Announcement Banner

946one

updated

5 years ago

9

946one

10 Posts

0

3274

January 18th, 2022 05:00

iDRAC9 Information Disclosure vulnerability

Security scans of our systems have vulnerability findings for our iDRAC9's - Information Disclosure, HTTP headers:

The HTTP headers sent by the remote web server disclose information that can aid an attacker. This information discloses the server’s name, framework name and their versions which serves no purpose for users, and there is no need to disclose this. Sites/Servers should not disclose any information not needed for the site to be available and working.

Header on tcp port 80 http = Apache (302-https://x.x.x.x:443/ )

Header on tcp port 443 https = Apache ( 302-https://x.x.x.x/restgui/start.html )

How do we remove the Web Server (Apache) from the headers?