Previous Topic: When Multiple Parameters are Passed to arwfutil Utility, Only the First Parameter is UsedNext Topic: OTP Length at Issuance Different from What Was Defined in the Profile


Defects Fixed

This section contains the following topics:

OTP Length at Issuance Different from What Was Defined in the Profile

AM_7.1--Credential Management Screen Not Showing Credential Information

Compilation Errors with wf-common-interface.hpp on RHEL

EAP-TLS Authentication Allowed for Any Certificate/Key Pair

Deleted Users Not Handled in the AuthMinder Upgrade Tool

Memory Leak in AuthMinder Server While Creating Profile and Policy

Insufficient Privilege Errors on Some Administration Console Screens

Configuration Management Report Showed Operation ID After Upgrade

Authentication Failure When Authenticating LDAP Users

Two-Way SSL Trust Store Details Not Visible When Configuring the Protocol

Server Crashing When Authenticating Over RADIUS Protocol

Users with View Privilege Able to Enable or Disable Authentication Mechanism

Inconsistency in Authentication Error Messages

Server Crashing When Creating Key Configuration with Invalid Input

Some Administration Console Pages Vulnerable to CSS Attacks

JSESSIONID Disclosed in the URL

UDS Accessible through Axis2 Web Administration Console

Session IDs Not Generated After User Authentication

HTTPS Responses Cached

Same Token Used for Cross-Site Request Forgery and the Session ID for Login Session

Cross Frame Scripting Vulnerability