The strike a vulnerability in Apache Jetspeed. Specifically the User Manager services allow for un-authorized access via the REST API. Any user is able to query the users directory to create and delete users without having to authenticate via the REST API. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021. Other reference:None