Highlighted
Established Member..
Established Member..
841 views

UCMDB Login Issue for Few Special Characters

Hi, 

 

We have UCMDB 10.20 Installed on Windows. we have integrated with LDAP and it is working fine. But for few Users, whose Login password contains Special Characters like "!#" etc., they are not able to login UCMDB Console. When we checked the error file. it says the Message. 

 

"WARN [qtp89109490-747] (Log4JLogger.java:449) - [SECURITY FAILURE Anonymous:null@unknown -> /ExampleApplication/IntrusionDetector] Invalid input: context=password, type(SafeString)=^[\p{L}\p{Digit},\\:/. _?&%=+-\[\]\(\)\|\"]*$, input=******** org.owasp.esapi.errors.ValidationException: password: Invalid input. Please conform to regex ^[\p{L}\p{Digit},\\:/. _?&%=+-\[\]\(\)\|\"]*$ with a maximum length of 1024" Is it something a Known Issue in UCMDB, which can be fixed? 

 

Regards Ashok

0 Likes
2 Replies
Highlighted
Visitor.

Re: UCMDB Login Issue for Few Special Characters

0 Likes
Highlighted
Micro Focus Contributor
Micro Focus Contributor

Re: UCMDB Login Issue for Few Special Characters

Hi,

 

This may be a bit late.

 

I had the same problem, and managed to fix it. So I am posting this just in case someone else encounters the same issue.

 

Basically, UCMDB does some validation on the user inputs (including password). So you'll need to edit "<UCMDB install dir>\deploy\ucmdb-ui\WEB-INF\conf\ESAPI_validation.properties" file, and edit the below line to add special characters used in the password as required:

 

Validator.SafeString=^[\\p{L}\\p{Digit},\\\\:/. _?&%!@#=+-\\[\\]\\(\\)\\|\\"]*$

 

Regards,

Mohamed

The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.