Security Issues With PeopleSoft Production Refreshes

Appsian05 Mar, 2021Security

The problem comes from the fact that the production environments were configured to trust each other for PeopleSoft Single Signon, but the node names and node passwords were not changed as part of the environment cloning logic. So when Fred signed on to the cloned Financials environment, the PS_TOKEN cookies generated are identical to what the production environment would generate (the details of PS_TOKEN cookie are documented in PeopleBooks, but the node name and node password are the important pieces here).

Recent Profiles

costume massage

Costume Massage

View Profile

13Win - Sân Chơi Giải Trí Uy Tín

13win - Sân Chơi Giải Trí Uy Tín

View Profile

sanford pharmacy

Sanford Pharmacy

View Profile

KWAI888

Kwai888

View Profile

Boyle Galloway

Boyle Galloway

View Profile

Thygesen Fry

Thygesen Fry

View Profile

Ok100

Ok100

View Profile

Nohunohu Com

Nohunohu Com

View Profile

Overgaard Valenzuela

Overgaard Valenzuela

View Profile

Bem88  Sân chơi game đổi thưởng

Bem88 Sân Chơi Game đổi Thưởng

View Profile