Fixes are available
8.5.0.1: WebSphere Application Server V8.5 Fix Pack 1
8.0.0.5: WebSphere Application Server V8.0 Fix Pack 5
8.5.0.2: WebSphere Application Server V8.5 Fix Pack 2
8.0.0.6: WebSphere Application Server V8.0 Fix Pack 6
8.0.0.7: WebSphere Application Server V8.0 Fix Pack 7
8.0.0.8: WebSphere Application Server V8.0 Fix Pack 8
8.0.0.9: WebSphere Application Server V8.0 Fix Pack 9
8.0.0.10: WebSphere Application Server V8.0 Fix Pack 10
8.0.0.11: WebSphere Application Server V8.0 Fix Pack 11
8.0.0.12: WebSphere Application Server V8.0 Fix Pack 12
8.0.0.13: WebSphere Application Server V8.0 Fix Pack 13
8.0.0.14: WebSphere Application Server V8.0 Fix Pack 14
8.0.0.15: WebSphere Application Server V8.0 Fix Pack 15
APAR status
Closed as program error.
Error description
Provide custom property to ignore committed response in WSServletResponseCallback
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: All users of IBM WebSphere Application * * Server V8.0 * **************************************************************** * PROBLEM DESCRIPTION: Provide an option to tell WebSphere * * to supress illegalStateException * * when committed Http Response is found. * **************************************************************** * RECOMMENDATION: * **************************************************************** A custom loginModule can gain access to http response by calling com.ibm.wsspi.security.auth.callback.WSServletResponseCallback. When a custom loginModule commits http response in an attempt to show user-friendly error message on user's browser, WebSphere detects the committed response and throws illegalStatusExcepiton. Due to the error, the browser would show generic 403 error. The messages created by the custom loginModule would not reach the browser.
Problem conclusion
This apar introduced a toplevel security custom property : com.ibm.websphere.security.allow.committed.response When this property is set to true, WebSphere does not throw illegalStateException when committed http response is found. This will help custom message in the http response set by the loginModule to be displayed on the end user's browser. APAR PM61452 is currently targeted for inclusion in Fix Packs 8.0.0.5 and 8.5.0.2 of WebSphere Application Server. Please refer to the Recommended Updates page for delivery information: http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980 In addition, please refer to URL: http://www.ibm.com/support/docview.wss?rs=404&uid=swg27006970 for Fix Pack PTF information.
Temporary fix
Comments
APAR Information
APAR number
PM61452
Reported component name
WEBSPHERE FOR Z
Reported component ID
5655I3500
Reported release
800
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt
Submitted date
2012-03-28
Closed date
2012-08-16
Last modified date
2012-08-17
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
WEBSPHERE FOR Z
Fixed component ID
5655I3500
Applicable component levels
R800 PSY
UP
Document Information
Modified date:
28 October 2021