My Oracle Support Banner

Access Log Show /cas/v1/tickets Request that Includes the Username and Password in Plain Text (Doc ID 2799449.1)

Last updated on APRIL 03, 2023

Applies to:

Oracle WebCenter Sites - Version 11.1.1.8.0 and later
Information in this document applies to any platform.

Symptoms

Noticed in access log, there is /cas/v1/tickets request, that includes the username and password in plain text.
For example, in access log see:

This cas request is being made in order to use the WebCenter Sites REST api.

Cause

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Symptoms
Cause
Solution
References


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.