Strategy Web Services discloses system information through the
happyaxis.jsppage as reported by “CVE-2020-11450 - Disclosure of information on the Axis2 Happiness Page exposes JVM configuration, CPU architecture, installation folder and other sensitive information."
Access happyaxis.jsp inside the Strategy Web Services deployment, e.g.,
http://machinename:port/StrategyWS/happyaxis.jsp
Upgrade to Strategy Web Services 2019 or above to take advantage of the fix. Administrator user credentials will be required to access the
happyaxis.jsppage.
In order to provide a workaround for
happyaxis.jsppage, follow these steps in in the Strategy Web Services deployment folder:
welcome.jsp.
welcome.jspand delete the following HTML code:
<li><a href="happyaxis.jsp">Validate</a>the web service installation's configuration</li>
happyaxis.jspand
happyaxis.jsp.
happyaxis.jspfrom the Strategy Web Services deployment folder.