How to disable HTTP TRACE in Red Hat Identity Management Server due risk of vulnerability in the trace method enabled?
Issue
IdM server was identified with the HTTP TRACE
method enabled. This method could be leveraged by malicious users to perform to debug web server connections.
Environment
- Red Hat Enterprise Linux
- 8.10
- 9.4
- Red Hat Identity Management (IdM)
- 4.9.13
- 4.11
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.