AEM Security vulnerability scan | Community
Skip to main content
Raja-Karuppsamy
Community Advisor
Community Advisor
September 21, 2021
Solved

AEM Security vulnerability scan

  • September 21, 2021
  • 2 replies
  • 2987 views

Hi All -  We are using OWASP ZAP open source tool to find the vulnerability in the websites and the result doesn't show the paths supposed to be blocked from dispatcher side [0]. When we were in AMS platform - Adobe CSE used to perform the security vulnerability scan on a monthly basis and shares the paths should be blocked from dispatcher like [0] if they find anything.

 

Can you please suggest a tool that tells what are all the paths supposed to be blocked from dispatcher side (to improve the security of the website)

 

[0]

/content.json
/content.1.json
/content.infinity.json
/content.xml
/content.1.xml
/content.feed.xml

 

Regards,

Raja

This post is no longer active and is closed to new replies. Need help? Start a new post to ask your question.
Best answer by Kishore_Kumar_

Hi @raja-karuppsamy ,

 

You can prepare the custom script like mentioned below and validate ,it none of the urls should return 200

 

https://hashimkhan.in/2018/03/13/tool-for-dispatcher-security/ 

2 replies

Kishore_Kumar_
Kishore_Kumar_Accepted solution
Level 9
September 21, 2021

Hi @raja-karuppsamy ,

 

You can prepare the custom script like mentioned below and validate ,it none of the urls should return 200

 

https://hashimkhan.in/2018/03/13/tool-for-dispatcher-security/ 

Raja-Karuppsamy
Community Advisor
Community Advisor
September 21, 2021

Thanks @kishore_kumar_ - we will check this.

manpreetk908
Level 4
September 21, 2021

Hi @raja-karuppsamy,

You can refer the Adobe documentation https://experienceleague.adobe.com/docs/experience-manager-dispatcher/using/configuring/dispatcher-configuration.html?lang=en#testing-dispatcher-security which lists the paths which should be blocked from dispatcher.

 

Hope it helps!

 

Regards,

Manpreet

 

Raja-Karuppsamy
Community Advisor
Community Advisor
September 21, 2021

Thanks for your response - we have already blocked all the paths mentioned in above mentioned Adobe document, but still we have to run the security scan every quarter to identify the vulnerabilities in AEM.