Article - CS327941

Error "The request was rejected because the URL contained a potentially malicious String "%25"" reported in MethodServer.log when donwloading a file from Navigate with SSO enabled

Modified: 29-Apr-2021   


Applies To

  • Windchill Navigate (formerly ThingWorx Navigate) 8.5.0 to 8.5.1

Description

Error below is reported in MethodServer.log when donwloading a file with special characters in Name ( eg: "Special2-°!§$%&()=^^^',.-;_.pptx") from Navigate with SSO enabled:
 
ERROR [ajp-nio-127.0.0.1-8010-exec-4] org.apache.catalina.core.ContainerBase.[Catalina].[localhost].[/Windchill].[OauthAuthBridgeServlet]  - Servlet.service() for servlet [OauthAuthBridgeServlet] in context with path [/Windchill] threw exception
org.springframework.security.web.firewall.RequestRejectedException: The request was rejected because the URL contained a potentially malicious String "%25"
                at org.springframework.security.web.firewall.StrictHttpFirewall.rejectedBlacklistedUrls(StrictHttpFirewall.java:265)
                at org.springframework.security.web.firewall.StrictHttpFirewall.getFirewalledRequest(StrictHttpFirewall.java:245)
                at org.springframework.security.web.FilterChainProxy.doFilterInternal(FilterChainProxy.java:194)
                at org.springframework.security.web.FilterChainProxy.doFilter(FilterChainProxy.java:178)
                at org.springframework.web.filter.DelegatingFilterProxy.invokeDelegate(DelegatingFilterProxy.java:357)
                at org.springframework.web.filter.DelegatingFilterProxy.doFilter(DelegatingFilterProxy.java:270)


 
This is a printer-friendly version of Article 327941 and may be out of date. For the latest version click CS327941