Pen testing team found that the Identity Portal (14.4) application and/or its users are primarily vulnerable to: insecure direct object reference, and file upload functionality.
Please let me know how can I disable or remove the upload feature or functionality from the identity portal 14.4
/sigma/rest/protected/formServices/file/upload |
/sigma/rest/protected/campaigns/<campaignId>/task/<taskId>/attachment/upload |
/sigma/rest/protected/campaigns/<campaignId>/spreadsheet/upload |
Release : 14.4
Component : CA IDENTITY SUITE (VIRTUAL APPLIANCE)
New sigma.war file provided by L2 through DE508978.