Summary #

Netsparker identified a version disclosure (IBM Security Access Manager (WebSEAL)) in the target web server's HTTP response.

This information might help an attacker gain a greater understanding of the systems in use and potentially develop further attacks targeted at the specific version of IBM Security Access Manager (WebSEAL).

Impact #
An attacker might use the disclosed information to harvest specific security vulnerabilities for the version identified.
Remediation #
Configure your web server to prevent information leakage from the suppress-server-identity function of its HTTP response.
Classifications #
CAPEC-170; CWE-205; HIPAA-164.306(a), 164.308(a); ISO27001-A.18.1.3; WASC-13; OWASP 2013-A5; OWASP 2017-A6
Netsparker

Dead accurate, fast & easy-to-use Web Application Security Scanner

Get a demo