Fixes are available
APAR status
Closed as program error.
Error description
When a session is invalidated during a servlet invocation, and then a getSession call is made in the same servlet invocation after the invalidate call, the session that was just invalidated is erroneously returned. Also, URL rewritting is on by default - this is incorrect.
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: All users of WebSphere Application Server * * also running WebSphere Extended Deployment * * Data Grid / Object Grid. * **************************************************************** * PROBLEM DESCRIPTION: Invalidated sessions were being * * returned on subsequent getSession * * calls on the same servlet request; * * URL encoding was always being * * performed; valid sessions not being * * returned when session are invalidated * * and the created in servlet forward * * scenarios. * **************************************************************** * RECOMMENDATION: * **************************************************************** Invalidated sessions were being returned on subsequent getSession calls on the same servlet request; URL encoding was always being performed; valid sessions not being returned when session are invalidated and the created in servlet forward scenarios.
Problem conclusion
Using the latest 6.1.0 WebSphere Extended Deployment DataGrid/ObjectGrid IFIX2, there we various problems seen during customer testing of this new function (invalidated sessions returned, url encoding occurring when not wanted, valid sessions not returned during servelt forward scenarios). In addition to the fix published for this APAR, this fix will be included in the WebSphere Extended Deployment DataGrid 6.1.0 IFIX3 and the WebSphere Extended Deployment fixpack 6.1.0.1.
Temporary fix
Comments
APAR Information
APAR number
PK53904
Reported component name
WEBSPH APP SERV
Reported component ID
5724J0800
Reported release
61A
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt
Submitted date
2007-10-02
Closed date
2007-10-12
Last modified date
2007-10-12
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
WEBSPH APP SERV
Fixed component ID
5724J0800
Applicable component levels
R61A PSY
UP
R61H PSY
UP
R61I PSY
UP
R61P PSY
UP
R61S PSY
UP
R61W PSY
UP
[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.1","Line of Business":{"code":"LOB45","label":"Automation"}}]
Document Information
Modified date:
19 October 2021