Friday 22 May 2020

Must do - high security risk

If you see this in your logfiles:

6320/8992       Sat Mar  7 22:21:02.011000              secnodemgr.c674
        WARNING:Default Single Sign-on node configuration is being used. This is a potential security risk. Please refer to EnterpriseOne Security Administration Guide to setup Single Sign-on Node Configuration and Single Sign-on Token Lifetime Configuration.

Call me, I'll show you how I can log in as any user without a password.

Really, that is enough said!

1 comment:

Mohammad Messiah said...

I have seen similar logs. I am just curious to know how you can enter with any user?