If your SystemOut.log is throwing the following warning message, it means that you will need to specific white and black list for your custom web application:
1 2 3 4 5 6 7 | < span class = "pun" >[</ span >< span class = "lit" >3</ span >< span class = "pun" >/</ span >< span class = "lit" >24</ span >< span class = "pun" >/</ span >< span class = "lit" >16</ span >< span class = "pln" > </ span >< span class = "lit" >12</ span >< span class = "pun" >:</ span >< span class = "lit" >18</ span >< span class = "pun" >:</ span >< span class = "lit" >17</ span >< span class = "pun" >:</ span >< span class = "lit" >143</ span >< span class = "pln" > SGT</ span >< span class = "pun" >]</ span >< span class = "pln" > </ span >< span class = "lit" >0000027f</ span >< span class = "pln" > </ span >< span class = "typ" >AbstractReque</ span >< span class = "pln" > W com</ span >< span class = "pun" >.</ span >< span class = "pln" >ibm</ span >< span class = "pun" >.</ span >< span class = "pln" >wps</ span >< span class = "pun" >.</ span >< span class = "pln" >resolver</ span >< span class = "pun" >.</ span >< span class = "pln" >resource</ span >< span class = "pun" >.</ span >< span class = "typ" >AbstractRequestDispatcherFactory</ span >< span class = "pln" > matchesWebAppDefault</ span >< span class = "pun" >(</ span >< span class = "pln" >aResource</ span >< span class = "pun" >)</ span >< span class = "pln" > </ span >< span class = "typ" >Servlet</ span >< span class = "pln" > context </ span >< span class = "pun" >[/</ span >< span class = "typ" >WebApp</ span >< span class = "pun" >]</ span >< span class = "pln" > does </ span >< span class = "kwd" >not</ span >< span class = "pln" > specify a blackwhite list </ span >< span class = "kwd" >when</ span >< span class = "pln" > accessing resource </ span >< span class = "pun" >[</ span >< span class = "pln" >themes</ span >< span class = "pun" >/</ span >< span class = "pln" >html</ span >< span class = "pun" >/</ span >< span class = "pln" >dynamicSpots</ span >< span class = "pun" >/</ span >< span class = "pln" >custom</ span >< span class = "pun" >/</ span >< span class = "pln" >header</ span >< span class = "pun" >.</ span >< span class = "pln" >jsp</ span >< span class = "pun" >],</ span >< span class = "pln" > falling back to the </ span >< span class = "kwd" >default</ span >< span class = "pln" > </ span >< span class = "pun" >[[</ span >< span class = "pln" >whitelist</ span >< span class = "pun" >(</ span >< span class = "kwd" >null</ span >< span class = "pun" >),</ span >< span class = "pln" > blacklist</ span >< span class = "pun" >(</ span >< span class = "pln" >WEB</ span >< span class = "pun" >-</ span >< span class = "pln" >INF</ span >< span class = "pun" >/.*)]].</ span >< span class = "pln" > </ span >< span class = "typ" >Applications</ span >< span class = "pln" > can define a custom list </ span >< span class = "kwd" >by</ span >< span class = "pln" > adding the keys </ span >< span class = "pun" >[</ span >< span class = "pln" >com</ span >< span class = "pun" >.</ span >< span class = "pln" >ibm</ span >< span class = "pun" >.</ span >< span class = "pln" >portal</ span >< span class = "pun" >.</ span >< span class = "pln" >resource</ span >< span class = "pun" >.</ span >< span class = "pln" >whitelist</ span >< span class = "pun" >]</ span >< span class = "pln" > </ span >< span class = "kwd" >and</ span >< span class = "pln" > </ span >< span class = "pun" >[</ span >< span class = "pln" >com</ span >< span class = "pun" >.</ span >< span class = "pln" >ibm</ span >< span class = "pun" >.</ span >< span class = "pln" >portal</ span >< span class = "pun" >.</ span >< span class = "pln" >resource</ span >< span class = "pun" >.</ span >< span class = "pln" >blacklist</ span >< span class = "pun" >]</ span >< span class = "pln" > to their web</ span >< span class = "pun" >.</ span >< span class = "pln" >xml deployment descriptor</ span >< span class = "pun" >.</ span >< span class = "pln" > </ span >< span class = "typ" >For</ span >< span class = "pln" > details see information </ span >< span class = "kwd" >for</ span >< span class = "pln" > APAR PI47714 related to CVE</ span >< span class = "pun" >-</ span >< span class = "lit" >2014</ span >< span class = "pun" >-</ span >< span class = "lit" >8912</ span >< span class = "pln" > </ span >< span class = "pun" >(</ span >< span class = "typ" >Security</ span >< span class = "pln" > bulletin</ span >< span class = "pun" >:</ span >< span class = "pln" > http</ span >< span class = "pun" >:</ span >< span class = "com" >//www.ibm.com/support/docview.wss?uid=swg21963226).</ span > |
Add the following parameters to your web.xml and redeployed your application:
http://mygeekjourney.com/websphere-portal/websphere-portal-specify-white-black-list-web-application/