Set guest user for soap requests [Updated in Security Center 1.3 and 2.0]

  • Release version: Yokohama
  • Updated January 30, 2025
  • 1 minute to read
  • Configure this property to control the level of access of unauthenticated SOAP requests.

    This property controls the level of access of unauthenticated SOAP requests. If it is not set to the recommended value of soap.guest, or is set to a user with limited privileges, then SOAP requests will execute on behalf of the user. If this property is blank, then it enables unauthenticated access to administrator or maintenance level operations which negates all security controls within the instance.

    More information

    Attribute Description
    Configuration name com.glide.soap.guest_user
    Configuration type System Properties (/sys_properties_list.do)
    Data type string
    Recommended value soap.guest
    Default value soap.guest
    Category Access control
    Security risk
    • Severity score: 8.1
    • CVSS score: High
    • Security risk details: Setting this property to blank enables unauthenticated access to administrator or maintenance level operations.
    Dependencies and prerequisites None