Do not allow custom header status messages
Scanned 9/3/2026
Install to Claude Code
npx -y skills add CyberStrikeus/CyberStrike --skill cis-tomcat7-v100-10.9 --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Cis Tomcat7 V100 10.9?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/cyberstrikeus-cis-tomcat7-v100-10-9)More formats (shields.io, HTML) on the badges page.
---
name: cis-tomcat7-v100-10.9
description: "Do not allow custom header status messages"
category: cis-tomcat
version: "1.0.0"
author: cyberstrike-official
tags: [cis, tomcat, tomcat-7, http-headers]
cis_id: "10.9"
cis_benchmark: "CIS Apache Tomcat 7 Benchmark v1.0.0"
tech_stack: [tomcat, java]
cwe_ids: []
chains_with: []
prerequisites: []
severity_boost: {}
---
# CIS Apache Tomcat 7 - 10.9 Do not allow custom header status messages (Scored)
## Profile Applicability
- Level 2
## Description
Do not allow custom header status messages
## Rationale
See CIS Apache Tomcat 7 Benchmark v1.0.0 for detailed rationale.
## Audit Procedure
Refer to CIS Apache Tomcat 7 Benchmark v1.0.0 Section 10.9 for audit commands.
## Remediation
Refer to CIS Apache Tomcat 7 Benchmark v1.0.0 Section 10.9 for remediation steps.
## References
- CIS Apache Tomcat 7 Benchmark v1.0.0
## Assessment Status
- **Scored**
- **Profile**: Level 2
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!