Hi,
our CRM has been pen tested and one issue identified as a gap was "information disclosure".
The testers claimed, that the error messages returned to a user, e.g. if a user is missing privileges, contains to much information, like the stack trace a.s.o.
They said we should deactivate these kind of error messages.
Unfortunately I did not find any documentation, how to do that?
My idea would be to disable these kind of error messages, so that they are not displayed to the users and instead turn on tracing on server side on at least error level, where we then would have to look for such errors, if users are having issues.
Of course I would setup some maintenance plans to zip/archive/delete these logs in regular intervals.
Any feedback about that issue would be highly appreciated ;)
thx Thomas
btw: we are on 8.2.3 on prem