• Anthony Fielding (Veracode)

    Hi @narayanayv (Community Member)​,

    The CWE-526 flaw found by the dynamic analysis scanner is due to the server returning HTTP response headers containing sensitive information such as the server name e.g. "Server: Apache". If you view the flaw in Flaw Details the "Request/Response" tab should clearly indicate where we identified the flaw. It is recommended to not expose this sensitive information.

     

    Kind regards,

    Anthony Fielding

    Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.