IBM Support

PI19941: AJAX PROXY PARSING ERROR FOR COOKIES WHICH END IN "=" CAUSES SERVER TO REMOVE

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • When using Liberty Profile to run the Ajax Proxy, but full
    profile to run the application, the Ajax Proxy will accept
    cookies containing "=", but will set them on the browser with
    the "=" characters removed.
    

Local fix

  • modify cookie names to not include "="
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server                                      *
    *                  Feature Pack for Web 2.0 using the          *
    *                  AjaxProxy                                   *
    *                  component.                                  *
    ****************************************************************
    * PROBLEM DESCRIPTION: The AjaxProxy feature does not handle   *
    *                      cookies that have values ending in an   *
    *                      "=" character.                          *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    The AjaxProxy feature does not handle cookies that have values
    ending in an "=" character.  Any cookies through the AjaxProxy
    with an = on the end will be transmitted incorrectly and could
    cause issues.
    

Problem conclusion

  • The AjaxProxy code has been fixed to correctly pass any
    cookies with an equal sign ( = ) on the end.
    
    The fix for this APAR is currently targeted for inclusion in
    V8 Web 2.0 and Mobile fix pack 1.1.0.5 and the V8.5 WebSphere
    Application Server 8.5.5.3.  Please refer to the Recommended
    Updates page for delivery information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    

Temporary fix

Comments

APAR Information

  • APAR number

    PI19941

  • Reported component name

    WEBSPHERE APP S

  • Reported component ID

    5724J0800

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2014-06-12

  • Closed date

    2014-06-12

  • Last modified date

    2014-06-12

  • APAR is sysrouted FROM one or more of the following:

    PM90483

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE APP S

  • Fixed component ID

    5724J0800

Applicable component levels

  • R850 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.5","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
27 April 2022