Version Disclosure (Liferay Portal)

Severity: Low
Summary#

Invicti identified a version disclosure (Liferay Portal) in the target web server's HTTP response.

This information can help an attacker gain a greater understanding of the systems in use and potentially develop further attacks targeted at the specific version of Liferay Portal.

Impact#
An attacker might use the disclosed information to harvest specific security vulnerabilities for the version identified.
Remediation#

Apply the following changes on your portal-ext.properties file to disable Liferay header version verbosity:

http.header.version.verbosity=Off
Invicti

Dead accurate, fast & easy-to-use Web Application Security Scanner

Get a demo