Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-12154

Security alerts reported during ZAP Spidering of the production application with partner login

    Details

    • Type: Bug
    • Status: Open
    • Priority: Medium
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: None
    • Labels:
      None
    • Environment:
      Production
    • Bug Type:
      Functional
    • Bug Severity:
      Medium
    • Module:
      Platform - Security
    • Reported by:
      Harbinger
    • Company:
      All Clients/Multiple Clients
    • Item State:
      Development - On Hold

      Description

      Scenario Traversed:

      • Login with partner credentials.
      • Select security testing company 'Beta testing 1'
      • Navigate to Search employee and select any test employee.
      • Navigate to Change employee password.
      • Change the password of selected employee.
      • Logout from the application.

      Attached is the penetration test report of spidering above mentioned workflow from OWASP ZAP.

      We have observed that the alerts under 'Low' category need to be addressed.

      Satya Can you please assign this ticket to concerned developer.

      Prasad Pise Samir Rakesh Roy

        Attachments

          Activity

          santosh.balid Santosh Balid (Inactive) logged work - 24/Nov/17 05:45 AM
          • Time Spent:
            1h
             

            analysis

          santosh.balid Santosh Balid (Inactive) logged work - 24/Nov/17 01:43 PM
          • Time Spent:
            2h
             

            Analysis

          santosh.balid Santosh Balid (Inactive) logged work - 29/Nov/17 12:10 PM
          • Time Spent:
            7h
             

            Analysis and Discussion

          santosh.balid Santosh Balid (Inactive) logged work - 30/Nov/17 08:50 AM
          • Time Spent:
            4h
             

            Analysis

          santosh.balid Santosh Balid (Inactive) logged work - 01/Dec/17 11:45 AM
          • Time Spent:
            4h
             
            <No comment>

            People

            Assignee:
            gaurav.sodani Gaurav Sodani (Inactive)
            Reporter:
            anirudha.joshi anirudha joshi (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Dates

              Created:
              Updated:

                Time Tracking

                Estimated:
                Original Estimate - 0h
                0h
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 18h
                18h