Security Issues With PeopleSoft Production Refreshes

Appsian05 Mar, 2021Security

The problem comes from the fact that the production environments were configured to trust each other for PeopleSoft Single Signon, but the node names and node passwords were not changed as part of the environment cloning logic. So when Fred signed on to the cloned Financials environment, the PS_TOKEN cookies generated are identical to what the production environment would generate (the details of PS_TOKEN cookie are documented in PeopleBooks, but the node name and node password are the important pieces here).

Recent Profiles

ONEBRA

Onebra

View Profile

DR88 Nhà Cái

Dr88 Nhà Cái

View Profile

The Heart Of Tradition

The Heart Of Tradition

View Profile

Hi88 Soccer

Hi88 Soccer

View Profile

E2bet Social

E2bet Social

View Profile

Nhà cái VN88

Nhà Cái Vn88

View Profile

98Win bar

98win Bar

View Profile

Delson Deng

Delson Deng

View Profile