Encrypt login ID and Password in cookies
Hello,
We are using PeopleSoft HRMS 9.0 , PeopleTools 8.49.11. Recently, our application was audited by an external client and they mentioned "Web vulnerability" in our application.
They said that that transmission of credentials from client to server is not encrypted. The user ID and password is passed in plain text to the cookies.
As per my understanding, peoplesoft does not encrypted the user name and password and people, the connect ID takes over.
Do you have any clue if we can encrypt the username and password before it is passed on to the cookies?
0