IBM Support

PI95544: NPE THROWN IN METHOD AUTHORIZEEJB()

Fixes are available

17.0.0.2: WebSphere Application Server Liberty 17.0.0.2
17.0.0.3: WebSphere Application Server Liberty 17.0.0.3
17.0.0.4: WebSphere Application Server Liberty 17.0.0.4
18.0.0.1: WebSphere Application Server Liberty 18.0.0.1
18.0.0.2: WebSphere Application Server Liberty 18.0.0.2
18.0.0.3: WebSphere Application Server Liberty 18.0.0.3
18.0.0.4: WebSphere Application Server Liberty 18.0.0.4
19.0.0.1: WebSphere Application Server Liberty 19.0.0.1
19.0.0.2: WebSphere Application Server Liberty 19.0.0.2
19.0.0.3: WebSphere Application Server Liberty 19.0.0.3
19.0.0.4: WebSphere Application Server Liberty 19.0.0.4
19.0.0.5: WebSphere Application Server Liberty 19.0.0.5
19.0.0.6: WebSphere Application Server Liberty 19.0.0.6
19.0.0.7: WebSphere Application Server Liberty 19.0.0.7
19.0.0.8: WebSphere Application Server Liberty 19.0.0.8
19.0.0.9: WebSphere Application Server Liberty 19.0.0.9
19.0.0.10: WebSphere Application Server Liberty 19.0.0.10
19.0.0.11: WebSphere Application Server Liberty 19.0.0.11
19.0.0.12: WebSphere Application Server Liberty 19.0.0.12
20.0.0.1: WebSphere Application Server Liberty 20.0.0.1
20.0.0.2: WebSphere Application Server Liberty 20.0.0.2
20.0.0.3: WebSphere Application Server Liberty 20.0.0.3
20.0.0.4: WebSphere Application Server Liberty 20.0.0.4
20.0.0.5: WebSphere Application Server Liberty 20.0.0.5
20.0.0.6: WebSphere Application Server Liberty 20.0.0.6
20.0.0.7: WebSphere Application Server Liberty 20.0.0.7
20.0.0.8: WebSphere Application Server Liberty 20.0.0.8
20.0.0.9: WebSphere Application Server Liberty 20.0.0.9
20.0.0.10: WebSphere Application Server Liberty 20.0.0.10
20.0.0.11: WebSphere Application Server Liberty 20.0.0.11
20.0.0.12: WebSphere Application Server Liberty 20.0.0.12
21.0.0.3: WebSphere Application Server Liberty 21.0.0.3
21.0.0.4: WebSphere Application Server Liberty 21.0.0.4
21.0.0.5: WebSphere Application Server Liberty 21.0.0.5
21.0.0.6: WebSphere Application Server Liberty 21.0.0.6
21.0.0.7: WebSphere Application Server Liberty 21.0.0.7
21.0.0.8: WebSphere Application Server Liberty 21.0.0.8
21.0.0.9: WebSphere Application Server Liberty 21.0.0.9
21.0.0.1: WebSphere Application Server Liberty 21.0.0.1
21.0.0.2: WebSphere Application Server Liberty 21.0.0.2
21.0.0.10: WebSphere Application Server Liberty 21.0.0.10
21.0.0.11: WebSphere Application Server Liberty 21.0.0.11
21.0.0.12: WebSphere Application Server Liberty 21.0.0.12
22.0.0.1: WebSphere Application Server Liberty 22.0.0.1
22.0.0.2: WebSphere Application Server Liberty 22.0.0.2
22.0.0.3: WebSphere Application Server Liberty 22.0.0.3
22.0.0.4: WebSphere Application Server Liberty 22.0.0.4

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • NPE thrown:
    in java.lang.NullPointerException
    at com.ibm.ws.ejbcontainer.security.internal.
    EJBSecurityCollaboratorImpl.authorizeEJB(EJBSecurityCollabor
    ator
    Impl.
    java:370)
    

Local fix

  • NA
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server Liberty at 17.0.0.1 or earlier       *
    *                  level                                       *
    ****************************************************************
    * PROBLEM DESCRIPTION: NullPointerException is thrown after    *
    *                      IBM JDK upgrade to Java 8 SR5 FP10      *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    IBM JDK Java 8 SR5 FP10 includes APAR IJ03256 (http://www-
    01.ibm.com/support/docview.wss?uid=swg1IJ03256), which delivers
    a fix for Open JDK bug 8015081
    (https://bugs.openjdk.java.net/browse/JDK-8015081).  This fix
    introduced a behavior change to disallow null values in Subject
    Sets.
    
    Due to this change in Java, Liberty may throw
    NullPointerException while refreshing token contents as
    PrivateCredential in Subject.
    
    The following error stack can be seen in trace and in an FFDC
    record:
    
    ------ Sample error stack --------------
    java.lang.NullPointerException: invalid null input(s)
    	at
    java.base/java.util.Objects.requireNonNull(Objects.java:246)
    	at
    java.base/javax.security.auth.Subject$SecureSet.remove(Subject.j
    ava:1171)
    	at
    java.base/java.util.Collections$SynchronizedCollection.remove(Co
    llections.java:2039)
    	at
    com.ibm.ws.security.authentication.internal.jaas.modules.ServerC
    ommonLoginModule.updateSubjectWithPrivateCredentialsOtherThanSSO
    Token(ServerCommonLoginModule.java:257)
    	at
    com.ibm.ws.security.authentication.internal.jaas.modules.ServerC
    ommonLoginModule.updateSubjectWithTemporarySubjectContents(Serve
    rCommonLoginModule.java:237)
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    PI95544

  • Reported component name

    WAS LIBERTY COR

  • Reported component ID

    5725L2900

  • Reported release

    855

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-03-21

  • Closed date

    2018-04-26

  • Last modified date

    2018-04-26

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WAS LIBERTY COR

  • Fixed component ID

    5725L2900

Applicable component levels

  • R855 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSD28V","label":"WebSphere Application Server Liberty Core"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"855","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
04 May 2022