My Oracle Support Banner

The OAAM Admin Console Server Returned Too Detailed HTTP Status Message (Doc ID 960509.1)

Last updated on JANUARY 24, 2019

Applies to:

Oracle Adaptive Access Manager - Version and later
Information in this document applies to any platform.


How to configure the server for this? - In our latest battery of penetration tests on the ARM Admin Console, an attempted attack was made in which a TRACK request was issued with javascript.
The server that hosts the Admin Console returned a 501 status with detailed information about the server and the cause of the error. The server should return a more generic error to prevent persons will ill intent from getting details of the system.


To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!

In this Document

My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.