IBM Support

PM23579: JSESSIONID COOKIE NOT CORRECTLY REVOKED ON LOGOUT

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • The JSESSIONID cookie is to be revoked upon logout, but the
    cookie modification code does not always set the correct cookie
    path. In this case, browsers will ignore the cookie change and
    send the outdated cookie in further requests. With external
    security authentication, this can lead to misinterpretation of
    a session timeout scenario so that portal session suspend and
    resume is not triggered during login.
    

Local fix

  • NA
    

Problem summary

  • The JSESSIONID cookie is to be revoked upon logout, but the
    cookie modification code does not always set the correct cookie
    path. In this case browsers will ignore the cookie change and
    send the outdated cookie in further requests. With external
    security authentication, this can lead to misinterpretation of a
    session timeout scenario so that portal session suspend and
    resume is not triggered during login.
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    PM23579

  • Reported component name

    WEBSPHERE PORTA

  • Reported component ID

    5724E7600

  • Reported release

    61C

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2010-10-01

  • Closed date

    2010-10-20

  • Last modified date

    2010-10-20

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE PORTA

  • Fixed component ID

    5724E7600

Applicable component levels

  • R615 PSY

       UP

  • R61C PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSHRKX","label":"WebSphere Portal"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.1.0.3","Line of Business":{"code":"LOB31","label":"WCE Watson Marketing and Commerce"}}]

Document Information

Modified date:
21 December 2021