Discussions
Stay up-to-date with the latest news from NetSuite. You’ll be in the know about how to connect with peers and take your business to new heights at our virtual, in-person, on demand events, and much more.
Now is the time to ask your NetSuite-savvy friends and colleagues to join the NetSuite Support Community! Refer now! Click here to watch and learn more!
Security Flaw
Defect 251269 has been posted. I was wondering if anyone else has run into a security flaw in Netsuite when processing Merchant e- solutions transactions with cc.
It is an error 163. Basically, Netsuite error_code => 163
auth_response_text => HTTP GET is not allowed, use HTTP POST. Meaning the transactional information is posted in the URL. Meaning anyone with the motivation can snag the information from the URL.
I understand Merchant E made an update in order to continue towards a greater level of PCI security but it appears Netsuite has dropped the ball.
This has been going on for two weeks and it doesn't seem to be getting solved fast enough.
0