PeopleTools and Lifecycle Management - PSFT (MOSC)

MOSC Banner

Peopletools and Spring Framework vulnerability

edited Jan 29, 2013 6:03AM in PeopleTools and Lifecycle Management - PSFT (MOSC) 2 commentsAnswered
Hi,

Our Company uses PT8.50 and PT 8.52 with "out of the box setup" functionality. We have to provide below questions to inforamtion security regarding "Spring Framework vulnerability".

1) Does the application utilize the Spring Framework? [please name each application]

2.       2)What version of the framework is the application using?

3.       3)How big is the app deployment?

4.       4)The article below indicates the problem is in the EL (Expression Language). If double resolution EL is turned off, the risk is mitigated. Does the application have that feature turned off?  (note: version 3.0.5 or earlier cannot turn it off)

5.       If the application is using double resolution EL, is it dependent on it? Can it be turned off? What would this entail?

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center