Microsoft-IIS 10.0
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035496b2b5267c797a98f3c61537274b016c2f67c6b76
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /api/insight/contactsupplierlink/{contactSupplierLinkId}
GET /api/depot/checkstorenumber/{storeId}
GET /api/insight/contactpeople/{contactPeopleId}
GET /api/insight/contactpeople/{contactPeopleId}/contactsupplierlink
GET /api/insight/country
GET /api/insight/county
GET /api/insight/supplier/{vendorId}/contactpeople
GET /api/insight/supplieraddress/{vendorId}
GET /api/product/getallsupplierupdates
GET /api/product/getsupplierdetailsbyid/{supplierId}
GET /api/product/getsupplierdetailsbysuppliernumber/{supplierNumber}
GET /api/product/getsupplierupdatesbyid/{supplierId}
GET /api/supplier/{supplierId}/contacts
POST /api/Api
POST /api/depot
POST /api/insight
POST /api/jobs
POST /api/jobs/edi/sendedifile
POST /api/jobs/general/applyretentionpolicy
POST /api/jobs/suppliercollaboration/clearoldarchive/{monthsRetained}
POST /api/jobs/suppliercollaboration/sendreport/{reportId}
POST /api/jobs/suppliercollaboration/updatenextrundates
POST /api/jobs/suppliercollaboration/updatesubscriptions
POST /api/jobs/suppliersync/processimport
POST /api/product
POST /api/sap
POST /api/sap/statusdeleted/{supplierId}
POST /api/sap/statussuspend/{supplierId}
POST /api/supplier
PUT /api/Api/transactioncomplete/{success}
PUT /api/depot/transactioncomplete/{success}
PUT /api/insight/contactpeople
PUT /api/insight/contactsupplierlink
PUT /api/insight/transactioncomplete/{success}
PUT /api/jobs/transactioncomplete/{success}
PUT /api/product/transactioncomplete/{success}
PUT /api/sap/transactioncomplete/{success}
PUT /api/supplier/transactioncomplete/{success}
Open service 2.20.142.40:443 · axiomdevsupplier.icelanddev.net
2026-01-22 22:54
HTTP/1.1 302 Moved Temporarily Content-Length: 0 Server: Microsoft-IIS/10.0 Location: https://axiomdevsupplier.icelanddev.net/Account/SignIn/?origin=%2F Request-Context: appId=cid-v1:3e4b92ac-e700-4435-9216-053d959a3200 X-Powered-By: ASP.NET Expires: Thu, 22 Jan 2026 22:54:14 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 22 Jan 2026 22:54:14 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=42 Server-Timing: origin; dur=31 Strict-Transport-Security: max-age=31536000 Content-Security-Policy: upgrade-insecure-requests Server-Timing: ak_p; desc="1769122454152_34901524_433397794_7348_14413_0_33_-";dur=1
Open service 2.20.142.40:443 · axiomdevsupplier.icelanddev.net
2026-01-09 21:17
HTTP/1.1 302 Moved Temporarily Content-Length: 0 Server: Microsoft-IIS/10.0 Location: https://axiomdevsupplier.icelanddev.net/Account/SignIn/?origin=%2F Request-Context: appId=cid-v1:3e4b92ac-e700-4435-9216-053d959a3200 X-Powered-By: ASP.NET Expires: Fri, 09 Jan 2026 21:18:01 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 09 Jan 2026 21:18:01 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=71 Server-Timing: origin; dur=99 Strict-Transport-Security: max-age=31536000 Content-Security-Policy: upgrade-insecure-requests Server-Timing: ak_p; desc="1767993480934_34901524_1563860189_16923_9356_164_173_-";dur=1
Open service 2.20.142.40:443 · axiomdevsupplier.icelanddev.net
2026-01-02 14:12
HTTP/1.1 302 Moved Temporarily Content-Length: 0 Server: Microsoft-IIS/10.0 Location: https://axiomdevsupplier.icelanddev.net/Account/SignIn/?origin=%2F Request-Context: appId=cid-v1:3e4b92ac-e700-4435-9216-053d959a3200 X-Powered-By: ASP.NET Expires: Fri, 02 Jan 2026 14:12:25 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 14:12:25 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=14 Server-Timing: origin; dur=29 Strict-Transport-Security: max-age=31536000 Content-Security-Policy: upgrade-insecure-requests Server-Timing: ak_p; desc="1767363145155_34901524_1080139192_4350_7159_99_136_-";dur=1
Open service 2.20.142.40:443 · axiomdevsupplier.icelanddev.net
2025-12-22 17:16
HTTP/1.1 302 Moved Temporarily Content-Length: 0 Server: Microsoft-IIS/10.0 Location: https://axiomdevsupplier.icelanddev.net/Account/SignIn/?origin=%2F Request-Context: appId=cid-v1:3e4b92ac-e700-4435-9216-053d959a3200 X-Powered-By: ASP.NET Expires: Mon, 22 Dec 2025 17:16:22 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 22 Dec 2025 17:16:22 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=210 Server-Timing: origin; dur=31 Strict-Transport-Security: max-age=31536000 Content-Security-Policy: upgrade-insecure-requests Server-Timing: ak_p; desc="1766423781902_34901540_231108621_24110_9245_0_39_-";dur=1