CTX473053 New
“Internal Server Error 43549” response from Gateway with malformed request “/epatype?Param”
Applicable Products : Citrix Gateway
Secuerity scanning report vulnerability on ADC: Web Server Misconfiguration – Server Error Message when http request url includes “/epatype?”. Report pointed that 500 error response from server make attacker knowing whether certain inputs trigger a server error can aid or inform an attacker of potential vulnerabilities. “/epatype” is a http request url during EPA scan, and 500 error is a general response from ADC when request url is incorrect which should not be considerated as a potential vulnerability.