How to Hide Apache Tomcat Version Number from Error Pages

When you call a page that does not  exist in the tomcat server, or when an existing page returns an error, the tomcat server will display the version number. This might be a security risk, especially if you are running an old Tomcat server that has some known exploits.

How to hide the version number from the error pages

1.Go to $CATALINA_HOME/lib, and create the org/apache/catalina/util directory

2.Under org/apache/catalina/util directory create ServerInfo.properties file

3.Now add below lines

server.info=XXX (What ever yo want)

4.Now restart tomcat server and on error page  it will show the value you have specified in ServerInfo.properties file .

 

Advertisements
This entry was posted in Tomcat. Bookmark the permalink.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s