search cancel

URL contains BadQueryChars: '/myURI/MyServlet;variable=value'


Article ID: 77169


Updated On:


CA Single Sign On Secure Proxy Server (SiteMinder) CA Single Sign On SOA Security Manager (SiteMinder) CA Single Sign-On


We have a Web Agent protecting an application, and we are getting the following errors when accessing the URL '/myURI/MyServlet;variable=value':
"URL contains invalid characters. Exiting with HTTP 500 server error '00-0002'."

In our ACO we have defined the following parameters:

Doing some tests we have noticed that when we remove the semicolon character from the BadQueryChars then we can access the URL above, but as there is no query string in the URL we don't know why it is complaining about BadQueryChars, as we don't even have the semicolon defined in the BadUrlChars parameter.


As per the documentation, BadQueryChars "specifies characters that the Web Agent prohibits in the query string portion (following the '?') in a URL."
When the URL does not contain a '?' character, the Agent is actually checking the whole URL for BadQueryChars


Web Agent R12.52 SP1 CR05


This issue is fixed in Web Agent R12.52 SP1 CR09. Upgrade to that version to fix this issue.

Web Agent


The BadQueryChars ACO parameter incorrectly checks the entire URL if there is no query string.


Additional Information