QuestionQ47

Security, accessibility, and troubleshooting

A business asks an AEM Forms Developer to orchestrate a business workflow that reads internal employee details and exposes those details as a service to external vendors. When an administrator moves the workflow service from QA to Staging, the Infra security team reports a vulnerability: the application can be invoked by a different service even though the Developer created only one REST endpoint service.

What is the solution to this issue?

Explanation

Activated AEM Forms services can automatically expose SOAP, EJB, and Remoting endpoints in addition to REST. Disabling every non-REST endpoint prevents invocation through those unintended service interfaces while retaining the required REST endpoint.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!