Hello, we have a security team that uses IBM AppScan (9.0.3.9) to scan our products for security vulnerabilities. It was recently discovered that our Jira Software instance (7.10.0) has five verb tampering issues (Authentication Bypass Using HTTP Verb Tampering). Has anyone run across this? If so, how did you address it? Or, possibly determine that it is a false positive?
The way they determine this is the tool accesses a page using a standard method (e.g. POST) and gets the response. Then the same page is requested using a bogus verb. The same result comes back in the response, so it assumes that the verb tampering was successful.
Details of one example from the error report:
URL: http://[DOMAIN]:8080/osd.jsp
Risk: It might be possible to escalate user privileges and gain administrative permissions over the web application. It is possible to gather sensitive information about the web application such as usernames, passwords, machine name and/or sensitive file locations
Method manipulated from: GET to: BOGUS
Reasoning: The test result seems to indicate a vulnerability because the Test Response is
identical to the Original Response, indicating that the verb tampering was able to
bypass the site authentication