Security vulnerability

Security vulnerability

We have a VO installation we have been testing and have been very pleased overall. However, one of the requirements by our organization is that the server be able to pass internal network scans for vulnerabilities (SANS.org). After our initial scan, the server came up as having the following vulnerability but I can't seem to figure out how or where in the configuration to address the issue:

Description:

The Apache HTTP Server could allow a remote attacker to obtain sensitive information. Apache HTTP Server uses a configuration directive called ServerToken to control what information the server discloses about itself in the HTTP header lines of the banner in a response to a query. The information disclosed includes the operating system and the software version numbers running on the server. The ServerToken has not been set, which could allow an attacker to examine the banner and obtain sensitive information, which the attacker could use to launch further attacks.

Platforms Affected:

* Apache Software Foundation: Apache HTTP Server Any version
* Data General: DG/UX Any version
* Hewlett-Packard Company: Tru64 UNIX Any version
* IBM: AIX Any version
* Linux: Linux Any version
* Microsoft Corporation: Windows 95
* Microsoft Corporation: Windows 98
* Microsoft Corporation: Windows 98 Second Edition
* Microsoft Corporation: Windows Me
* Microsoft Corporation: Windows XP
* Microsoft Corporation: Windows 2000 Any version
* Microsoft Corporation: Windows 2003 Any version
* Microsoft Corporation: Windows NT 4.0
* Santa Cruz Operation, Inc.: SCO Unix Any version
* SGI: IRIX Any version
* Sun Microsystems, Inc.: Solaris Any version
* Wind River Systems, Inc.: BSD Any version

Remedy:

Set the ServerToken to limit the amount of information disclosed in the HTTP header lines.

Consequences:

Obtain Information

References:

* Federal Office for Information Security Web site, S 4.194 Secure basic configuration of an Apache web server at http://www.bsi.bund.de/english/gshb/manual/s/s04194.html. (Refer to section on Information about the server)


Any suggestions?

Thanks,

Karl