IBM Support

PI25813: Fix double-encoding of "state" parameter in OAuth flow

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • The "state" should be returned in the same manner it was
    delivered.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server Liberty Profile utilizing OAuth      *
    ****************************************************************
    * PROBLEM DESCRIPTION: The "state" parameter is URL-encoded    *
    *                      twice in OAuth flow                     *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    When going through the OAuth flow, the "state" parameter
    presented by the OAuth client is URL-encoded twice when
    processing the authorization request. The client expects this
    parameter to be encoded only once.
    

Problem conclusion

  • An additional layer of URL encoding on the "state" parameter
    after its generation was removed. The "state" parameter should
    now be encoded only once, as expected, and returned properly.
    The fix for this APAR is currently targeted for inclusion in fix
    pack 8.5.5.4.  Please refer to the Recommended Updates page for
    delivery information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    

Temporary fix

Comments

APAR Information

  • APAR number

    PI25813

  • Reported component name

    WAS LIBERTY COR

  • Reported component ID

    5725L2900

  • Reported release

    855

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2014-09-17

  • Closed date

    2014-10-14

  • Last modified date

    2014-10-14

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WAS LIBERTY COR

  • Fixed component ID

    5725L2900

Applicable component levels

  • R855 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSD28V","label":"WebSphere Application Server Liberty Core"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"855","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
28 April 2022