Vulnerability related to HTTP methods, TRACE and/or TRACK
search cancel

Vulnerability related to HTTP methods, TRACE and/or TRACK

book

Article ID: 258533

calendar_today

Updated On:

Products

CA Service Desk Manager

Issue/Introduction

We found the following vulnerability / security concern in Service Desk Manager (SDM). How can we address it?

The remote web server supports the TRACE and/or TRACK methods. TRACE and TRACK are HTTP methods that are used to debug web server connections. 

Environment

Release : 17.3

Resolution

The methods TRACK and TRACE can be disabled directly on the Tomcat web server.  The client is free to update the Tomcat configuration to suit their specific needs.

SDM does not use those methods and thus it will not have any effect on SDM.