XSS Vulnerabilities :: SmPwServices.fcc

Document ID : KB000050999
Last Modified Date : 14/02/2018
Show Technical Document Details


I am running Password Services, and when I am running Penetration Test, I discover that vulnerability has been found in the 'Change Password' form on the following parameters: SNENC, SMTOKEN, TARGET and USERNAME which compromise the security of the environment. How can I avoid this?


Set the following ACO parameters:


If you are using a .fcc file for logout then in the logoffuri paramteer you need to set SMQUERYDATA. For e.g. logoffuri should be something like:
and not /AAA/logout.fcc

Since SecureURLs is enabled, webagent will look for SMQUERYDATA in the url every time it process an .fcc file.