PeopleTools and Lifecycle Management - PSFT (MOSC)

MOSC Banner

Encrypt login ID and Password in cookies

edited Mar 28, 2013 2:51AM in PeopleTools and Lifecycle Management - PSFT (MOSC) 9 commentsAnswered
Hello,

We are using PeopleSoft HRMS 9.0 , PeopleTools 8.49.11. Recently, our application was audited by an external client and they mentioned "Web vulnerability" in our application.

They said that that transmission of credentials from client to server is not encrypted. The user ID and password is passed in plain text to the cookies.

As per my understanding, peoplesoft does not encrypted the user name and password and people, the connect ID takes over.

Do you have any clue if we can encrypt the username and password before it is passed on to the cookies?

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center