Link to home
Start Free TrialLog in
Avatar of Ricardo Elena
Ricardo ElenaFlag for United States of America

asked on

Jboss, fix these vulnerability, Web Server Internal IP Address/Internal Network Name Disclosure Vulnerability

Doing a Vulnerability scan on my JBoss server, I got these Vulnerability

Web Server Internal IP Address/Internal Network Name Disclosure Vulnerability

Some Web servers contain a vulnerability giving remote attackers the ability to attain your internal IP address or internal network name.
An attacker connected to a host on your network using HTTPS (typically on port 443) could craft a specially formed GET request from the Web server resulting in a 3XX Object Moved error message containing the internal IP address or internal network name of the Web server.
A target host using HTTP may also be vulnerable to this issue.

But I only find fix or patch information for IIS servers, need help to fix these on JBoss server
Avatar of mcnute
mcnute
Flag of Germany image

I guess what that means is, that, as apache does on error pages, discloses the os you're running the jboss server and what version the jboss server is. In apache httpd server you can disable the info which is given on error pages such as 404. Look for a similar configuration within your jboss installation and disable it.
ASKER CERTIFIED SOLUTION
Avatar of Ramakanta Sahoo
Ramakanta Sahoo
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial