Enterprise Manager Generic (MOSC)

MOSC Banner

PCI Compliance - Vulnerability: Common Web Site Structure Directories

edited Feb 7, 2013 3:54AM in Enterprise Manager Generic (MOSC) 2 commentsAnswered
How do I fixed this from our scan.
This address is for the Admin Server for Cloud Control 12C 12.1.0.1

Vulnerability:  Common Web Site Structure Directories

               Risk:  Low

                URL's: https://hostname:7101/css/

                                   https://hostname:7101/images/

 

Impact:

 

Directory Enumeration vulnerabilities were discovered within your web application. Risks associated with an attacker discovering a directory on your application server depend upon what type of directory is discovered, and what types of files are contained within it. The primary threat, other than accessing files containing sensitive information, is that an attacker can utilize the information discovered in that directory to perform other types of attacks. Recommendations include restricting access to important directories or files by adopting a "need to know" requirement for both the document and server root, and turning off features such as Automatic Directory Listings that provide information that could be utilized by an attacker when formulating

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center