Tomcat security warning default pages exposes version
search cancel

Tomcat security warning default pages exposes version

book

Article ID: 373359

calendar_today

Updated On:

Products

CA Automic Dollar Universe

Issue/Introduction

We have Dollar Universe Web console hosted on Tomcat and we received security warning stating that the default error page, default index page, example JSPs and/or example servlets are installed on the remote Apache
Tomcat server raises a threat where an attacker uncover information about the remote Tomcat

Environment

Component: Dollar Universe

Release: 6.x, 7.x

Resolution

The security warning raised is NOT related to Dollar Universe Product, rather related to Tomcat where you have deployed Dollar Universe Web Console.

As it's internal to Tomcat we don't have any visibility and can't make any recommendation. However, the most common practice is to create & use custom default page. Please refer Apache community/support for suggestions and implementation guidelines.