Release Notes
Abstract
Changes included in some fix packs might negatively affect existing product function. Evaluate these APAR(s) for the potential impact in your environment.
Content
# 8.5.5.27
| APAR | Impact | Description |
|---|---|---|
|
Medium |
"THE SPECIFIED SSLALIAS NAME DOES NOT EXIST" despite com.ibm.websphere.ssl.fallback.for.nonexistent.alias or "node/" prefixed DefaultSSLAlias |
# 8.5.5.26
| APAR | Impact | Description |
|---|---|---|
|
High |
MQ uses wrong SSL settings or Java Proxy and ODR fails to start or send requests |
|
|
Medium |
WAS startup fails complaining of 'The element type 'services' must be terminated by the matching...' |
# 8.5.5.25
| APAR | Impact | Description |
|---|---|---|
|
High |
Exception creating CMS keystore |
# 8.5.5.24
| APAR | Impact | Description |
|---|---|---|
|
High |
java.lang.NullPointerException occurs related to to com.ibm.ISecurityUtilityImpl.PasswordUtil |
|
|
Medium |
Failure to create CMS keystore with NPE in com.ibm.ws.ssl.config.CMSKeyStoreUtility.usePQCForCMSKeystore |
|
|
Low |
NCSA log incorrectly displays the year timestamp when configured 'accessLogFormat' |
# 8.5.5.23
| APAR | Impact | Description |
|---|---|---|
|
High |
java.lang.NullPointerException occurs related to to com.ibm.ISecurityUtilityImpl.PasswordUtil |
|
|
Medium |
Problem with AdminTask.enablePasswordEncryption |
|
|
Medium |
Possible deadlock in resource adapters |
|
|
Medium |
LDAP SSL Connections may use default SSL config |
# 8.5.5.22
| APAR | Impact | Description |
|---|---|---|
|
High |
RENEWING WAS GENERATED PERSONAL CERTIFICATE NOT REFLECTED BY SOAP ENDPOINT |
|
|
Medium |
Errors federating or syncing 8.5.5.21 and earlier nodes to 8.5.5.22 |
|
|
Medium |
Possible deadlock in resource adapters |
|
|
Medium |
java.lang.IllegalArgumentException: Class 'Group' does not have a feature named 'password.' |
|
|
Partial Fix |
'Error creating client_auth_token' at server shutdown. |
# 8.5.5.21
| APAR | Impact | Description |
|---|---|---|
|
High |
RENEWING WAS GENERATED PERSONAL CERTIFICATE NOT REFLECTED BY SOAP ENDPOINT |
|
|
Medium |
APPCLIENT fails to install and update in 8.5.5.21 |
|
|
Medium |
JVMCFRE106 DUPLICATE METHOD error will be logged when client attempts to use an EJB |
|
|
Medium |
Quality of protection panel for System SSL not accessible. |
|
|
Medium |
Possible deadlock in resource adapters |
|
|
Low |
NPE in SSL Socket Factory |
|
|
Low |
Some expected TLS ciphers not negotiable |
|
|
Low |
NPE in com.ibm.ejs.j2c.ConnectionFactoryRefBuilderImpl |
|
|
Low |
ArrayIndexOutOfBoundsException after 8.5.5.20/9.0.5.8 |
|
|
Low |
The asserted user 'unauthenticated' is no longer authenticated. |
|
|
Partial Fix |
'Error creating client_auth_token' at server shutdown. |
# 8.5.5.20
| APAR | Impact | Description |
|---|---|---|
|
Medium |
OpenID Connect CWTAI2030I/CWTAI2007E |
|
|
Medium |
NPE in Portlet Bridge |
|
|
Medium |
STOPSERVER, SERVERSTATUS FAILS WHEN AES ENCRYPTION IS ENABLED FOR THE COMMAND |
|
|
Medium |
NPE submitting batch job with no servers available |
|
|
Medium |
early webServer crashes with Intelligent Management enabled |
|
|
Medium |
Possible deadlock in resource adapters |
|
|
Medium |
java.lang.ClassNotFoundException: org.apache.myfaces.application.viewstate.SecureSerializedViewCollection |
|
|
Low |
Some expected TLS ciphers not negotiable |
|
|
Low |
ClassCastException in WebCollaborator |
|
|
Low |
ArrayIndexOutOfBoundsException after 8.5.5.20/9.0.5.8 |
|
|
Low |
The asserted user 'unauthenticated' is no longer authenticated. |
# 8.5.5.19
| APAR | Impact | Description |
|---|---|---|
|
Medium |
OpenID Connect CWTAI2030I/CWTAI2007E |
|
|
Medium |
startup failure after disabling custom password encryption |
|
|
Medium |
Possible deadlock in resource adapters |
|
|
Medium |
Datasource custom property password problems |
|
|
Low |
Profile or certificate creation fails with |
|
|
Low |
Password prompt hides terminal output on IBM I platform |
|
|
Low |
Custom scheduler in the EJB timer service panel not displayed correctly |
|
|
Low |
The asserted user 'unauthenticated' is no longer authenticated. |
# 8.5.5.18
| APAR | Impact | Description |
|---|---|---|
|
High |
Potential vulnerability in admin console |
|
|
Medium |
CNTR5104E RECEIVED WHEN DEPLOYING EJB APPLICATION |
|
|
Medium |
NPE with custom password encryption |
|
|
Medium |
Possible deadlock in resource adapters |
|
|
Medium |
failed to login to admin console the first time with RAD |
|
|
Medium |
OpenID Connect CWTAI2030I/CWTAI2007E |
|
|
Medium |
startup failure after disabling custom password encryption |
|
|
Low |
Some admin console with collection tables load slowly |
|
|
Low |
no post-sync deployment processing on dmgr |
|
|
Low |
Custom scheduler in the EJB timer service panel not displayed correctly |
|
|
Low |
The asserted user 'unauthenticated' is no longer authenticated. |
|
|
Low |
Password prompt hides terminal output on IBM I platform |
|
|
Low |
HTML img tag element displayed inside the TPV |
|
|
Low |
Profile or certificate creation fails with |
# 8.5.5.17
| APAR | Impact | Description |
|---|---|---|
|
High |
Potential vulnerability in admin console |
|
|
Medium |
native_stdout.log on Windows fills up with repeating debug timestamps |
|
|
Medium |
CWWIM5106E with mixed cell including 8.5.5.17 or later |
|
|
Medium |
CNTR5104E RECEIVED WHEN DEPLOYING EJB APPLICATION |
|
|
Low |
HTML img tag element displayed inside the TPV |
|
|
Low |
no post-sync deployment processing on dmgr |
|
|
Low |
Some admin console with collection tables load slowly |
|
|
Low |
Custom scheduler in the EJB timer service panel not displayed correctly |
# 8.5.5.16
| APAR | Impact | Description |
|---|---|---|
|
High |
CNTR5104E RECEIVED WHEN DEPLOYING EJB APPLICATION |
|
|
High |
Potential vulnerability in admin console |
|
|
Medium |
Failure in Admin Console after editing multi-valued custom property |
|
|
Medium |
Intermittent ConcurrentModificationException from MetadataRepository |
|
|
Medium |
JSF errors related to java.io.FileNotFoundException: 'Too many open files'. |
|
|
Medium |
SECJ0129E authorization failure under load on z/OS using SAF Authorization. |
|
|
Medium |
CNTR5104E RECEIVED WHEN DEPLOYING EJB APPLICATION |
|
|
Low |
Customized task list in admin console not displayed as links |
|
|
Low |
HTML img tag element displayed inside the TPV |
|
|
Low |
WebServer logs with '_log' in the name can't be viewed in the console |
|
|
Low |
Some admin console with collection tables load slowly |
# 8.5.5.15
| APAR | Impact | Description |
|---|---|---|
|
High |
Potential vulnerability in admin console |
|
|
Medium |
Failure in Admin Console after editing multi-valued custom property |
|
|
Medium |
JSF errors related to java.io.FileNotFoundException: 'Too many open files'. |
|
|
Medium |
SECJ0129E authorization failure under load on z/OS using SAF Authorization. |
|
|
Medium |
Potential denial of service in WebSphere Application Server Admin Console (CVE-2019-4080) |
|
|
Medium |
Correction for PH02461 |
|
|
Medium |
LDAP search filter issue with parenthesis |
|
|
Low |
HTML img tag element displayed inside the TPV |
|
|
Low |
clearClassCache not run on upgrade |
|
|
Low |
WebServer logs with '_log' in the name can't be viewed in the console |
|
|
Low |
class version error starting NDDMZ on z/OS |
# 8.5.5.14
| APAR | Impact | Description |
|---|---|---|
|
Medium |
Failure in Admin Console after editing multi-valued custom property |
|
|
Medium |
Daemon abend0c4s in bboclssa and possible termination |
|
|
Medium |
JSF errors related to java.io.FileNotFoundException: 'Too many open files'. |
|
|
Medium |
SECJ0129E authorization failure under load on z/OS using SAF Authorization. |
|
|
Low |
Remove or update PI97281 |
|
|
Low |
HTML img tag element displayed inside the TPV |
|
|
Low |
clearClassCache not run on upgrade |
|
|
Low |
WebServer logs with '_log' in the name can't be viewed in the console |
|
|
Low |
Inputting an invalid webserver conf file path on the console produces a blank page |
# 8.5.5.13
| APAR | Impact | Description |
|---|---|---|
|
Medium |
Daemon abend0c4s in bboclssa and possible termination |
|
|
Medium |
Update of composite component within an ui:repeat does not work |
|
|
Low |
HTML img tag element displayed inside the TPV |
|
|
Low |
clearClassCache not run on upgrade |
|
|
Low |
In use count can be wrong after APAR PI77049 - causing ABEND=00dc3000 RSNCODE=0a150001 |
|
|
Low |
Allow empty main-class attribute in manifest.mf for application client module |
|
|
Low |
Not able to renew a self-signed wildcard certificate |
# 8.5.5.12
| APAR | Impact | Description |
|---|---|---|
|
High |
IBMPROXY is down by SIGSEGV |
|
|
High |
ClassCastExceptions during naming lookup for beanManger |
|
|
Medium |
JMS connections from Websphere Application Server (WAS) are not destroyed was to fix pack v8.5.5.12 |
|
|
Medium |
Reimplements the fixes for PI75986 and PI78268 |
|
|
Medium |
ArrayIndexOutOfBoundsException from OpenJPA for @EmbeddedId |
|
|
Low |
Web Service call is failing after applying latest FixPacks + IFPI70810 |
|
|
Low |
HTML img tag element displayed inside the TPV |
|
|
Low |
In use count can be wrong after APAR PI77049 - causing ABEND=00dc3000 RSNCODE=0a150001 |
|
|
Low |
Dynamic outbound ssl configuration incorrectly matching outbound request |
|
|
Low |
Allow empty main-class attribute in manifest.mf for application client module |
|
|
Low |
com.ibm.websphere.security.spnego.useRACMAPMappingToSAF property value not displayed correctly in admin console |
|
|
Low |
JPA application behavior changes after migration to WAS 9.0.0.4 |
# 8.5.5.11
| APAR | Impact | Description |
|---|---|---|
|
High |
Hang on org/apache/webbeans/context/sessioncontext.addchildrequest |
|
|
Medium |
SRVE0014E from dynacache component |
|
|
Medium |
Loop while closing an SSL connection |
|
|
Medium |
Web Services Potential for weak Client security bindings (CVE-2017-1501) |
|
|
Medium |
VMM panel fails with an authentication error when applying changes to the security configuration of LDAP |
|
|
Medium |
ArrayIndexOutOfBoundsException from OpenJPA for @EmbeddedId |
|
|
Low |
Issues with ResponseWrapper |
|
|
Low |
com.ibm.websphere.security.spnego.useRACMAPMappingToSAF property value not displayed correctly in admin console |
|
|
Low |
JPA application behavior changes after migration to WAS 9.0.0.4 |
|
|
Low |
WSGRID jobs not getting ended status returned by SIBus z/OS |
# 8.5.5.10
| APAR | Impact | Description |
|---|---|---|
|
High |
java.lang.ClassCastException when group search is performed |
|
|
Medium |
PMI counters URIRequestCount URIConcurrentRequests and URIServiceTime are disabled at runtime. |
|
|
Medium |
Loop while closing an SSL connection |
|
|
Medium |
VMM panel fails with an authentication error when applying changes to the security configuration of LDAP |
|
|
Medium |
Security crypto jar fails with Not signed by a trusted signer error |
|
|
Medium |
Web Services Potential for weak Client security bindings (CVE-2017-1501) |
|
|
Medium |
A JSP error Unresolved compilation problem is thrown during runtime |
|
|
Low |
JPA application behavior changes after migration to WAS 9.0.0.4 |
|
|
Low |
Choosing 'none' for JNDI datasource name of Job Scheduler System app no longer causes automatic configuration of default datasource |
|
|
Low |
com.ibm.websphere.security.spnego.useRACMAPMappingToSAF property value not displayed correctly in admin console |
|
|
Low |
WSGRID jobs not getting ended status returned by SIBus z/OS |
|
|
Low |
NullPointerException is seen in some cases when a client does not trust a server |
|
|
Low |
Error occurs when viewing Intelligent Management charting report |
# 8.5.5.9
| APAR | Impact | Description |
|---|---|---|
|
High |
JAX-WS application fails with a java.lang.ClassCastException in the log |
|
|
Medium |
PMI counters URIRequestCount URIConcurrentRequests and URIServiceTime are disabled at runtime. |
|
|
Medium |
HMGR0149E logged when com.ibm.wsspi.security.token.singleSignonTokenFactory property changed to com.ibm.ws.security.ltpa.LTPATokenFactory |
|
|
Medium |
Collector script fails on z/OS with collector.sh 37: FSUM7351 not found |
|
|
Medium |
A JSP error Unresolved compilation problem is thrown during runtime |
|
|
Low |
Error occurs when viewing Intelligent Management charting report |
|
|
Low |
Default ThreadPoolStats data cannot be retrieved due to InstanceNotFoundException |
|
|
Low |
NullPointerException is seen in some cases when a client does not trust a server |
|
|
Low |
JPA application behavior changes after migration to WAS 9.0.0.4 |
|
|
Low |
Choosing 'none' for JNDI datasource name of Job Scheduler System app no longer causes automatic configuration of default datasource |
|
|
Low |
Liberty: configUtility find or install throws a NoClassDefFoundError by local repository |
|
|
Low |
WSGRID jobs not getting ended status returned by SIBus z/OS |
# 8.5.5.8
| APAR | Impact | Description |
|---|---|---|
|
High |
Out Of Memory error on the On Demand Router due to HttpRouteAction objects accumulating |
|
|
High |
Liberty: Collective member certificate login fails with LDAP or Federated user registry |
|
|
Medium |
HMGR0149E logged when com.ibm.wsspi.security.token.singleSignonTokenFactory property changed to com.ibm.ws.security.ltpa.LTPATokenFactory |
|
|
Medium |
Collector script fails on z/OS with collector.sh 37: FSUM7351 not found |
|
|
Medium |
PMI counters URIRequestCount URIConcurrentRequests and URIServiceTime are disabled at runtime. |
|
|
Medium |
Extraneous error messages display when trying to stop an application |
|
|
Medium |
SAML token fails signature validation after being propagated by WS-Security |
|
|
Low |
NullPointerException is seen in some cases when a client does not trust a server |
|
|
Low |
The Value of annotations is ignored when injecting beans |
|
|
Low |
Liberty: Merged plugin-cfg.xml generated by ClusterManager mbean generate ClusterPluginConfig operation contains dup elements |
|
|
Low |
JPA application behavior changes after migration to WAS 9.0.0.4 |
|
|
Low |
Liberty: configUtility find or install throws a NoClassDefFoundError by local repository |
|
|
Low |
WSGRID jobs not getting ended status returned by SIBus z/OS |
|
|
Low |
Default ThreadPoolStats data cannot be retrieved due to InstanceNotFoundException |
|
|
Low |
A redirect using an URI relative to the current request URL redirects to the wrong URL |
# 8.5.5.7
| APAR | Impact | Description |
|---|---|---|
|
High |
Out Of Memory error on the On Demand Router due to HttpRouteAction objects accumulating |
|
|
High |
When doing IdP-initiated SSO if a RelayState is not in the SAMLResponse the authentication fails |
|
|
High |
500 error when rolling out new edition and deleting old edition |
|
|
High |
Liberty: Collective member certificate login fails with LDAP or Federated user registry |
|
|
High |
XA Transaction recovery issues might occur |
|
|
Medium |
z/OS users could experience authorization failures and see error message: SECJ0129E: Authorization failed for user |
|
|
Medium |
Collector script fails on z/OS with collector.sh 37: FSUM7351 not found |
|
|
Medium |
The publishWSDL command is not picking up changes made to the HTTP URL |
|
|
Medium |
HMGR0149E logged when com.ibm.wsspi.security.token.singleSignonTokenFactory property changed to com.ibm.ws.security.ltpa.LTPATokenFactory |
|
|
Medium |
SAML token fails signature validation after being propagated by WS-Security |
|
|
Medium |
Contexts and Dependency Injection (CDI) Application Scoped contexts are not acquired properly causing issues with web services applications |
|
|
Low |
The Value of annotations is ignored when injecting beans |
|
|
Low |
Liberty: Merged plugin-cfg.xml generated by ClusterManager mbean generate ClusterPluginConfig operation contains dup elements |
|
|
Low |
NullPointerException is seen in some cases when a client does not trust a server |
|
|
Low |
JPA application behavior changes after migration to WAS 9.0.0.4 |
|
|
Low |
Liberty: configUtility find or install throws a NoClassDefFoundError by local repository |
|
|
Low |
Default ThreadPoolStats data cannot be retrieved due to InstanceNotFoundException |
|
|
Low |
WSGRID jobs not getting ended status returned by SIBus z/OS |
|
|
Low |
A redirect using an URI relative to the current request URL redirects to the wrong URL |
# 8.5.5.6
| APAR | Impact | Description |
|---|---|---|
|
High |
Liberty: Collective member certificate login fails with LDAP or Federated user registry |
|
|
High |
Out Of Memory error on the On Demand Router due to HttpRouteAction objects accumulating |
|
|
Medium |
Contexts and Dependency Injection (CDI) Application Scoped contexts are not acquired properly causing issues with web services applications |
|
|
Medium |
NullPointerException might be caught in the servlet listener code when security is enabled. |
|
|
Low |
A redirect using an URI relative to the current request URL redirects to the wrong URL |
|
|
Low |
Default ThreadPoolStats data cannot be retrieved due to InstanceNotFoundException |
|
|
Low |
NullPointerException is seen in some cases when a client does not trust a server |
|
|
Low |
Liberty profile: There is an increased performance overhead for users of the SSL feature in Liberty profile |
|
|
Low |
Liberty: Merged plugin-cfg.xml generated by ClusterManager mbean generate ClusterPluginConfig operation contains dup elements |
|
|
Low |
JPA application behavior changes after migration to WAS 9.0.0.4 |
|
|
Low |
OSGi applications that contain blueprint xml in bundle fragments do not start after Liberty profile update |
|
|
Low |
Dynamic switching from polled to mbean (and vice versa) config monitoring doesn't work. |
# 8.5.5.5
| APAR | Impact | Description |
|---|---|---|
|
High |
Out Of Memory error on the On Demand Router due to HttpRouteAction objects accumulating |
|
|
High |
'java.lang.Exception: A WSDL Definition could not be generated for the implementation class could happen during application deployment |
|
|
Medium |
Memory leak when _ underscore character used in JMS connection factory name |
|
|
Medium |
Contexts and Dependency Injection (CDI) Application Scoped contexts are not acquired properly causing issues with web services applications |
|
|
Low |
A redirect using an URI relative to the current request URL redirects to the wrong URL |
|
|
Low |
Default ThreadPoolStats data cannot be retrieved due to InstanceNotFoundException |
|
|
Low |
A Property File Based Configuration (PFBC) file might fail to apply |
|
|
Low |
Liberty profile: There is an increased performance overhead for users of the SSL feature in Liberty profile |
|
|
Low |
Liberty: Merged plugin-cfg.xml generated by ClusterManager mbean generate ClusterPluginConfig operation contains dup elements |
|
|
Low |
JPA application behavior changes after migration to WAS 9.0.0.4 |
|
|
Low |
OSGi applications that contain blueprint xml in bundle fragments do not start after Liberty profile update |
|
|
Low |
Dynamic switching from polled to mbean (and vice versa) config monitoring doesn't work. |
# 8.5.5.4
| APAR | Impact | Description |
|---|---|---|
|
High |
Out Of Memory error on the On Demand Router due to HttpRouteAction objects accumulating |
|
|
High |
'java.lang.Exception: A WSDL Definition could not be generated for the implementation class could happen during application deployment |
|
|
Medium |
NumberFormatException in Extended Cache Monitor |
|
|
Medium |
When removing a server or a node with Dynamic SSL Configuration on WebSphere Application Server a NullPointerException is shown. |
|
|
Medium |
Contexts and Dependency Injection (CDI) Application Scoped contexts are not acquired properly causing issues with web services applications |
|
|
Medium |
Memory leak when _ underscore character used in JMS connection factory name |
|
|
Medium |
NullPointerException when application uses CDI @Produces method with InjectionPoint |
|
|
Low |
DMZ Proxy installation not writable by WASADMIN |
|
|
Low |
A redirect using an URI relative to the current request URL redirects to the wrong URL |
|
|
Low |
Liberty profile: ApacheValidationProvider class not found by third party packages that utilize Bean Validation |
|
|
Low |
Liberty profile: applications do not pick up published changes to annotation-based metadata. |
|
|
Low |
If a Parallel Job Manager Top Level Job is cancelled before all subjobs are submitted the Top Level Job will remain in cancel pending state. |
|
|
Low |
OSGi applications that contain blueprint xml in bundle fragments do not start after Liberty profile update |
|
|
Low |
Liberty: Merged plugin-cfg.xml generated by ClusterManager mbean generate ClusterPluginConfig operation contains dup elements |
|
|
Low |
Session remains open in SipContainer if it has a newly created outgoing message which was not sent. |
|
|
Low |
Default ThreadPoolStats data cannot be retrieved due to InstanceNotFoundException |
# 8.5.5.3
| APAR | Impact | Description |
|---|---|---|
|
High |
'java.lang.Exception: A WSDL Definition could not be generated for the implementation class could happen during application deployment |
|
|
High |
Liberty profile: FileNotFoundExceptions when file paths include spaces. |
|
|
High |
Liberty profile: ClassNotFoundExceptions occur where nested libraries are in use |
|
|
High |
Out Of Memory error on the On Demand Router due to HttpRouteAction objects accumulating |
|
|
High |
A potential performance issue with ODR/Proxy on Microsoft Windows operating systems |
|
|
High |
System garbage collection(gc) is getting called very frequently and causing High Cpu Usage. |
|
|
Medium |
Memory leak when _ underscore character used in JMS connection factory name |
|
|
Medium |
NumberFormatException in Extended Cache Monitor |
|
|
Medium |
NullPointerException when application uses CDI @Produces method with InjectionPoint |
|
|
Medium |
When removing a server or a node with Dynamic SSL Configuration on WebSphere Application Server a NullPointerException is shown. |
|
|
Low |
The application login page is repeatedly displayed after supplying userid and password |
|
|
Low |
Liberty profile Resource references must match based on type rather than name only |
|
|
Low |
Default ThreadPoolStats data cannot be retrieved due to InstanceNotFoundException |
Was this topic helpful?
Document Information
Modified date:
26 February 2025
UID
ibm11172212