PeopleTools and Lifecycle Management - PSFT (MOSC)

MOSC Banner

Issues encountered during the security scan in our PeopleSoft ELM environment.

During the Security scan, below are the major security related issues encountered. We are PT8.54 and Weblogic 12C with Oracle HTTP 12C. Could anyone please help me how to get below informations

2)request does not contain an anti-CSRF token -- 

various URL identified - looks all delivered PeopleSoft

Ex:psc/elmeprd/EMPLOYEE/ELM/c/PORTAL_ADMIN_PORTAL_EDIT_FAV.gblAJAX/packaged application/systems 

2) Jquery lib version 1.6.2 security issues

PeopleSoft upgrade

3)Strict Transport Sec config and not enforced to https only not http 

WebAdmin change – Strict Transport Security header to https rule

4) Content scoped to parent domain –

WebAdmin change – PS_TOKENEXPIRE

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center