How to Disable the HTTP OPTIONS in OneClick's Tomcat Server
search cancel

How to Disable the HTTP OPTIONS in OneClick's Tomcat Server


Article ID: 190976


Updated On:


CA Spectrum


The HTTP OPTIONSmethod is used to describe the communication options for the target resource. When enabled a client can send a request to the tomcat
 server asking for allowed methods. It is possible that this might be used for malicious intent to identify allowed methods to use in a potential attack.

This knowledge document  will explain how to disable the HTTP  OPTIONS method.


Release : 10.x

Component : Spectrum OneClick


The OPTIONS method can be disabled on the OneClick server by updating the web.xml file and adding the block below BEFORE
the </web-app> closing tag.

FILE:  $SPECROOT/tomcat/conf/web.xml 


- backup the existing web.xml
     cp -p $SPECROOT/tomcat/conf/web.xml  $SPECROOT/tomcat/conf/web.xml.backup

- edit $SPECROOT/tomcat/conf/web.xml (add below just before the closing </web-app> tag)

      <web-resource-name>restricted methods</web-resource-name>
      <auth-constraint />


- save changes
- restart OneClick tomcat

Tomcat should now block the OPTIONS method.