Security Issues With PeopleSoft Production Refreshes

Appsian05 Mar, 2021Security

The problem comes from the fact that the production environments were configured to trust each other for PeopleSoft Single Signon, but the node names and node passwords were not changed as part of the environment cloning logic. So when Fred signed on to the cloned Financials environment, the PS_TOKEN cookies generated are identical to what the production environment would generate (the details of PS_TOKEN cookie are documented in PeopleBooks, but the node name and node password are the important pieces here).

Recent Profiles

leseu com

Leseu Com

View Profile

Trang Socolive

Trang Socolive

View Profile

JAMIE BELLAMY ACUPUNCTURE

Jamie Bellamy Acupuncture

View Profile

Sv368

Sv368

View Profile

Kèo Nhà Cái

Kèo Nhà Cái

View Profile

ff333

Ff333

View Profile

Local News in Elgin

Local News In Elgin

View Profile