Summary #

Netsparker identified a stack trace disclosure (Apache MyFaces) in the target web server's HTTP response.

Impact #

An attacker can obtain information such as:

  • Stack trace.
  • Information about the generated exception.

This information might help an attacker gain more information and potentially focus on the development of further attacks for the target system.

Remediation #
Apply the following configuration to your web.xml file to prevent information leakage by applying custom error pages.
<error-page>
        <error-code>500</error-code>
        <location>/server_error.html</location>
</error-page>
Classifications #
PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC-214, CWE-248, HIPAA-248, ISO27001-A.9.2.3, WASC-14, OWASP 2013-A5, OWASP 2017-A6
Vulnerability Index

Vulnerability Index

You can search and find all vulnerabilities

OR

Search Vulnerability

Netsparker

Dead accurate, fast & easy-to-use Web Application Security Scanner

GET A DEMO