WA00550 W22 - The TRACE method must be disabled.

Information

Use the Apache TraceEnable directive to disable the HTTP TRACE request method. Refer to the Apache documentation for more details http://httpd.apache.org/docs/2.2/mod/core.html#traceenable. The HTTP 1.1 protocol requires support for the TRACE request method which reflects the request back as a response and was intended for diagnostics purposes. The TRACE method is not needed and is easily subject to abuse and should be disabled.

Solution

Disable the TraceEnable directive by setting it to 'off'.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Apache_2-2_WIN_V1R13_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, Rule-ID|SV-33183r1_rule, STIG-ID|WA00550_W22, Vuln-ID|V-26325

Plugin: Windows

Control ID: ff8345c8ead3a86f1f6bed29b651dea6488ff7be4161450c88205450a57eeb12