How To Prevent Http Options From Being Displayed During A PCI Test (Doc ID 785764.1)

Last updated on NOVEMBER 04, 2016

Applies to:

Oracle HTTP Server - Version: 10.1.2.0.2 to 10.1.3.4.0 - Release: AS10gR2 to AS10gR3
Information in this document applies to any platform.

Goal

telnet servername.oracle.com 7777
Trying 1.1.2.3.4...
Connected to servername.oracle.com (1.1.2.3.4).
Escape character is '^]'.             ======> Now type in the following words
OPTIONS / HTTP/1.0


Hit Enter

HTTP/1.1 200 OK
Date: Thu, 12 Feb 2009 23:11:19 GMT
Server: Oracle-Application-Server-10g/10.1.3.1.0 Oracle-HTTP-Server
Content-Length: 0
Allow: GET, HEAD, OPTIONS, TRACE   =====> These options are displayed which fails PCI test
Connection: close






Solution

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms