| name | cis-tomcat7-v100-2.4 |
| description | Disable X-Powered-By HTTP Header and Rename the Server Value for all Connectors |
| category | cis-tomcat |
| version | 1.0.0 |
| author | cyberstrike-official |
| tags | ["cis","tomcat","tomcat-7","information-disclosure"] |
| cis_id | 2.4 |
| cis_benchmark | CIS Apache Tomcat 7 Benchmark v1.0.0 |
| tech_stack | ["tomcat","java"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
CIS Apache Tomcat 7 - 2.4 Disable X-Powered-By HTTP Header and Rename the Server Value for all Connectors (Scored)
Profile Applicability
Description
Disable X-Powered-By HTTP Header and Rename the Server Value for all Connectors
Rationale
See CIS Apache Tomcat 7 Benchmark v1.0.0 for detailed rationale.
Audit Procedure
Refer to CIS Apache Tomcat 7 Benchmark v1.0.0 Section 2.4 for audit commands.
Remediation
Refer to CIS Apache Tomcat 7 Benchmark v1.0.0 Section 2.4 for remediation steps.
References
- CIS Apache Tomcat 7 Benchmark v1.0.0
Assessment Status