APAR status
Closed as program error.
Error description
OIDC might think that the UserInfo output is a JWT when it is not.
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: All users of IBM WebSphere Application * * Server * * and OIDC * **************************************************************** * PROBLEM DESCRIPTION: When the OIDC TAI processes the * * UserInfo * * output from a provider, the TAI might * * think that the UserInfo is a JWT when * * it * * is not * **************************************************************** * RECOMMENDATION: Install a fix pack or interim fix that * * contains this APAR. * **************************************************************** If plain-text UserInfo output from an OpenID connect provider contains three periods, the OIDC TAI thinks that the UserInfo is a JWT when it is not. The TAI then attempts to decode the UserInfo as a JWT, which fails. The following error is emitted: CWTAI2089E: The response is not in JSON format. Failed to parse JSON string [java.lang.IllegalStateException: Not a JSON Object (characters)]
Problem conclusion
The OIDC TAI is updated to properly identify plain-text UserInfo output. The fix for this APAR is targeted for inclusion in fix packs 8.5.5.27 and 9.0.5.24. For more information, see 'Recommended Updates for WebSphere Application Server': https://www.ibm.com/support/pages/node/715553
Temporary fix
Comments
APAR Information
APAR number
PH65119
Reported component name
WEBS APP SERV N
Reported component ID
5724H8800
Reported release
900
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2025-02-04
Closed date
2025-03-10
Last modified date
2025-03-10
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
WEBS APP SERV N
Fixed component ID
5724H8800
Applicable component levels
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"9.0","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]
Document Information
Modified date:
10 March 2025