DX Unified Infrastructure Management

 View Only

SECURITY NOTICE: adminconsole messes up processes configuration

  • 1.  SECURITY NOTICE: adminconsole messes up processes configuration

    Posted Mar 16, 2016 07:31 AM

    BEWARE:

     

    If you use your browsers feature to remember your username/password for your adminconsole access, and you use adminconsole to edit the processes probe configuration, it will automatically populate empty user/password fields with your UIM credentials.

     

    When you save the configuration, these values are saved too (unless you clear them before saving).

     

    This causes two problems:

    1) a minor problem: the processes you are monitoring most likely should not be running with you as the owner, and hence it will trigger an alarm

    2) a major problem: your UIM credentials are now located on a robot.

     

    I have raised a ticket (00335972: Security/Bug: Processes probe wrong username and includes password) for this, but I thought that someone might like to know about this issue here...