PeopleTools and Lifecycle Management - PSFT (MOSC)

MOSC Banner

pspc servlet clickjacking

edited Apr 30, 2020 5:09AM in PeopleTools and Lifecycle Management - PSFT (MOSC) 2 commentsAnswered

Hi Team,

Recently we have upgraded to 9.2 with 8.57.09 CS , customer found pspc servlet vulnerability  for clickjacking.

We have disabled the pspc servlet, we are getting 404 response but customer audit team wants no response from server.

Attached screenshot with pspc with and without disabling pspc and signin page with clickjacking enabled(No response from server).

Thanks

Manohar

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center