Skip to content

Apache Tomcat Application Server 9 Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000141-AS-000095

    Group
  • xpoweredBy attribute must be disabled.

    Individual connectors can be configured to display the Tomcat server info to clients. This information can be used to identify Tomcat versions which can be useful to attackers for identifying vulne...
    Rule Low Severity
  • SRG-APP-000141-AS-000095

    Group
  • SRG-APP-000141-AS-000095

    Group
  • Documentation must be removed.

    Tomcat provides documentation and other directories in the default installation which do not serve a production use. These files must be deleted.
    Rule Low Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules