Hi Team,
I have tested my webMethods version 9.7 production server and found following vulnerable results.
Can someone please tell me how to DISABLE this parameter in WM # RC4 Yes WEAK (more info) ??
Protocol details
POODLE (SSLv3) Vulnerable INSECURE (more info) SSL 3: 0xa
POODLE (TLS) No (more info)
Downgrade attack prevention No, TLS_FALLBACK_SCSV not supported (more info)
SSL/TLS compression No
RC4 Yes WEAK (more info) → How to DISABLE this parameter ???
Heartbeat (extension) No
Cipher Suites (sorted by strength as the server has no preference; deprecated and SSL 2 suites at the end)
TLS_RSA_WITH_3DES_EDE_CBC_SHA (0xa) 112
TLS_RSA_WITH_RC4_128_MD5 (0x4) WEAK 128
TLS_RSA_WITH_RC4_128_SHA (0x5) WEAK 128
TLS_RSA_WITH_AES_128_CBC_SHA (0x2f) 128
#Integration-Server-and-ESB#webMethods#webmethods-Protocol-and-Transport