IBM Support

PH31150: NULLPOINTEREXCEPTION DURING GETSESSION WHEN REQUEST CONTAINS A SESSIONID WITH INVALID LENGTH

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • If an incoming request contains a session ID with invalid
    length, a NULLPointerException may occur while application
    tries to call getSession()
    
    [xx/xx/xx xx:xx:xx:xxx UTC]
    000000e6 WASSessionCor W SessionAffinityManager setNextId
    Detected JSESSIONID with invalid length; expected length of 23,
    found 28, setting: 6EE422DCC3D7C035C03AA328D89E to
    null.
    
    [xx/xx/xx xx:xx:xx:xxx UTC] 000000e6 webapp E
    com.ibm.ws.webcontainer.webapp.WebApp logServletError
    SRVE0293E: [Servlet Error]-[MyServlet]:
    java.lang.NullPointerException
     at com.ibm.ws.session.store.comm
    on.BackedHashMap.getSession(BackedHashMap.java:134)
     at com.ibm.
    ws.session.store.common.BackedHashMap.getSession(BackedHashMap.j
    ava:113)
     at com.ibm.ws.session.store.common.BackedStore.getSess
    ion(BackedStore.java:71)
     at com.ibm.ws.session.store.memory.Mem
    oryStore.getSession(MemoryStore.java:717)
     at com.ibm.ws.session
    .SessionManager.getSessionFromStore(SessionManager.java:500)
    
    at com.ibm.ws.session.SessionManager.getSession(SessionManager.j
    ava:479)
     at com.ibm.ws.session.SessionManager.getSession(Sessio
    nManager.java:465)
     at com.ibm.ws.session.SessionManager.getSess
    ion(SessionManager.java:707)
     at com.ibm.ws.session.SessionConte
    xt.getIHttpSession(SessionContext.java:473)
     at com.ibm.ws.sessi
    on.SessionContext.getIHttpSession(SessionContext.java:426)
     at c
    om.ibm.ws.webcontainer.srt.SRTRequestContext.getSession(SRTReque
    stContext.java:113)
     at com.ibm.ws.webcontainer.srt.SRTServletRe
    quest.getSession(SRTServletRequest.java:2212)
     at javax.servlet.
    http.HttpServletRequestWrapper.getSession(HttpServletRequestWrap
    per.java:238)
    		.....
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server                                      *
    ****************************************************************
    * PROBLEM DESCRIPTION: Session manager may give                *
    *                      NullpointerException when JSESSIONID is *
    *                      altered                                 *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    When session manager detected JSESSIONID with invalid length,
    null session will be returned which may lead to
    NullpointerException randomly in the subsequent calls.
    

Problem conclusion

  • Code changes were made to catch the null session calls.
    
    The fix for this APAR is targeted for inclusion in fix pack
    8.5.5.20 and 9.0.5.7.
    For more information, see 'Recommended Updates for WebSphere
    Application Server':
    https://www.ibm.com/support/pages/node/715553
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH31150

  • Reported component name

    WEBS APP SERV N

  • Reported component ID

    5724H8800

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-11-01

  • Closed date

    2021-01-21

  • Last modified date

    2021-01-21

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBS APP SERV N

  • Fixed component ID

    5724H8800

Applicable component levels

  • R850 PSY

       UP

  • R900 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.5","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
02 November 2021