Synopsis
The remote web server is affected by an information disclosure vulnerability.
Description
Requesting the URI '/status' gives information about the currently running instance of the remote web server (most likely Apache Tomcat). It also allows anybody to reset the current statistics. A remote attacker can use this information to mount further attacks.
Solution
Disable this feature if it is not being used. Otherwise, restrict access to it.
Plugin Details
File Name: tomcat_status.nasl
Supported Sensors: Nessus
Vulnerability Information
CPE: cpe:/a:apache:tomcat
Required KB Items: installed_sw/Apache Tomcat
Vulnerability Publication Date: 1/1/1999