IBM Support

PI07543: COOKIE HTTPONLY CAUSES STRINGINDEXOUTOFBOUNDSEXCEPTION IN HTTPCOOKIE CLASS

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Web container custom property "com.ibm.ws.webcontainer
    .HTTPOnlyCookies" causes WebSphere Application Server to extend
    all cookies by key-only attribute "HTTPOnly", which cannot be
    interpreted by portlet container class
    "com.ibm.wps.pe.pc.legacy.service.proxysupport.HttpCookie".
    
    WebSphere Portal reports the following exception in
    SystemOut.log:
    
    [12/4/13 21:42:38:660 CET] 00000042 AbstractRemot E
    com.ibm.wps.remote.model.AbstractRemoteModel findByUniqueName
    Exception occured
    
    java.lang.StringIndexOutOfBoundsException
     at java.lang.String.substring(String.java:1093)
     at com.ibm.wps.pe.pc.legacy.service.proxysupport.HttpCookie
    .parseSingleCookie(HttpCookie.java:74)
     at com.ibm.wps.pe.pc.legacy.service.proxysupport.HttpCookie
    .parse(HttpCookie.java:51)
     at com.ibm.wps.pe.pc.legacy.service.proxysupport.CookieManager
    .put(CookieManager.java:128)
     at com.ibm.wps.connection.CookiedHttpURLConnection
    .getInputStream(CookiedHttpURLConnection.java:97)
    [...]
    

Local fix

  • Remove custom property "com.ibm.ws.webcontainer
    .HTTPOnlyCookies"
    from the web container service settings in the administrative
    console of WebSphere Application Server.
    

Problem summary

  • Web container custom property "com.ibm.ws.webcontainer
    .HTTPOnlyCookies" causes WebSphere Application Server to extend
    all cookies by key-only attribute "HTTPOnly", which cannot be
    interpreted by portlet container class
    "com.ibm.wps.pe.pc.legacy.service.proxysupport.HttpCookie".
    .
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    PI07543

  • Reported component name

    WEBSPHERE PORTA

  • Reported component ID

    5724E7600

  • Reported release

    700

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2013-12-05

  • Closed date

    2014-02-13

  • Last modified date

    2014-02-13

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE PORTA

  • Fixed component ID

    5724E7600

Applicable component levels

  • R700 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSHRKX","label":"WebSphere Portal"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.0","Line of Business":{"code":"LOB31","label":"WCE Watson Marketing and Commerce"}}]

Document Information

Modified date:
11 December 2021