System Is Not Generating A Complex Bidder Temporary Password

(Doc ID 2285791.1)

Last updated on JULY 12, 2017

Applies to:

PeopleSoft Enterprise SCM Strategic Sourcing - Version 9.2 to 9.2 [Release 9]
Information in this document applies to any platform.


On : 9.2 version, Bidder Registration

Very easy to know the Bidder Temporary Password
When registering a new bidder system will generate a password that is like the bidder username, this is very easy to guess and it may cause a security issues, also system doesn't force the bidder to change the password after the first login.

The issue can be reproduced at will with the following steps:
1. Register as a new bidder.
2. System will generate password that is like the username.
3. login to system with this password.
4. System will not force user to change it.


Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms