“exception-message” header reveals path to document root in 404 response.

2014-01-10 Thread August Kleimo
I'm failing a PCI compliance scan because my Tomcat Version 7.0.20 server is revealing the path to the document web root in an exception-message header when a missing page is requested. Does anyone know of way to get rid of this header from the response? Note: I'm running Railo 4.1.2 on top of

Re: “exception-message” header reveals path to document root in 404 response.

2014-01-10 Thread August Kleimo
Thanks, Perhaps it's coming from Railo then. I'll investigate down that path. On Fri, Jan 10, 2014 at 3:56 PM, Mark Eggers its_toas...@yahoo.com wrote: On 1/10/2014 3:28 PM, August Kleimo wrote: I'm failing a PCI compliance scan because my Tomcat Version 7.0.20 server is revealing the path

Re: exception-message header reveals path to document root in 404 response.

2014-01-10 Thread August Kleimo
, Jordan Michaels On 01/10/2014 04:02 PM, Caldarale, Charles R wrote: From: August Kleimo [mailto:aug...@kleimo.com] Subject: exception-message header reveals path to document root in 404 response. I'm failing a PCI compliance scan because my Tomcat Version 7.0.20 server is revealing the path