Share via


PCI-DSS CVE-2000-0649 Web server internal IP Address/Internal Network name disclosure vulnerability

Question

Monday, February 24, 2020 3:47 AM

Hi,

Ho can we address the PCI-DSS CVE-2000-0649 "Web server internal IP Address/Internal Network name disclosure vulnerability" issue in exchange server 2016 ?

Thanks

All replies (3)

Tuesday, February 25, 2020 3:47 AM âś…Answered

Hi Saaralanka,

It seems Microsoft has not fixed this vulnerability in updates. Once an update that fixes this issue is released, I would inform you here.  

Some users have found their own solution, check if these help:

https://www.mail-archive.com/[email protected]/msg166246.html

https://community.spiceworks.com/topic/2115159-web-server-internal-ip-address-internal-network-name-disclosure-vulnerability

/zh-cn/archive/blogs/msdn/mike/removing-an-iis-servers-ip-address-from-http-responses

Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.

Regards,

Eric Yin

Please remember to mark the replies as answers if they helped. If you have feedback for TechNet Subscriber Support, contact [email protected].


Tuesday, March 3, 2020 1:28 AM

Hi, I'm here to confirm with you if your issue has been resolved. If the problem is successfully solved, you can share your solution and mark them or the helpful reply as answer, this will make answer searching in the forum easier and be beneficial to other community members as well.

Regards,

Eric Yin

Please remember to mark the replies as answers if they helped. If you have feedback for TechNet Subscriber Support, contact [email protected].


Friday, August 7, 2020 6:24 AM

Hi Eric,

Is there any update about on this ?

Regards,

Saara