Summary #

Invicti identified a stack trace disclosure (Apache MyFaces) in the target web server's HTTP response.

Impact #

An attacker can obtain information such as:

  • Stack trace.
  • Information about the generated exception.

This information might help an attacker gain more information and potentially focus on the development of further attacks for the target system.

Remediation #
Apply the following configuration to your web.xml file to prevent information leakage by applying custom error pages.
Classifications #
PCI v3.1-6.5.5; PCI v3.2-6.5.5; CAPEC-214; CWE-248; HIPAA-164.306(a), 164.308(a); ISO27001-A.9.2.3; WASC-14; OWASP 2013-A5; OWASP 2017-A6
