Vulnerability library
Security checkMay 13, 2024

Server Version Disclosure

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

The Server header describes the server application that handled the request. Detailed information in this header can expose the server to attackers. Using the information in this header, attackers can find vulnerabilities easier, potentially leading to targeted attacks and unauthorized access.

Test for Server Version Disclosure Vulnerability with SmartScanner

Donwload FREE!

Recommendation

To mitigate this issue configure the web server to stop sending detailed information in the Server header.

Fix Server Version Disclosure in Apache

  1. Open the Apache configuration file (httpd.conf or apache2.conf) and add the following lines:
    ServerTokens Prod
    ServerSignature Off
    
  2. Restart the web server.

Fix Server Version Disclosure in Nginx

  1. Open the Nginx configuration file (nginx.conf) and add the following line to either http, server, or location sections:
    server_tokens off;
    
  2. Restart the web server.

Fix Server Version Disclosure in Tomcat

  1. Open the server.xml file.
  2. Find the Host section and add the following line immediately after it:

     <Valve className="org.apache.catalina.valves.ErrorReportValve" showReport="false" showServerInfo="false" />
    
  3. Save the file and restart the application.

References

Could your website be exposed too?

SmartScanner can check your website for Server Version Disclosure and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated May 13, 2024