Fixes are available
PI94754:ADMR0024E: User
8.5.5.14: WebSphere Application Server V8.5.5 Fix Pack 14
8.5.5.15: WebSphere Application Server V8.5.5 Fix Pack 15
8.5.5.17: WebSphere Application Server V8.5.5 Fix Pack 17
8.5.5.20: WebSphere Application Server V8.5.5.20
8.5.5.18: WebSphere Application Server V8.5.5 Fix Pack 18
8.5.5.19: WebSphere Application Server V8.5.5 Fix Pack 19
8.5.5.16: WebSphere Application Server V8.5.5 Fix Pack 16
APAR status
Closed as program error.
Error description
The following error message was seen in log files: [2/7/18 13:31:07:470 CET] 000000fd RoleBasedAuth 3 Unauthenticated or missing subject/credentials. java.lang.Exception: Unauthenticated or missing subject/credentials. at com.ibm.ws.security.role.RoleBasedAuthorizerImpl.getEffectiveCre dentials(RoleBasedAuthorizerImpl.java:785) at com.ibm.ws.security.role.RoleBasedAuthorizerImpl.isGrantedAnyRol e(RoleBasedAuthorizerImpl.java:981) at com.ibm.ws.management.authorizer.AdminAuthorizerImpl.checkAccess (AdminAuthorizerImpl.java:810) at com.ibm.ws.management.authorizer.AdminAuthorizerImpl.checkAccess (AdminAuthorizerImpl.java:259) ... ... at com.ibm.websphere.management.application.EditionHelper.getActive EditionOnServer(EditionHelper.java:645) at com.ibm.ws.policyset.runtime.server.FileLocatorImpl$3.run(FileLo catorImpl.java:232) at com.ibm.ws.policyset.runtime.server.FileLocatorImpl$3.run(FileLo catorImpl.java:229) at java.security.AccessController.doPrivileged(AccessController.jav a:400) at com.ibm.ws.policyset.runtime.server.FileLocatorImpl.getActiveEdi tion(FileLocatorImpl.java:228) ... ...
Local fix
N/A
Problem summary
**************************************************************** * USERS AFFECTED: All users of IBM WebSphere Application * * Server for JAX-WS Web services with polciy * * attachments. * **************************************************************** * PROBLEM DESCRIPTION: ADMR0024E: User <null> does not have * * the required role to access 1 * * document(s). * **************************************************************** * RECOMMENDATION: * **************************************************************** The following error message was seen in log files: [2/7/18 13:31:07:470 CET] 000000fd RoleBasedAuth 3 Unauthenticated or missing subject/credentials. java.lang.Exception: Unauthenticated or missing subject/credentials. at com.ibm.ws.security.role.RoleBasedAuthorizerImpl.getEffectiveCre dentials(RoleBasedAuthorizerImpl.java:785) at com.ibm.ws.security.role.RoleBasedAuthorizerImpl.isGrantedAnyRol e(RoleBasedAuthorizerImpl.java:981) at com.ibm.ws.management.authorizer.AdminAuthorizerImpl.checkAccess (AdminAuthorizerImpl.java:810) at com.ibm.ws.management.authorizer.AdminAuthorizerImpl.checkAccess (AdminAuthorizerImpl.java:259) ... ... at com.ibm.websphere.management.application.EditionHelper.getActive EditionOnServer(EditionHelper.java:645) at com.ibm.ws.policyset.runtime.server.FileLocatorImpl$3.run(FileLo catorImpl.java:232) at com.ibm.ws.policyset.runtime.server.FileLocatorImpl$3.run(FileLo catorImpl.java:229) at java.security.AccessController.doPrivileged(AccessController.jav a:400) at com.ibm.ws.policyset.runtime.server.FileLocatorImpl.getActiveEdi tion(FileLocatorImpl.java:228) ... ... When security is enabled, the error message may look like the following: ADMR0024E: User defaultWIMFileBasedRealm/user1_5 does not have the required role to access 1 document(s).
Problem conclusion
The problem has been resolved by adding proper access control code. The fix for this APAR is currently targeted for inclusion in fix pack 8.5.5.14. Please refer to the Recommended Updates page for delivery information: http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
Temporary fix
Comments
APAR Information
APAR number
PI94754
Reported component name
WEBS APP SERV N
Reported component ID
5724H8800
Reported release
850
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2018-03-06
Closed date
2018-03-22
Last modified date
2018-03-22
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
WEBS APP SERV N
Fixed component ID
5724H8800
Applicable component levels
R850 PSY
UP
[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.5","Line of Business":{"code":"LOB45","label":"Automation"}}]
Document Information
Modified date:
11 January 2022