Skip to content

The A10 Networks ADC, when used to load balance web applications, must strip HTTP response headers.

An XCCDF Rule

Description

Providing too much information in error messages risks compromising the data and security of the application and system. HTTP response headers can disclose vulnerabilities about a web server. This information can be used by an attacker. The A10 Networks ADC can filter response headers; this removes the web server’s identifying headers in outgoing responses (such as Server, X-Powered-By, and X-AspNet-Version).

ID
SV-237040r639567_rule
Version
AADC-AG-000062
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

If the device is used to load balance web servers, configure the device to strip HTTP response headers.

The following command configures a WAF template and includes the option to strip HTTP response headers:
slb template waf
filter-resp-hdrs