IBM Support

PI15886: AN INVALID COOKIE NAME CAUSES AN ILLEGALARGUMENTEXCEPTION TO BE THROWN

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Session manager does a set a JSESSIONID cookie,
    but it wouldn't set a cookie which would result in an
    java.lang.IllegalArgumentException.
    
    Applications accessed by Android OS are not able to access
    production application due to the following error:
    
                  Caused by: java.lang.IllegalArgumentException:
    Cookie name "domain" is a reserved token
                       at
    javax.servlet.http.Cookie.<init>(Cookie.java:139)
                       at
    com.ibm.ws.webcontainer.osgi.request.IRequestImpl.getCooki
                  es(IRequestImpl.java:151)
                       at
    com.ibm.ws.webcontainer.srt.SRTServletRequest.getCookies(S
                  RTServletRequest.java:1622)
                       at
    javax.servlet.http.HttpServletRequestWrapper.getCookies(Ht
                  tpServletRequestWrapper.java:75)
                       at
    javax.servlet.http.HttpServletRequestWrapper.getCookies(Ht
                  tpServletRequestWrapper.java:75)
                       at
    org.springframework.security.web.authentication.rememberme
    .AbstractRememberMeServices.extractRememberMeCookie(Abstra
                  ctRememberMeServices.java:146)
                       at
    <customer package names>
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  IBM WebSphere Application Server Version    *
    *                  8.5.5 Liberty Profile users.                *
    ****************************************************************
    * PROBLEM DESCRIPTION: An invalid cookie name causes an        *
    *                      IllegalArgumentException to be thrown.  *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    When the WebContainer is creating cookies with an invalid name
    (for example, containing restricted words such as "domain") an
    IllegalArgumentException such as the following is thrown:
    Caused by: java.lang.IllegalArgumentException: Cookie name
    "domain" is a reserved token
    at
    javax.servlet.http.Cookie.<init>(Cookie.java:139)
    at
    com.ibm.ws.webcontainer.osgi.request.IRequestImpl.getCookies(IRe
    questImpl.java:151)
    at
    com.ibm.ws.webcontainer.srt.SRTServletRequest.getCookies(SRTServ
    letRequest.java:1622)
    at
    javax.servlet.http.HttpServletRequestWrapper.getCookies(HttpServ
    letRequestWrapper.java:75)
    at
    javax.servlet.http.HttpServletRequestWrapper.getCookies(HttpServ
    letRequestWrapper.java:75)
    ...
    

Problem conclusion

Temporary fix

  • N/A
    

Comments

APAR Information

  • APAR number

    PI15886

  • Reported component name

    WAS EXPRESS

  • Reported component ID

    5724I6300

  • Reported release

    855

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2014-04-11

  • Closed date

    2014-12-10

  • Last modified date

    2015-03-04

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WAS LIBERTY COR

  • Fixed component ID

    5725L2900

Applicable component levels

  • R855 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSD28V","label":"WebSphere Application Server Liberty Core"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"855","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
28 April 2022