By default, Tomcat\'s error pages disclose both the existence of Tomcat and the exact version of the container that\'s handling the requests. This is nice for development, but
I agree with Jeremy Stein, that
You should put an
If you want to secure the server it's (evidently) not as simple as taking care of these error pages. This link has a list of things you need to do:
https://www.owasp.org/index.php/Securing_tomcat