Uploaded image for project: 'New Features 2017'
  1. New Features 2017
  2. NF-3852

[Security] All Company - EE Login - Enroll Now - Request parameters values on Enroll Now page get altered and can be saved successfully.

    Details

    • Type: Bug
    • Status: In LB Testing
    • Priority: High
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: UI Refresh
    • Labels:
      None
    • Bug Type:
      Functional
    • Bug Severity:
      Critical
    • Level:
      Employee
    • Module:
      Platform - Security
    • Reported by:
      Harbinger
    • Item State:
      Development - On Hold
    • Issue Importance:
      Q2

      Description

      [Security] All Company - EE Login - Enroll Now - Request parameters values on Enroll Now page get altered and can be saved successfully.

      Environment : Azure
      Login : Employee
      Company : Beta Security Test
      Employee : Saba Abai / 164215 / Password1@
      Tool : ZAP

      Replication Steps:
      1. Login as Employee
      2. Start traversing employee self serve mode through OE/New Hire/Employee Dashboard -> Enroll Now
      3. Go to Enroll Now page
      4. Go to any plan which is already enrolled or enroll in new plan.
      5. Tamper the request parameters like Coverage Amount, Costs for enroll now action.
      6. Save the updated values.
      7. Verify the Confirmation Statement, Enrollment Summary, Enrollment reports

      Real life scenarios those are possible.
      1. Employee can increase the Coverage amount keeping the cost (Premium) same.
      2. Employee can increase Coverage amount and decrease cost (Premium).
      3. Employee can keep same Coverage amount for decreased cost (Premium).

      CC : Rakesh RoySamirBharti SatputeVijay SiddhaSatyaSachin HingoleHrishikesh DeshpandeGaurav SodaniNidhi Kaulshyam sharma

        Attachments

        1. EE_EePlanEligibilityRpt.jpg
          EE_EePlanEligibilityRpt.jpg
          210 kB
        2. EE_EnrollmentReport.jpg
          EE_EnrollmentReport.jpg
          142 kB
        3. EECoverageAndCost_Intercept.doc
          1.06 MB
        4. EnrollNowTamper_After.jpg
          EnrollNowTamper_After.jpg
          118 kB
        5. EnrollNowTamper_Before.jpg
          EnrollNowTamper_Before.jpg
          366 kB
        6. EnrollNowTamper_CostChange.jpg
          EnrollNowTamper_CostChange.jpg
          209 kB
        7. Re-Open_EnrollNow.jpg
          279 kB

          Issue Links

            Activity

            Hide
            rohan.khandave Rohan J Khandave (Inactive) added a comment -

            Please check after next azure deployment.

            Show
            rohan.khandave Rohan J Khandave (Inactive) added a comment - Please check after next azure deployment.
            Hide
            prasadp Prasad Pise (Inactive) added a comment -

            Hi Rohan J Khandave

            I have verified the fix on Azure environment. Although, it shows Forbidden Access for requests, I can still tamper the values successfully. Could you please reconfirm.

            PFA screenshot.

            Thanks
            -Prasad
            CC: Rakesh RoySamirVijayendra ShindeSachin HingoleHrishikesh Deshpande

            Show
            prasadp Prasad Pise (Inactive) added a comment - Hi Rohan J Khandave I have verified the fix on Azure environment. Although, it shows Forbidden Access for requests, I can still tamper the values successfully. Could you please reconfirm. PFA screenshot. Thanks -Prasad CC: Rakesh Roy Samir Vijayendra Shinde Sachin Hingole Hrishikesh Deshpande
            Hide
            rohan.khandave Rohan J Khandave (Inactive) added a comment -

            Can you please confirm with existing screens of enroll now in stage?

            Show
            rohan.khandave Rohan J Khandave (Inactive) added a comment - Can you please confirm with existing screens of enroll now in stage?
            Hide
            prasadp Prasad Pise (Inactive) added a comment -

            Hi Santosh Balid

            This issue exist on pre-prod environment. Could you please check.

            Show
            prasadp Prasad Pise (Inactive) added a comment - Hi Santosh Balid This issue exist on pre-prod environment. Could you please check.
            Hide
            santosh.balid Santosh Balid (Inactive) added a comment -

            Please plan it in future sprints.

            Cc : Satya, Jaideep Vinchurkar, Bharti Satpute

            Show
            santosh.balid Santosh Balid (Inactive) added a comment - Please plan it in future sprints. Cc : Satya , Jaideep Vinchurkar , Bharti Satpute

              People

              Assignee:
              gaurav.sodani Gaurav Sodani (Inactive)
              Reporter:
              prasadp Prasad Pise (Inactive)
              Developer:
              Rohan J Khandave (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Dates

                Created:
                Updated:
                Code Review Date:

                  Time Tracking

                  Estimated:
                  Original Estimate - 24h
                  24h
                  Remaining:
                  Time Spent - 13.5h Remaining Estimate - 10.5h
                  10.5h
                  Logged:
                  Time Spent - 13.5h Remaining Estimate - 10.5h
                  13.5h