10036-2Server Leaks Version Information via "Server" HTTP Response Header Field

PUBLISHEDsecurity alertLow
Passive

Metadata

Alert ID:
10036-2
Risk:
Low
Type:
Passive

Summary

The web/application server is leaking version information via the “Server” HTTP response header. Access to such information may facilitate attackers identifying other vulnerabilities your web/application server is subject to.

Solution

Ensure that your web server, application server, load balancer, etc. is configured to suppress the "Server" header or provide generic details.

References