IBM Support

PH52683: OIDC AN NPE CAN OCCUR WHEN EVALUATING A FILTER VALUE

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • If query value of a filter condition returns null, the OIDC
    TAI might emit a java.lang.NullPointerException and not
    intercept the request.
    
    For instance, if the filter is Referer%=acme.us.com and
    there is no Referer for the request, an NPE occurs.
    
    This issue does not occur when general HTTP headers do not
    exist.  For instance, if the Authroization header is not on
    the request, and the filter is Authroization%=Bearer, an NPE
    does not occur.
    
    
    [8/29/22 18:24:39:691 CDT] 0000394a CommonHTTPHea 3
    Configured filter
    [Referer%=acme.us.com]
    [8/29/22 18:24:39:691 CDT] 0000394a CommonHTTPHea 3
    getProcessAll returns [false]
    [8/29/22 18:24:39:691 CDT] 0000394a CommonHTTPHea 3   isAccepted
    HTTPheader obtained from
    'Referer' null
    [2/14/23 16:16:24:502 CST] 0000018a CommonHTTPHea 3
    isAccepted
    Checking
    condition:acme.us-dns.com%=
    [2/14/23 16:16:24:502 CST] 0000018a TrustAssociat 3
    interceptor Jazz Security Architecture OIDC
    TrustAssociationInterceptor throws exception
    java.lang.NullPointerException
    at com.ibm.ws.security.oidc.client.filter.ValueString.containe
    dBy(ValueString.java:75)
    at com.ibm.ws.security.oidc.client.filter.ContainsCondition.ch
    eckCondition(ContainsCondition.java:30)
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server                                      *
    *                  and OIDC                                    *
    ****************************************************************
    * PROBLEM DESCRIPTION: An NPE might occur in the OIDC TAI when *
    *                      it evaluates a filter value when        *
    *                      intercepting a request.                 *
    ****************************************************************
    * RECOMMENDATION:  Install a fix pack or interim fix that      *
    *                  contains this APAR.                         *
    ****************************************************************
    If query value of a filter condition returns null, the OIDC
    TAI might emit a java.lang.NullPointerException and not
    intercept the request.
    This issue does not occur when general HTTP headers do not
    exist.  For instance, if the Authroization header is not on
    the request, and the filter is Authroization%=Bearer, an NPE
    does not occur.
    

Problem conclusion

  • The OIDC TAI is updated to properly process null filter
    conditions.
    
    The fix for this APAR is targeted for inclusion in fix pack
    8.5.5.24 and 9.0.5.16.  For more information, see 'Recommended
    Updates for WebSphere Application Server':
    https://www.ibm.com/support/pages/node/715553
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH52683

  • Reported component name

    WEBS APP SERV N

  • Reported component ID

    5724H8800

  • Reported release

    900

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2023-02-16

  • Closed date

    2023-02-22

  • Last modified date

    2023-02-22

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBS APP SERV N

  • Fixed component ID

    5724H8800

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"9.0","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
23 February 2023