Please login or register to access secure site features.

Note: By continuing to use DevConnect Program Services you agree to our latest Registered Member Terms.

Sign in using DevConnect ID

Forgot password?

Trouble logging in?

Submit a ticket for Registration Support.

I have an SSO ID

sign in

Don't have a DevConnect or SSO ID ?

Create a DevConnect account or join the program.

register now
New DevConnect members must have forum permissions in order to post messages.
If the Reply and New Post buttons are not available to you, please request access using a General Support request ticket.
Forum Index » Avaya Orchestration Designer » Updated RuntimeConfig Admin App That Resolves CSRF and XSS Security Issues   XML
Author Message

Joined: 06/11/2013 14:29:24
Messages: 3881

If you have security concern with the CSRF and XSS attacks on the RuntimeConfig Admin app running on Tomcat, you should apply the updated version of the web app attached in this post. To apply, please follow the steps below:

1. Remove the existing Runtimeconfig app from the app server.
2. Re-redeploy runtimeconfig.war from this attachment.
 Filename runtimeconfig.war [Disk] Download
 Description No description given
 Filesize 4374 Kbytes
 Downloaded:  1417 time(s)

This message was edited 2 times. Last update was at 17/08/2018 23:33:46

Joined: 20/03/2018 12:10:40
Messages: 5

Hi Wilson,

Would you be so kind to provide the runtimeconfig fixed version for WebSphere? We are currently facing this problem. In case you need it here is our dev environment info:

JDK 1.8.0_172


Joined: 06/11/2013 14:29:24
Messages: 3881

We don't intend to provide a solution for Websphere. It is NOT feasible to do so. Websphere always has its own way of doing things. Keep in mind that this is just a regular application running on the platform. Customers should follow Websphere's guidelines or methods on how to security them.

Joined: 06/01/2014 10:52:49
Messages: 41

Hi Wilson,

We downloaded this version of the runtimeconfig, but we are still seeing bunch of vulnerabilities. Can you provide a more recent version that has the additional fixes? Below is the list of various issues.

Cross-Site Scripting: Reflected
Password Management: Insecure Submission
Cross-Site Scripting: DOM
Password Management: Password in HTML Form
Server-Side Request Forgery
Privacy Violation: Autocomplete
System Information Leak: External
Portability Flaw: Locale Dependent Comparison


This message was edited 1 time. Last update was at 01/12/2020 15:32:04

Go to: