Skip to content

Web server and/or operating system information must be protected.

An XCCDF Rule

Description

<VulnDiscussion>The web server response header of an HTTP response can contain several fields of information including the requested HTML page. The information included in this response can be web server type and version, operating system and version, and ports associated with the web server. This provides the malicious user valuable information without the use of extensive tools.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility>System Administrator</Responsibility><Responsibility>Web Administrator</Responsibility><IAControls></IAControls>

ID
SV-36672r1_rule
Severity
Low
Updated



Remediation - Manual Procedure

Edit the /usr/local/apache2/conf/httpd.conf file and ensure the directive is set to Prod.