We are getting a Medium vulnerability flagged against our SpectroSERVER system regarding "HTTP TRACE / TRACK Methods Allowed (11213)".
However, this is a SpectroSERVER only install on Linux.
Why is this vulnerability found on a SpectroSERVER only install on Linux?
Release : Any version installed on Linux
Component: SpectroSERVER
httpd running on the SpectroSERVER system
The SpectroSERVER does not use httpd so it is not required to be running on the SpectroSERVER.
httpd can be shutdown and prevented from running.
Please reference knowledge document "Does Spectrum on Linux require the httpd, httpd-tools and php OS packages be installed?" for more details.
The only time httpd is required is on the OneClick system if you have enabled ModSecurity. Reference "Enable ModSecurity Web Application Firewall" section of the documentation for more details.