4.4.1 Ensure 'disableXPoweredBy' is set to 'true'

Information

The disableXPoweredBy setting can reveal the server's identity.

Preventing the Liberty server from advertising its presence in this manner will prevent malicious attackers from determining the server's identity and exploiting any security vulnerabilities.

Solution

Add the disableXPoweredBy attribute to webContainer element in ${server.config.dir}/configDropins/overrides/<any file name>.xml Set the disableXPoweredBy attributes value to true

<webContainer disableXPoweredBy="true" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: MEDIA PROTECTION

References: 800-53|MP-6, CSCv7|13.2

Plugin: Unix

Control ID: 6b214d23b09d72277c2b8366a4618a6cdb7b3e09f025e807ddcadd7c4858904e