Forum Discussion
What is the reason HTTP Status 500 defined as an illegal http status in response in ASM?
HTTP 500 means one thing - your application has crashed. Leaking this to the Internet is really bad and it can be easily exploited by hackers. This is an OWASP Top 10 Vulnerability, which is especially dangerous if stack traces are shown, as the attacker can use the HTTP 500 error to pinpoint the location of the vulnerability in your application code.
This is a Medium risk level vulnerability, you can read more about it on OWASP Top 10 page here:
https://www.owasp.org/index.php/Top_10_2013-A5-Security_Misconfiguration
Information Leakage Threat:
http://projects.webappsec.org/w/page/13246936/Information%20Leakage
Hope this helps,
Sam
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
