IBM Support

PM80646: OAUTH PROVIDER DOES NOT SUPPORT REVERSE PROXY CONFIGURATION CAUSING INCORRECT URL REDIRECTION

Fixes are available

7.0.0.29: WebSphere Application Server V7.0 Fix Pack 29
PM80646; 8.0.0.5: oauth provider does not support reverse proxy configuration ca
8.0.0.7: WebSphere Application Server V8.0 Fix Pack 7
8.0.0.8: WebSphere Application Server V8.0 Fix Pack 8
7.0.0.31: WebSphere Application Server V7.0 Fix Pack 31
7.0.0.33: WebSphere Application Server V7.0 Fix Pack 33
8.0.0.9: WebSphere Application Server V8.0 Fix Pack 9
7.0.0.35: WebSphere Application Server V7.0 Fix Pack 35
8.0.0.10: WebSphere Application Server V8.0 Fix Pack 10
7.0.0.37: WebSphere Application Server V7.0 Fix Pack 37
8.0.0.11: WebSphere Application Server V8.0 Fix Pack 11
7.0.0.39: WebSphere Application Server V7.0 Fix Pack 39
8.0.0.12: WebSphere Application Server V8.0 Fix Pack 12
7.0.0.41: WebSphere Application Server V7.0 Fix Pack 41
8.0.0.13: WebSphere Application Server V8.0 Fix Pack 13
7.0.0.43: WebSphere Application Server V7.0 Fix Pack 43
8.0.0.14: WebSphere Application Server V8.0 Fix Pack 14
7.0.0.45: WebSphere Application Server V7.0 Fix Pack 45
8.0.0.15: WebSphere Application Server V8.0 Fix Pack 15
7.0.0.29: Java SDK 1.6 SR13 FP2 Cumulative Fix for WebSphere Application Server
7.0.0.45: Java SDK 1.6 SR16 FP60 Cumulative Fix for WebSphere Application Server
7.0.0.31: Java SDK 1.6 SR15 Cumulative Fix for WebSphere Application Server
7.0.0.35: Java SDK 1.6 SR16 FP1 Cumulative Fix for WebSphere Application Server
7.0.0.37: Java SDK 1.6 SR16 FP3 Cumulative Fix for WebSphere Application Server
7.0.0.39: Java SDK 1.6 SR16 FP7 Cumulative Fix for WebSphere Application Server
7.0.0.41: Java SDK 1.6 SR16 FP20 Cumulative Fix for WebSphere Application Server
7.0.0.43: Java SDK 1.6 SR16 FP41 Cumulative Fix for WebSphere Application Server

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • For OAuth, in the case of reverse proxy, the authorization URL
    doesn't reflect the real URL and a reverse proxy is not able to
    rewrite the value.
    

Local fix

  • For the workaround, as the content form template is
    customizable, the developer can update the template to reset
    the authorization url to target server on page load.
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  IBM WebSphere Application Server            *
    *                  administrators of application servers       *
    *                  using OAuth                                 *
    ****************************************************************
    * PROBLEM DESCRIPTION: With OAuth, a user may not be           *
    *                      redirected to a reverse proxy server.   *
    ****************************************************************
    * RECOMMENDATION:  Install a fix pack that incluses this APAR  *
    *                  and update the installed OAuth app,         *
    *                  WebSphereOauth20SP.ear, from the            *
    *                  (WAS_HOME)/installableApps directory..      *
    ****************************************************************
    In a WebSphere OAuth authorization process, a user may not
    be redirected to the requested reverse proxy server after
    authorization is granted.  The user is redirected to an HTTP
    server directly.
    

Problem conclusion

  • The WebSphere Application Server is updated to redirected the
    user to the requested URL.
    
    When a fix pack containing this APAR is installed, the fix
    will not be active until the installed OAuth ear,
    WebSphereOauth20SP.ear, is updated from the
    (WAS_HOME)/installableApps directory.
    
    The fix for this APAR is currently targeted for inclusion in
    fix packs 7.0.0.29, 8.0.0.7 and the fix pack following
    8.5.0.2. Please refer to the Recommended Updates page for
    delivery information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    
    Keywords: IBMWL3WSS, OAUTH
    

Temporary fix

Comments

APAR Information

  • APAR number

    PM80646

  • Reported component name

    WEBSPHERE APP S

  • Reported component ID

    5724J0800

  • Reported release

    700

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2013-01-15

  • Closed date

    2013-03-12

  • Last modified date

    2015-09-23

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE APP S

  • Fixed component ID

    5724J0800

Applicable component levels

  • R700 PSY

       UP

  • R800 PSY

       UP

  • R850 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.0","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
29 October 2021