View Categories

SOAP Request Strict Security Should Be Enabled

Impact Area

Security

Severity

High

Affected Element

System property

Rule ID #

SN-0174

Impact #

Without appropriate authorization configured on the incoming SOAP requests, an unauthorized user can get access to sensitive content/data on the target instance.

Remediation #

Set the system property “glide.soap.strict_security” to true.

Time to fix

15 min

References #

This rule is linked to Common Weakness Enumeration CWE-862 Missing Authorization.

Powered by BetterDocs