Tomcat vulnerability reported after upgrading DLO to 9.8.3

book

Article ID: 100062394

calendar_today

Updated On:

Description

Error Message

A vulnerability is reported, for  “Non-Generic Error Page – Server Error Information Disclosure” 

Cause

This relates to Apache Tomcat versions being reported on Default web pages.

 

Resolution

To prevent the Apache Tomcat version information from being reported on web pages;

  • Locate the file server.xml (default path C:\Program Files\Veritas\Veritas DLO\Dedupe\Tomcat\conf ) and make a backup copy of that.
  • Edit the server.xml file.
  • Scroll down to the following line;

  • Below that, but before the next tag, Add the following line;

  • Save the amended server.xml file and restart the Mindtree StoreSmart Dedupe Server service.

NOTE: If BOI components are installed on the server, the same change will need to be done with the 'server.xml' file located in the  C:\Program Files\Veritas\Veritas DLO\IOServer\Tomcat\conf  folder.

 

Issue/Introduction

Apache Tomcat vulnerability is reported after upgrading Desktop and Laptop Option (DLO) to v9.8.3