# Fetch web server misconfiguration summary details Provides a list of computers that have associated server misconfigurations (e.g., web server hardening issues). Supports filtering based on resource attributes. ## Endpoints GET `/dcapi/threats/servermisconfigurations` ## Request URL `https://`[*{serverurl}*](https://www.manageengine.com/products/desktop-central/help/api/cloud/oauth-authentication-endpoint-domain.html)`/dcapi/threats/servermisconfigurations` ## Scope `DesktopCentralCloud.VulnerabilityMgmt.READ` ## Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Query Parameters - **page** `string` *(Optional)*: Displays the content of the provided page number. - **customername** `string` *(Optional)* - **customerid** `long` *(Optional)* - **pageLimit** `string` *(Optional)*: Displays the provided number of server misconfigurations details per page. - **os_platform_name** `string` *(Optional)*: Filters web server misconfigurations based on the platform provided. - **severity** `string` *(Optional)*: Filters web server misconfigurations based on the severity provided. - **updated_time** `string` *(Optional)*: Filters web server misconfigurations based on the updated time provided. - **affected_systems** `string` *(Optional)* - **published_time** `string` *(Optional)*: Filters web server misconfigurations based on the published time provided. - **hardeningid** `string` *(Optional)*: Filters web server misconfigurations based on the hardening ID provided. - **description** `string` *(Optional)*: Filters web server misconfigurations that contain the provided hardening description. - **hardeningname** `string` *(Optional)*: Filters web server misconfigurations that contain the provided hardening name. - **category** `string` *(Optional)*: Filters web server misconfigurations based on the category provided. - **resolution** `string` *(Optional)*: Filters web server misconfigurations that contain the provided hardening resolution. ## Sample Request ```curl curl --request GET \ --url https://appdomains/dcapi/threats/servermisconfigurations \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' ``` ## Response Parameters ### HTTP Code 200 #### Response Body — application/json `JSON Object` ## Possible Response Codes - **200** `HTTP code` ## Sample Response: HTTP 200 ```json { "metadata": { "pageLimit": 30, "totalRecords": "2", "totalPages": 1, "links": { "next": null, "prev": null }, "page": 1 }, "response_code": 200, "message_type": "servermisconfigurations", "message_response": { "servermisconfigurations": [ { "os_platform_name": "Windows", "severity": "Moderate", "updated_time": "1540475593000", "affected_systems": 1, "published_time": "1540475595000", "hardeningid": "55", "description": "You can mitigate most of the common Cross Site Scripting attack using HttpOnly and Secure flag in a cookie. Without having HttpOnly and Secure, it is possible to steal or manipulate web application session and cookies and it s dangerous.", "hardeningname": "Set cookie with HttpOnly and Secure flag", "category": "Session hijacking", "resolution": "Check the HTTP header if the cookies contain HTTPOnly and Secure flag" }, { "os_platform_name": "Windows", "severity": "Info", "updated_time": "1540475593000", "affected_systems": 1, "published_time": "1540475595000", "hardeningid": "111", "description": "The default installation of Tomcat includes connectors with default settings. These are traditionally set up for convenience, but may lead to security exposure. If you're using an application bundled with this web server, contact the application vendor to obtain the details of necessary connectors, and remove the connectors that are unused", "hardeningname": "Verify TomCat XML for unused connectors", "category": "Default Contents", "resolution": "Remove or comment each unused Connector in $CATALINA_HOME/conf/server.xml." } ] }, "status": "success" } ``` ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.