IBM Support

PH69515: OIDC MIGHT GET A STATE COOKIE ERROR WHEN THE CLIENTSECRET PARAMETER IS NOT SET

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • When the clientSecret is not provided in the OIDC config, if the
    state data must be read from the State cookie value, an error
    like the following might be emitted:
    
    - The OIDC state cookie [OIDCSTATE_rp1] is not in the correct
    format.
    

Local fix

  • Reconfigure the OIDC TAI with a clientSecret property.  This
    might require a change in the OP's configuration.
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server and OIDC                             *
    ****************************************************************
    * PROBLEM DESCRIPTION: OIDC authentication might fail if the   *
    *                      clientSecret parameter is not set to    *
    *                      a value.                                *
    ****************************************************************
    When the clientSecret is not provided in the OIDC config, if the
    state data must be read from the State cookie value, an error
    like the following might be emitted: - The OIDC state cookie
    [OIDCSTATE_rp1] is not in the correct format. The following
    entry appears in an OIDC trace: [12/16/25 16:09:35:474 EET]
    000001c9 StateData 3 The cookie may have been tampered with.
    [12/16/25 16:09:35:474 EET] 000001c9 StateData 3 The cookie does
    not contain an underscore.
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    PH69515

  • Reported component name

    WEBSPHERE APP S

  • Reported component ID

    5724J0800

  • Reported release

    900

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2025-12-29

  • Closed date

    2026-05-06

  • Last modified date

    2026-05-06

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE APP S

  • Fixed component ID

    5724J0800

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"9.0","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Document Information

Modified date:
06 May 2026