SAP Knowledge Base Article - Preview

3256619 - HTTP OPTIONS vulnerability in Enterprise Manager

Symptom

When executing the command curl -i -X OPTIONS on the Enterprise Manager host at port 8081 you receive the following output:

EMHOST:admuser > curl -i -X OPTIONS http://<EM_HOST>:8081
HTTP/1.1 200 OK
X-Content-Type-Options: nosniff
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'
X-XSS-Protection: 1; mode=block
X-FRAME-OPTIONS: SAMEORIGIN
Allow: GET,HEAD,POST,OPTIONS
Content-Length: 0


Read more...

Environment

Introscope Enterprise Manager 10.7 and lower

Product

SAP Solution Manager all versions

Keywords

HTTP OPTIONS,  HTTP OPTIONS vulnerability EM , HTTP OPTIONS vulnerability Introscope , KBA , XX-PART-WILY , Introscope by CA Technologies , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.