Provides a list of computers that have associated server misconfigurations (e.g., web server hardening issues). Supports filtering based on resource attributes
get /dcapi/threats/servermisconfigurations
https://{server-hostname}:8383/dcapi/threats/servermisconfigurations
VulnerabilityMgmt.READCopied!
Authorization: d92d4xxxxxxxxxxxxx15f52
curl --request GET \
--url https://appdomain/dcapi/threats/servermisconfigurations \
--header 'Authorization: d92d4xxxxxxxxxxxxx15f52' {
"metadata": {
"pageLimit": 30,
"totalRecords": "2",
"totalPages": 1,
"links": {
"next": null,
"prev": null
},
"page": 1
},
"response_code": 200,
"message_type": "servermisconfigurations",
"message_response": {
"servermisconfigurations": [
{
"os_platform_name": "Windows",
"severity": "Moderate",
"updated_time": "1540475593000",
"affected_systems": 1,
"published_time": "1540475595000",
"hardeningid": "55",
"description": "You can mitigate most of the common Cross Site Scripting attack using HttpOnly and Secure flag in a cookie. Without having HttpOnly and Secure, it is possible to steal or manipulate web application session and cookies and it s dangerous.",
"hardeningname": "Set cookie with HttpOnly and Secure flag",
"category": "Session hijacking",
"resolution": "Check the HTTP header if the cookies contain HTTPOnly and Secure flag"
},
{
"os_platform_name": "Windows",
"severity": "Info",
"updated_time": "1540475593000",
"affected_systems": 1,
"published_time": "1540475595000",
"hardeningid": "111",
"description": "The default installation of Tomcat includes connectors with default settings. These are traditionally set up for convenience, but may lead to security exposure. If you're using an application bundled with this web server, contact the application vendor to obtain the details of necessary connectors, and remove the connectors that are unused",
"hardeningname": "Verify TomCat XML for unused connectors",
"category": "Default Contents",
"resolution": "Remove or comment each unused Connector in $CATALINA_HOME/conf/server.xml."
}
]
},
"status": "success"
}
![]()
Duration: 1 minute | Threshold: 30 | Lock period: 5 minutes
Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.