# Cis Tomcat8 V100 2.1

> Alter the Advertised server.info String

- Skill: `cyberstrikeus/cis-tomcat8-v100-2-1` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-tomcat8-v100-2-1`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-tomcat8-v100-2-1/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-tomcat8-v100-2-1

---


# 2.1 Alter the Advertised server.info String (Scored)

## Description

The `server.info` attribute contains the name of the application service. This value is presented to Tomcat clients when clients connect to the tomcat server.

## Rationale

Altering the `server.info` attribute may make it harder for attackers to determine which vulnerabilities affect the server platform.

## Audit Procedure

Perform the following to determine if the server.info value has been changed:

1. Extract the ServerInfo.properties file and examine the server.info attribute.

```bash
$ cd $CATALINA_HOME/lib
$ jar xf catalina.jar org/apache/catalina/util/ServerInfo.properties
$ grep server.info org/apache/catalina/util/ServerInfo.properties
```

## Remediation

Perform the following to alter the server platform string that gets displayed when clients connect to the tomcat server.

1. Extract the ServerInfo.properties file from the catalina.jar file:

```bash
$ cd $CATALINA_HOME/lib
$ jar xf catalina.jar org/apache/catalina/util/ServerInfo.properties
```

2. Navigate to the util directory that was created:

```bash
$ cd org/apache/catalina/util
```

3. Open ServerInfo.properties in an editor

4. Update the `server.info` attribute in the ServerInfo.properties file:

```
server.info=<SomeWebServer>
```

5. Update the catalina.jar with the modified ServerInfo.properties file:

```bash
$ jar uf catalina.jar org/apache/catalina/util/ServerInfo.properties
```

## Default Value

The default value for the server.info attribute is Apache Tomcat/.. For example, Apache Tomcat/7.0.

## References

1. http://www.owasp.org/index.php/Securing_tomcat

## CIS Controls

- Not mapped in this benchmark version

## Profile Applicability

- Level 2

