Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-4676

[Security Test] {Critical Information Disclosure} Table Names, Column Names get displayed in proxy tool.

    Details

    • Type: Bug
    • Status: Open
    • Priority: High
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: None
    • Labels:
    • Environment:
      Production
    • Bug Severity:
      Low
    • Module:
      BenAdmin - Security
    • Reported by:
      Harbinger

      Description

      [Security Test]

      {Critical Information Disclosure}

      Table Name and Column Names get displayed in proxy tools.
      Test Environment : Production: VM-208..
      Tool used:
      Tamper Data - Mozilla Browser plugin

      1. Login as Admin
      2. Go to Add Employee
      3. Enter required fields in Add New employee page
      4. Go to Tamper Data
      5. Click on Start Tamper
      6. Go to Add Employee Page and click on Save button.
      7. Check for the Tamper Data POST form parameters.

      For more details check attached Screenshot.

      This issue is observed throughout the application.

        Attachments

          Activity

          prasadp Prasad Pise (Inactive) created issue -
          rakeshr Rakesh Roy (Inactive) made changes -
          Field Original Value New Value
          Module Parent values: BenAdmin(10100) Parent values: BenAdmin(10100)Level 1 values: Security(10112)
          prasadp Prasad Pise (Inactive) made changes -
          Severity Medium [ 13102 ]
          prasadp Prasad Pise (Inactive) made changes -
          Issue Category EBS [ 10350 ] Harbinger [ 10700 ]
          rakeshr Rakesh Roy (Inactive) made changes -
          Bug Severity Low [ 16703 ]
          satyap Satya made changes -
          Labels Security
          satyap Satya made changes -
          Environment_New Production [ 18442 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Link This issue relates to DEV-13718 [ DEV-13718 ]

            People

            Assignee:
            samir Samir
            Reporter:
            prasadp Prasad Pise (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Dates

              Created:
              Updated: