Looking for the vulnerability index of Invicti's legacy products?
Oracle PeopleSoft SSO weak secret key - Vulnerability Database

Oracle PeopleSoft SSO weak secret key

Description

PeopleSoft supports its own Single Sign-On technology based on the PS_TOKEN cookie. PS_TOKEN is signed with a PS node password. Your application is using a weak/known node password and Invicti managed to guess this password.

Remediation

Change the value of the Node Password to a long random string.

Related Vulnerabilities