Details
Individual connectors can be configured to display the Tomcat server info to clients. This information can be used to identify Tomcat versions which can be useful to attackers for identifying vulnerable versions of Tomcat. Individual connectors must be checked for the xpoweredBy attribute to ensure they do not pass Tomcat server info to clients.
Solution
From the Tomcat server as a privileged user, edit the $CATALINA_BASE/conf/server.xml file.
Examine each
sudo systemctl restart tomcat
sudo systemctl daemon-reload
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Unix.
References
- 800-53|CM-7a.
- CAT|III
- CCI|CCI-000381
- Rule-ID|SV-222957r615938_rule
- STIG-ID|TCAT-AS-000550
- STIG-Legacy|SV-111439
- STIG-Legacy|V-102497
- Vuln-ID|V-222957