owasp.org advises remediation for JCS ports 22001 and 22002 about HTTP OPTIONS Method Enabled
search cancel

owasp.org advises remediation for JCS ports 22001 and 22002 about HTTP OPTIONS Method Enabled

book

Article ID: 266376

calendar_today

Updated On:

Products

CA Identity Suite CA Identity Manager CA Identity Governance

Issue/Introduction

JCS Ports 22001 and 22002 offers http OPTIONS Method as Enabled.
It's advised by owasp.org by Test Method ID WSTG-CONF-06 to ensure that only the required methods are allowed, and that the allowed methods are properly configured. Also advised to ensure that no workarounds are implemented to bypass security measures implemented by user-agents, frameworks, or web servers.

Environment

Release : 14.4, 14.4.1, 14.4.2

Resolution

Engineering responded that:

1. About port 22001, the OPTIONS method is an http method that you cannot access via http URL on port 22001. Also the machine is not exposed externally. We think this is not vulnerable.

2. About port 22002, have NO OPTIONS method exposed.