Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0010470
TypeCategorySeverityReproducibilityDate SubmittedLast Update
defect[Openbravo ERP] 00. Application dictionarycriticalalways2009-09-03 10:172009-09-05 00:00
ReporternetworkbView Statuspublic 
Assigned Toiciordia 
PriorityimmediateResolutionno change requiredFixed in Version
StatusclosedFix in branchFixed in SCM revision
ProjectionnoneETAnoneTarget Version
OSAnyDatabaseAnyJava version
OS VersionDatabase versionAnt version
Product Version2.50MP4SCM revision 
Review Assigned To
Web browser
ModulesCore
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0010470: The user System of the application should be removed

DescriptionThe user System of the application should be removed. All the applications
have a user System with password System that is not known for many Partners and clients, so generally this user is not removed when starting a project,
so if some one knows that this users exists, it is possible to access to the application as system administrator.
The Openbravo user is correct because is known and the partners used to change the password of this user.
Steps To Reproduce-Login with user System and password System
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]
related to defect 0010447 closedmarvintm User System shouldn't be able to login, but it currently has a password 

-  Notes
(0019469)
iciordia (manager)
2009-09-04 11:46

This is not a bug. The configuration manual (http://wiki.openbravo.com/wiki/ERP/2.50/Configuration_Manual/Getting_started#Change_default_passwords [^]) explains that defaults passwords should be modified as a first step in the process.

Additionaly, recently we did another fix (bug 10447) so user System is created by default without privilege to log in.

Ismael

- Issue History
Date Modified Username Field Change
2009-09-03 10:17 networkb New Issue
2009-09-03 10:17 networkb Assigned To => rafaroda
2009-09-04 11:43 iciordia Assigned To rafaroda => iciordia
2009-09-04 11:46 iciordia Status new => closed
2009-09-04 11:46 iciordia Note Added: 0019469
2009-09-04 11:46 iciordia Resolution open => no change required
2009-09-04 12:00 rafaroda Relationship added related to 0010447
2009-09-04 19:12 dmitry_mezentsev Relationship added blocks 0010399
2009-09-05 00:00 anonymous sf_bug_id 0 => 2851895


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker