2.16 Disabling Access to the Tomcat Documents

In Windows Access Manager, the Tomcat documents are accessible on 8080/8443 ports without any authentication. This may result in vulnerability issues. This happens because the remote web server does not set a permissive Content-Security-Policy (CSP) response header in some responses. To fix this issue, go to C:\Program Files (x86)\Novell\Tomcat\webapps and remove the docs folder.

After deleting the docs folder, accessing Administration Console with /docs in the URL returns the HTTP 404 Not Found error.