April 23, 2020
Estimated Post Reading Time ~

Disable WebDAV

Recommendation
  • WebDAV should be disabled in the publish environment. This can be done by stopping the appropriate OSGi bundles.
  • Connect to the Felix Management Console running on:
  • http://<host>:<port>/system/console
  • For example http://localhost:4503/system/console/bundles.
In the list of bundles, find the bundle named:
  1. Apache Sling Simple WebDAV Access to repositories (org.apache.sling.jcr.webdav)
  • Click the stop button (in the Actions column) to stop this bundle.
  • Again in the list of bundles, find the bundle named:
2. Apache Sling DavEx Access to repositories (org.apache.sling.jcr.davex)
Click the stop button to stop this bundle.

Note
A restart of AEM is not required.

WebDav related findings

Finding ID
JVM Name
Total risk
Effort to Fix
WD1
Stop Apache Sling Simple WebDAV
Critical
Low
WD2
Stop Apache Sling DavEx
Critical
Low


By aem4beginner

No comments:

Post a Comment

If you have any doubts or questions, please let us know.