Internal Netwok name Disclosure Vulnerability

Dear Support

According to external audits ,gave following vulnerability in our domino web server , its says following .

observation: An attacker connected to a host on your network using HTTPS (typically on port 443) could craft a specially formed GET request from the Web server resulting in a 3XX Object Moved error message containing the internal IP address or internal network name of the Web server

Recommendation :

Modify the Apache configuration file as Set “ServerName” to a proper FQDN.

Use module mod_rewrite to modify the 3xx error message returned by the server.

Please give instruction to avoid this

Regards

Dayantha

Subject: Contact IBM Lotus Support on-this…

Although it seems you may not have the Web Server of your Domino Server configured properly, I strongly suggest you engage IBM Lotus Support on this-one.