Skip to main content

Hitachi ID Identity Manager web form input protection

The Hitachi ID Identity Manager web user portal is implemented using the standard common gateway interface (CGI) mechanism, available on all web servers. CGI programs are exclusively responsible for accepting user input and displaying web pages. As such, the CGI programs may be attacked so need to incorporate strong protections.

All Identity Manager CGI programs use a standard string library to validate all inputs and protect against buffer overflow, SQL injection, cross site scripting and similar attacks. This is done by checking maximum input lengths, filtering out special characters and HTML codes, checking for valid formatting and value ranges, etc.

Read More:

  • Multi-layered security architecture:
    Security is implemented as multiple layers, each of which acts to protect Identity Manager data and embedded entitlements.
  • Use of Encryption:
    Use of Encryption to protect sensitive user data in storage and transit.
  • Web Form Input Protection:
    Inputs to web forms in Identity Manager are automatically protected against bogus data, buffer overruns and more.
page top page top