Is it possible to disable "AutoComplete attribute for Password in Form Based Authentication" in CA PPM?

Document ID : KB000096308
Last Modified Date : 27/07/2018
Show Technical Document Details
Question:
Is it possible to disable "AutoComplete attribute for Password in Form Based Authentication" in CA PPM?
Answer:
The CA PPM solution, like other web based applications, put the following code in ALL of our PPM forms: form autocomplete="off". However, modern browsers are overriding this feature and ignoring the html code - https://www.owasp.org/index.php/Testing_for_Vulnerable_Remember_Password_(OTG-AUTHN-005) . Unfortunately this is a well vetted out vulnerability but because browsers are ignoring the code, unfortunately Clarity is not the root cause of this vulnerability.