SAP Knowledge Base Article - Public

3376592 - Possible Password Transmitted over Query String Vulnerability on the Talent Community URL - Recruiting Marketing

Symptom

The scan report for vulnerabilities is displaying "[Possible] Password Transmitted over Query String" for the Talent Community URL: https://jobs.company.com/talentcommunity/subscribe

Environment

SAP SuccessFactors Recruiting Marketing

Cause

This redirect to the Talent Community URL happens because there's a "TC Join" Menu option added to the Header in Career Site Builder.

Resolution

You can remove the "TC Join" Menu Option from Career Site Builder > Appearance > Styles > Header > Select the desired locale > Select the desired Brand > Menu tab.

Keywords

rmk vulnerability, talent community vulnerability, subscribe, rmk header, csb vulnerability , KBA , LOD-SF-RMK-SEC , Security & Vulnerabilities , Problem

Product

SAP SuccessFactors Recruiting all versions