Spectrum server receiving a medium Tenable Security finding against HTTP TRACE / TRACK Methods Allowed (11213)
search cancel

Spectrum server receiving a medium Tenable Security finding against HTTP TRACE / TRACK Methods Allowed (11213)

book

Article ID: 260533

calendar_today

Updated On:

Products

CA Spectrum DX NetOps

Issue/Introduction

We are getting a Medium vulnerability flagged against our SpectroSERVER system regarding "HTTP TRACE / TRACK Methods Allowed (11213)".

However, this is a SpectroSERVER only install on Linux. 

Why is this vulnerability found on a SpectroSERVER only install on Linux?

Environment

Release : Any version installed on Linux
Component: SpectroSERVER

Cause

httpd running on the SpectroSERVER system

Resolution

The SpectroSERVER does not use httpd so it is not required to be running on the SpectroSERVER.

httpd can be shutdown and prevented from running.

Please reference knowledge document "Does Spectrum on Linux require the httpd, httpd-tools and php OS packages be installed?" for more details.

Additional Information

The only time httpd is required is on the OneClick system if you have enabled ModSecurity. Reference "Enable ModSecurity Web Application Firewall" section of the documentation for more details.