The security team has reported that jbossweb version label (JBossWeb/2.0.1.GA) has been disclosed on 500 error pages. This will have to be supressed somehow. Some forums suggest adding a server attribute in the server.xml located in the jboss-web.deployer folder. However this didnt help . Some forums suggest changing the ServerInfo properties file in jboss source code to have it changed. Another solution would be adding custom error pages. Adding custom error pages seem to be a better solution than changing the source code. Please share your expertise on the subject if you have any information.