Issues encountered during the security scan in our PeopleSoft ELM environment.
During the Security scan, below are the major security related issues encountered. We are PT8.54 and Weblogic 12C with Oracle HTTP 12C. Could anyone please help me how to get below informations
2)request does not contain an anti-CSRF token --
various URL identified - looks all delivered PeopleSoft
Ex:psc/elmeprd/EMPLOYEE/ELM/c/PORTAL_ADMIN_PORTAL_EDIT_FAV.gblAJAX/packaged application/systems
2) Jquery lib version 1.6.2 security issues
PeopleSoft upgrade
3)Strict Transport Sec config and not enforced to https only not http
WebAdmin change – Strict Transport Security header to https rule
4) Content scoped to parent domain –
WebAdmin change – PS_TOKENEXPIRE