Previous Topic: JSESSIONID Disclosed in the URLNext Topic: Session IDs Not Generated After User Authentication


UDS Accessible through Axis2 Web Administration Console

Symptom:

Users could earlier upload non-CA applications to UDS by using the Axis2 Web Administration Console.

Solution:

This issue has now been resolved. To prevent malicious access to UDS application, access to Web Administration Module of Axis2 that is shipped with UDS is disabled.