittent 408 Request Timeout error can be seen from any type of request to the web site. The problem is reproducible using any type of browser, whether SSL is enabled or not. Upon reproducing the problem, it appears that the full request does not get to the web server due to a timeout being hit where the request is truncated with a 408 error.
On Oracle iPlanet Web Server 7.0u9 or newer, the problem is not observed and the request timeout is 30 seconds between subsequent requests, while in WS7.0u8, the timeout appears to not reset during a subsequent request, making the problem easier to exploit.
Example access logs shows the 408 response code and the HTTP method, URI and HTTP version being truncated or missing:
184.108.40.206 - - [14/Mar/2012:10:14:52 -0400] "P" 408 148 "-" "-" "-" 7490
Sign In with your My Oracle Support account
Don't have a My Oracle Support account? Click to get started
My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms