I'm looking for a bit of feedback on WebDAV, in this case running on IIS7.5. I've had an IBM Rational AppScan report come to me with a medium severity finding as a result of DAV entries in the response headers.
I'm conscious WebDAV has had its issues in the past but Microsoft seems to feel improvements have been in IIS7.5 (info here and here). So the question is this: does WebDAV on IIS7.5 pose a risk sufficient to warrant action? Are there any precedents of it being exploited in IIS7.5 form?
Of course there's always the argument of "turn it off unless you need it", but a couple of logistical situations makes this a little more difficult in this scenario. I'm also conscious these vulnerability scans can tend to be a bit hit-and-miss and am happy to claim "false positive" if necessary.