What if the version of Tomcat 4 server is leaked???

The company's project was scanned by the security company “HTTP Header information disclosure ”, How to modify ? Problem description In the... Returned by the server HTTP If there are server related component versions and other information in the header, it will play a certain role in the attacker's further intrusion

testing procedure HTTP Check whether the middleware detailed version information is returned in the response message header . image.png

Safety suggestion Hide or modify banner Information .

I changed it and there was no response image.png

Take the answer 1:

Hello! , modify server The field is different or empty . See the configuration document :


If it can't be changed or doesn't take effect , You can also use the front proxy layer nginx, Delete this header.

