HTTP OPTIONS Method Vulnerability on JCS Ports 22001 and 22002 - Identity Manager
search cancel

HTTP OPTIONS Method Vulnerability on JCS Ports 22001 and 22002 - Identity Manager

book

Article ID: 266376

calendar_today

Updated On:

Products

CA Identity Suite CA Identity Manager

Issue/Introduction

Security vulnerability scanners may flag JCS ports 22001 and 22002 for having the "HTTP OPTIONS Method Enabled." This article explains the security assessment of this configuration in alignment with OWASP recommendations (Test Method ID WSTG-CONF-06).

Environment

Identity Manager 14.5

Resolution

OWASP recommends ensuring that only required HTTP methods are allowed and properly configured to prevent unauthorized access. The flag regarding JCS ports 22001 and 22002 has been investigated to determine if it poses a tangible security risk.

Engineering has assessed the ports and provided the following findings:

  1. Port 22001: The OPTIONS method is not accessible via HTTP URL. Additionally, the component is not exposed to external networks, rendering the vulnerability non-exploitable in a standard production deployment.
  2. Port 22002: The OPTIONS method is not exposed on this port.

Based on this assessment, these ports do not present a security vulnerability in the context of the Identity Manager/Suite architecture.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.