Security Issues With PeopleSoft Production Refreshes

Appsian05 Mar, 2021Security

The problem comes from the fact that the production environments were configured to trust each other for PeopleSoft Single Signon, but the node names and node passwords were not changed as part of the environment cloning logic. So when Fred signed on to the cloned Financials environment, the PS_TOKEN cookies generated are identical to what the production environment would generate (the details of PS_TOKEN cookie are documented in PeopleBooks, but the node name and node password are the important pieces here).

Recent Profiles

G28 t1com

G28 T1com

View Profile

Visita777

Visita777

View Profile

MILYON88

Milyon88

View Profile

Công ty cửa HTDoor House & Trust

Công Ty Cửa Htdoor House & Trust

View Profile

Kèo Bóng Đá

Kèo Bóng Đá

View Profile

13winnitcom

13winnitcom

View Profile

Tuphoria

Tuphoria

View Profile

678VIP

678vip

View Profile

shukan hospital

Shukan Hospital

View Profile