
Attachment uploads are currently disabled. This is a temporary situation and will resume as normal in the coming days.
Solved!
Go to SolutioniDRAC9 Information Disclosure vulnerability
Security scans of our systems have vulnerability findings for our iDRAC9's - Information Disclosure, HTTP headers:
The HTTP headers sent by the remote web server disclose information that can aid an attacker. This information discloses the server’s name, framework name and their versions which serves no purpose for users, and there is no need to disclose this. Sites/Servers should not disclose any information not needed for the site to be available and working.
Header on tcp port 80 http = Apache (302-https://x.x.x.x:443/ )
Header on tcp port 443 https = Apache ( 302-https://x.x.x.x/restgui/start.html )
How do we remove the Web Server (Apache) from the headers?
Responses (0)
Solutions (0)
