My Oracle Support Banner

OAM Credential Visible Using a Web Scanning Tool (Doc ID 3069979.1)

Last updated on JANUARY 30, 2025

Applies to:

Oracle Access Manager - Version 12.2.1.4.0 to 12.2.1.4.241009 [Release 12c]
Information in this document applies to any platform.

Goal

During a security testing with Burp Suite's web security scanner tool, it is observe that the credentials being submitted to OAM server via /auth_cred_submit is visible, is this expected?
 

Solution

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Goal
Solution


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.