Forum Discussion
Ranbir_183916
Nimbostratus
Jan 23, 2015Vulnerabilities "Server Information Disclosure" and "Missing Secure Attribute"
could somone suggest how to fix the below vulnerabilities.
"Server Information Disclosure" and "Missing Secure Attribute"
nathe
Cirrocumulus
Jan 23, 2015So, ASM will remove the Server header by default if it's enabled on the VIP.
If you haven't got ASM then irules will be your friend here. See the following links:
SOL11324: Setting the secure attribute for HTTP cookies
This will have an example on how you can loop through headers and remove any that you want.
Hope this helps,
N
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
