...
once we install 2.4patch10, creating a new user in the sponsor portal shows "invalid input" once patch 10 is rolled back to patch 5 it works fine
a parenthesis '()' used in timezone/location
remove parenthesis
from support bundle, the exception points to an error with the regex expression which couldn't parse the timezone: com.cisco.cpm.admin.restui.websec.InsecurePattern:[expression2] pattern:\w(\(.*\)) action:Error value:Jerusalem | Israel Time(GMT+02:00) parameter name:location exclusionTag:SecureBaseUtil 2019-12-12 09:55:02,375 ERROR [https-jsse-nio-10.48.60.186-8553-exec-10][] cisco.ise.tomcat.xss.PortalXssCheckFilter -::::- com.cisco.cpm.admin.restui.websec.WebSecurityException 2019-12-12 10:24:50,129 ERROR [webSec-1][] cpm.admin.restui.websec.PatternBasedAnalyzer -::::- Value was found harmful by the pattern:com.cisco.cpm.admin.restui.websec.InsecurePattern:[expression2] pattern:\w(\(.*\)) action:Error value:Ekaterinburg | Ekaterinburg Time(GMT+05:00) parameter name:location exclusionTag:SecureBaseUtil 2019-12-12 10:24:50,130 ERROR [https-jsse-nio-10.48.60.186-8553-exec-8][] cisco.ise.tomcat.xss.PortalXssCheckFilter -::::- com.cisco.cpm.admin.restui.websec.WebSecurityException at com.cisco.cpm.admin.restui.websec.WebSecurityCheckerUtil.checkRequestSecurity(WebSecurityCheckerUtil.java:549) at com.cisco.ise.tomcat.xss.PortalXssCheckFilter.hasXSSContent(PortalXssCheckFilter.java:189) at com.cisco.ise.tomcat.xss.PortalXssCheckFilter.doFilter(PortalXssCheckFilter.java:135) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166) at com.cisco.ise.filters.JspFilter.doFilter(JspFilter.java:100) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166) at com.cisco.ise.tomcat.filters.ResponseHeadersFilter.doFilter(ResponseHeadersFilter.java:58) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166) at com.cisco.ise.tomcat.filters.FilterUTF8.doFilter(FilterUTF8.java:70) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193) at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166) at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:198) at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:96) at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:496) at org.apache.catalina.valves.RequestFilterValve.process(RequestFilterValve.java:348) at com.cisco.ise.tomcat.valves.PortalISERequestFilterValue.invoke(PortalISERequestFilterValue.java:38) at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:140) at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:81) at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:87) at org.apache.catalina.valves.MethodsValve.invoke(MethodsValve.java:52) at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:342) at org.apache.coyote.http11.Http11Processor.service(Http11Processor.java:803) at org.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:66) at org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:790) at org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1459) at org.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:49) at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)