Discussions
Stay up-to-date with the latest news from NetSuite. You’ll be in the know about how to connect with peers and take your business to new heights at our virtual, in-person, on demand events, and much more.
Now is the time to ask your NetSuite-savvy friends and colleagues to join the NetSuite Support Community! Refer now! Click here to watch and learn more!
PCI Scan Alert - SSL 2.0 Vulnerability
Hello Everyone -
I've gone digging for an answer here, but couldn't find anything, so here goes:
I've had two different companies run a PCI Compliance scan (both on my own, non-NetSuite hosted site and the shopping cart) for me in the past week. Both are saying that shopping.netsuite.com is passing, but that checkout.netsuite.com has the following vulnerabilities:
1. Weak SSL ciphers
2. SSL 2.0
They offer a variety of 'solutions', but I thought I would throw the basics out here first to see if anyone else had ideas or a similar experience.
I can't tell if they are scanning the whole site, or whether the vulnerabilities they mention even pertain to customer information. Any ideas? Thanks in advance.
0