QID 150844
QID 150844: Cross Site Tracing Found
Cross Site Tracking (XST) involves using XSS and TRACE or TRACK HTTP methods. TRACE allows the client to see what is being received at the other end of the request chain and use that data for testing or diagnostic information. Detection: WAS scan requests a header and expects the response header QTraceXsCheck, if this header is present then vulnerability will be reported.
XST could be used to steal user cookies through Cross Site Scripting.
Solution
Disable TRACE HTTP method.
Vendor References
CVEs related to QID 150844
Software Advisories
| Advisory ID | Software | Component | Link |
|---|