Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  Unauthorized Method for Known URL Error

    Posted 05-21-2021 04:46
    Hi Guys!

    Recently I got multiple Alerts for a few urls, Unauthorized Method for Known URL (POST). Problem is POST is already a known method for theese URLs.

    The Violation pane says the violated method is POST, but it also says POST is among allowed methods.



    When I try to add it to the profile (again) with the plus sign button I got an error, saying "The method POST is already allowed for URL xyz".

    I tried deleting the urls, and add them again from scrach, but the problem persists

    SecureSphere X2510 - ver. 13.6.0.51_0 

    Please advise!

    Regards

    #On-PremisesWAF(formerlySecuresphere)

    ------------------------------
    Attila Pozsonyi
    administrator
    Hungarian State Treasury
    Budapesy
    ------------------------------


  • 2.  RE: Unauthorized Method for Known URL Error

    Posted 05-24-2021 10:13
    Hi Attila,

    If you access the profile directly under Main > Profile > Overview and navigate to the path defined in the alert, is there any learned SOAP? It should be on the right side of the window.



    Also, have any URL patterns been defined for this profile that match the path in the alert?



    Thanks.


  • 3.  RE: Unauthorized Method for Known URL Error

    Posted 05-27-2021 09:30
    Hi Jaired, 

    No, there isn't any learned SOAP, and there are no url patterns that match the urls mentioned above.


    ------------------------------
    Attila Pozsonyi
    administrator
    Hungarian State Treasury
    Budapesy
    ------------------------------