PeopleTools and Lifecycle Management - PSFT (MOSC)

MOSC Banner

Error messages can be configured by the user (post authentication)

Hello,

I would like to ask if there is something like the parameter "Suppress SQL Error = 1 " into the file psappsrv.cfg to Enabling SQL Error Message Suppression, to not give detail information or not present the message "Invalid URL -unknown Content Type or not Content Type found in URL https://psalfauat/c2544/EMPLOYEE/ERP/YouWonAnIpad" when the end-user type an invalid URL (post authentication)

We have the vulnerability report: Error messages on the site can be controlled by the user. A message such as the following can cause a legitimate user to send his credentials to a malicious site.

So we would like to know if is possible to eliminated the detail massage when a not valid URL is typing by the end-user

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center