Description
Exposing the Apache server-status page allows attackers to gather detailed information about the server’s current state, facilitating potential attacks by revealing active connections, server uptime, and resource usage.
Recommendation
To mitigate this risk, disable the server-status functionality in the Apache configuration file. Additionally, restrict access to the /server-status URL using appropriate access controls.
References
Could your website be exposed too?
SmartScanner can check your website for Apache server-status enabled and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Apache server-info enabled - Vulnerability
- Apache Version Disclosure - Vulnerability
- Server Version Disclosure - Vulnerability
- Tomcat Version Disclosure - Vulnerability


