Uploaded image for project: 'New Features 2017'
  1. New Features 2017
  2. NF-2334

All Company- Employee Login - URL parameters - Security - URL parameters in all the SSM pages,reports are displayed in plain text.

    Details

    • Type: Bug
    • Status: Closed
    • Priority: High
    • Resolution: Bug Fixed
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: UI Refresh
    • Labels:
      None
    • Environment:
      Pre Production
    • Bug Type:
      Functional
    • Bug Severity:
      Medium
    • Level:
      Employee
    • Module:
      BenAdmin - Security
    • Reported by:
      Harbinger
    • Company:
      All Clients/Multiple Clients
    • Item State:
      Stage QA - Production Deployment on Hold
    • Issue Importance:
      Q2

      Description

      All Company- Employee Login - URL parameters - Security - URL parameter values in all the SSM pages,reports are displayed in plain text.

      As observed all the URL parameter values are displayed in plain english text and can be vulnerable for security breach.

      This can be generic issue and may exist for Admin,Partners,SA user roles too.

      CC : Vijayendra ShindeSachin HingoleRakesh RoyHrishikesh DeshpandeRohan J KhandaveSamir

        Attachments

        1. CCSF_URLData_notEncrypted.jpg
          CCSF_URLData_notEncrypted.jpg
          222 kB
        2. ParameterURL.jpg
          ParameterURL.jpg
          180 kB
        3. EmpBen.jpg
          EmpBen.jpg
          99 kB

          Issue Links

            Activity

            pratap.patil Pratap Patil (Inactive) logged work - 19/Feb/18 12:37 PM
            • Time Spent:
              5h
               

              Analysis, Code Correction and unit testing , impact testing .

            prasadp Prasad Pise (Inactive) logged work - 21/Feb/18 02:16 PM
            • Time Spent:
              2h
               

              Codemap Verification
              Internal Discussion

            prasadp Prasad Pise (Inactive) logged work - 22/Feb/18 01:31 PM
            • Time Spent:
              1h
               

              ReTest
              Internal Discussion

            prasadp Prasad Pise (Inactive) logged work - 23/Feb/18 12:54 PM
            • Time Spent:
              0.5h
               

              Internal Discussion
              URL repro

            komal.barde Komal Barde (Inactive) logged work - 23/Feb/18 05:22 PM
            • Time Spent:
              7h
               

              Analysis
              Code Correction
              Unit testing
              Discussion with Pratap and Prasad for issue repro

            komal.barde Komal Barde (Inactive) logged work - 26/Feb/18 12:10 PM
            • Time Spent:
              2h
               
              • Unit testing
              • Attained code review
              • Code merge and commit
            prasadp Prasad Pise (Inactive) logged work - 27/Feb/18 01:53 PM
            • Time Spent:
              2h
               

              Verification, Internal Discusison
              Issue Repro on Codemap and Preprod

            komal.barde Komal Barde (Inactive) logged work - 27/Feb/18 04:57 PM
            • Time Spent:
              2h
               
              • Analysis
              • Code Correction
              • Unit testing
              • Discussion with Pratap and Prasad for issue repro
            prasadp Prasad Pise (Inactive) logged work - 28/Feb/18 12:12 PM
            • Time Spent:
              3h
               

              Internal Discussions
              Verification on Codemap and Preprod environment for Beneficiary Changes
              Employee Self Serve Mode verification for Codemap and PreProd

            prasadp Prasad Pise (Inactive) logged work - 20/Mar/18 12:28 PM
            • Time Spent:
              2h
               
              <No comment>

              People

              Assignee:
              prasadp Prasad Pise (Inactive)
              Reporter:
              prasadp Prasad Pise (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:

                  Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 26.5h
                  26.5h