Security vulnerability scanners may flag JCS ports 22001 and 22002 for having the "HTTP OPTIONS Method Enabled." This article explains the security assessment of this configuration in alignment with OWASP recommendations (Test Method ID WSTG-CONF-06).
Identity Manager 14.5
OWASP recommends ensuring that only required HTTP methods are allowed and properly configured to prevent unauthorized access. The flag regarding JCS ports 22001 and 22002 has been investigated to determine if it poses a tangible security risk.
Engineering has assessed the ports and provided the following findings:
Based on this assessment, these ports do not present a security vulnerability in the context of the Identity Manager/Suite architecture.
To speak with a customer representative or a Support Engineer see . Scroll to the bottom of the page and click on your respective region.