Unencrypted Password
It has been observed that the password is not encrypted at the application layer and it is found in clear text while browsing the application.
Hello Team,
I would suggest you open a ticket with support and attach the vulnerability scan report with detailed description of the issue.
Btw, may i have what have you selected for "SSL communication with database server:", under core/config page.
Was my reply helpful?
If you find this post useful, please give it a Kudos! Also, please don't forget to select "Accept as a Solution" if this reply resolves your query!
Try to use SSl - Just trying understand the nature will the password be get encrypted for ePO authentication?
For LDAP users i believe it will not be saved anywhere.
Yes I can open a SR for the same. Thanks
You would want to clarify exactly where you are seeing this when you open ticket, with screenshot also and epo server mer.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: