Uploaded image for project: 'New Features 2017'
  1. New Features 2017
  2. NF-3852

[Security] All Company - EE Login - Enroll Now - Request parameters values on Enroll Now page get altered and can be saved successfully.

    Details

    • Type: Bug
    • Status: In LB Testing
    • Priority: High
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: UI Refresh
    • Labels:
      None
    • Bug Type:
      Functional
    • Bug Severity:
      Critical
    • Level:
      Employee
    • Module:
      Platform - Security
    • Reported by:
      Harbinger
    • Item State:
      Development - On Hold
    • Issue Importance:
      Q2

      Description

      [Security] All Company - EE Login - Enroll Now - Request parameters values on Enroll Now page get altered and can be saved successfully.

      Environment : Azure
      Login : Employee
      Company : Beta Security Test
      Employee : Saba Abai / 164215 / Password1@
      Tool : ZAP

      Replication Steps:
      1. Login as Employee
      2. Start traversing employee self serve mode through OE/New Hire/Employee Dashboard -> Enroll Now
      3. Go to Enroll Now page
      4. Go to any plan which is already enrolled or enroll in new plan.
      5. Tamper the request parameters like Coverage Amount, Costs for enroll now action.
      6. Save the updated values.
      7. Verify the Confirmation Statement, Enrollment Summary, Enrollment reports

      Real life scenarios those are possible.
      1. Employee can increase the Coverage amount keeping the cost (Premium) same.
      2. Employee can increase Coverage amount and decrease cost (Premium).
      3. Employee can keep same Coverage amount for decreased cost (Premium).

      CC : Rakesh RoySamirBharti SatputeVijay SiddhaSatyaSachin HingoleHrishikesh DeshpandeGaurav SodaniNidhi Kaulshyam sharma

        Attachments

        1. EnrollNowTamper_CostChange.jpg
          209 kB
          Prasad Pise
        2. EE_EePlanEligibilityRpt.jpg
          210 kB
          Prasad Pise
        3. EnrollNowTamper_Before.jpg
          366 kB
          Prasad Pise
        4. EE_EnrollmentReport.jpg
          142 kB
          Prasad Pise
        5. EnrollNowTamper_After.jpg
          118 kB
          Prasad Pise
        6. EECoverageAndCost_Intercept.doc
          1.06 MB
          Prasad Pise
        7. Re-Open_EnrollNow.jpg
          279 kB
          Prasad Pise

          Issue Links

            Activity

            Hide
            rohan.khandave Rohan J Khandave (Inactive) added a comment -

            Please check after next azure deployment.

            Show
            rohan.khandave Rohan J Khandave (Inactive) added a comment - Please check after next azure deployment.
            Hide
            prasadp Prasad Pise (Inactive) added a comment -

            Hi Rohan J Khandave

            I have verified the fix on Azure environment. Although, it shows Forbidden Access for requests, I can still tamper the values successfully. Could you please reconfirm.

            PFA screenshot.

            Thanks
            -Prasad
            CC: Rakesh RoySamirVijayendra ShindeSachin HingoleHrishikesh Deshpande

            Show
            prasadp Prasad Pise (Inactive) added a comment - Hi Rohan J Khandave I have verified the fix on Azure environment. Although, it shows Forbidden Access for requests, I can still tamper the values successfully. Could you please reconfirm. PFA screenshot. Thanks -Prasad CC: Rakesh Roy Samir Vijayendra Shinde Sachin Hingole Hrishikesh Deshpande
            Hide
            rohan.khandave Rohan J Khandave (Inactive) added a comment -

            Can you please confirm with existing screens of enroll now in stage?

            Show
            rohan.khandave Rohan J Khandave (Inactive) added a comment - Can you please confirm with existing screens of enroll now in stage?
            Hide
            prasadp Prasad Pise (Inactive) added a comment -

            Hi Santosh Balid

            This issue exist on pre-prod environment. Could you please check.

            Show
            prasadp Prasad Pise (Inactive) added a comment - Hi Santosh Balid This issue exist on pre-prod environment. Could you please check.
            Hide
            santosh.balid Santosh Balid (Inactive) added a comment -

            Please plan it in future sprints.

            Cc : Satya, Jaideep Vinchurkar, Bharti Satpute

            Show
            santosh.balid Santosh Balid (Inactive) added a comment - Please plan it in future sprints. Cc : Satya , Jaideep Vinchurkar , Bharti Satpute

              People

              Assignee:
              gaurav.sodani Gaurav Sodani (Inactive)
              Reporter:
              prasadp Prasad Pise (Inactive)
              Developer:
              Rohan J Khandave (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Dates

                Created:
                Updated:
                Code Review Date:

                  Time Tracking

                  Estimated:
                  Original Estimate - 24h
                  24h
                  Remaining:
                  Time Spent - 13.5h Remaining Estimate - 10.5h
                  10.5h
                  Logged:
                  Time Spent - 13.5h Remaining Estimate - 10.5h
                  13.5h