Peopletools and Spring Framework vulnerability
Our Company uses PT8.50 and PT 8.52 with "out of the box setup" functionality. We have to provide below questions to inforamtion security regarding "Spring Framework vulnerability".
1) Does the application utilize the Spring Framework? [please name each application]
2. 2)What version of the framework is the application using?
3. 3)How big is the app deployment?
4. 4)The article below indicates the problem is in the EL (Expression Language). If double resolution EL is turned off, the risk is mitigated. Does the application have that feature turned off? (note: version 3.0.5 or earlier cannot turn it off)
5. If the application is using double resolution EL, is it dependent on it? Can it be turned off? What would this entail?