Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549c764bef53d6e7daf6dcbf0ab207e220eae0b41d1
Public Swagger UI/API detected at path: /swagger/index.html - sample paths: DELETE /iProdData/DeleteCart DELETE /iProdData/DeleteSketch DELETE /iProdData/RemoveItemFromCart DELETE /iProdData/RemovePost GET /iProdData/CalcProductMaxQty GET /iProdData/DownloadFile GET /iProdData/Error GET /iProdData/GetBom GET /iProdData/GetBomBotItems GET /iProdData/GetCsvPresetting GET /iProdData/GetCurrencyInfo GET /iProdData/GetCustomerName GET /iProdData/GetDeclarationsForPhaseInstance GET /iProdData/GetDocument GET /iProdData/GetFileVersions GET /iProdData/GetIprodCustomerData GET /iProdData/GetIprodCustomerItemLabels GET /iProdData/GetIprodCustomerName GET /iProdData/GetIprodCustomerVat GET /iProdData/GetItem GET /iProdData/GetItemBySerialAndWarehouses GET /iProdData/GetMachine GET /iProdData/GetMachineGroup GET /iProdData/GetMachinePickingLists GET /iProdData/GetMachineReturnLists GET /iProdData/GetNextPhaseInstanceInfo GET /iProdData/GetNotifications GET /iProdData/GetOpenAlarms GET /iProdData/GetPartPrograms GET /iProdData/GetPhase GET /iProdData/GetPhaseInstance GET /iProdData/GetPhaseInstanceTrackingData GET /iProdData/GetPickingList GET /iProdData/GetPosMarketplaceProducts GET /iProdData/GetPosOrders GET /iProdData/GetPost GET /iProdData/GetPostsByPhase GET /iProdData/GetShoppingCartsByMachine GET /iProdData/GetShoppingCartsByUser GET /iProdData/GetSketchByPhaseInstance GET /iProdData/GetSketchesByWorkOrder GET /iProdData/GetSpares GET /iProdData/GetTenantInfo GET /iProdData/GetTimeZoneInfo GET /iProdData/GetTracesLocations GET /iProdData/GetTrackingData GET /iProdData/GetUnboundMachine GET /iProdData/GetUserBalance GET /iProdData/GetUserByNfcCardId GET /iProdData/GetUserTimeSheets GET /iProdData/GetWarehouseIdForDeclaration GET /iProdData/GetWarehouses GET /iProdData/GetWorkOrder GET /iProdData/PiCheckTools GET /iProdData/ProductionDeclareList POST /iProdData/AddItemToCart POST /iProdData/CheckSalesOrderOpen POST /iProdData/CloseOpenAlarms POST /iProdData/CompleteSalesOrder POST /iProdData/CreateCart POST /iProdData/CreatePickingList POST /iProdData/CreateReturnList POST /iProdData/DownloadFileApp POST /iProdData/GetLogoUrl POST /iProdData/GetTherapyData POST /iProdData/GetUser POST /iProdData/GetUserApp POST /iProdData/MakePosPayment POST /iProdData/MakeUserTransaction POST /iProdData/ProductionDeclare POST /iProdData/RemoveMachine POST /iProdData/SaveDocument POST /iProdData/SaveItem POST /iProdData/SaveMachine POST /iProdData/SavePost POST /iProdData/SaveTrackSketch POST /iProdData/SaveTrackingData POST /iProdData/SaveUser POST /iProdData/SendTherapyResults POST /iProdData/SetAndGetCoupledMachine POST /iProdData/SetTelemetryData POST /iProdData/StartSalesOrder POST /iProdData/UpdateJourney POST /iProdData/UpdatePhaseInstance POST /iProdData/UpdatePhaseInstanceQty POST /iProdData/UpdateProductionDetail POST /iProdData/UploadFile
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549c764bef53d6e7daf6dcbf0ab207e220e7f6161d9
Public Swagger UI/API detected at path: /swagger/index.html - sample paths: DELETE /iProdData/DeleteCart DELETE /iProdData/DeleteSketch DELETE /iProdData/RemoveItemFromCart DELETE /iProdData/RemovePost GET /iProdData/CalcProductMaxQty GET /iProdData/DownloadFile GET /iProdData/Error GET /iProdData/GetBom GET /iProdData/GetBomBotItems GET /iProdData/GetCsvPresetting GET /iProdData/GetCurrencyInfo GET /iProdData/GetCustomerName GET /iProdData/GetDeclarationsForPhaseInstance GET /iProdData/GetDocument GET /iProdData/GetFileVersions GET /iProdData/GetIprodCustomerData GET /iProdData/GetIprodCustomerItemLabels GET /iProdData/GetIprodCustomerName GET /iProdData/GetIprodCustomerVat GET /iProdData/GetItem GET /iProdData/GetItemBySerialAndWarehouses GET /iProdData/GetMachine GET /iProdData/GetMachineGroup GET /iProdData/GetMachinePickingLists GET /iProdData/GetMachineReturnLists GET /iProdData/GetNextPhaseInstanceInfo GET /iProdData/GetNotifications GET /iProdData/GetOpenAlarms GET /iProdData/GetPartPrograms GET /iProdData/GetPhase GET /iProdData/GetPhaseInstance GET /iProdData/GetPhaseInstanceTrackingData GET /iProdData/GetPickingList GET /iProdData/GetPosMarketplaceProducts GET /iProdData/GetPosOrders GET /iProdData/GetPost GET /iProdData/GetPostsByPhase GET /iProdData/GetShoppingCartsByMachine GET /iProdData/GetShoppingCartsByUser GET /iProdData/GetSketchByPhaseInstance GET /iProdData/GetSketchesByWorkOrder GET /iProdData/GetSpares GET /iProdData/GetTenantInfo GET /iProdData/GetTimeZoneInfo GET /iProdData/GetTracesLocations GET /iProdData/GetTrackingData GET /iProdData/GetUnboundMachine GET /iProdData/GetUserBalance GET /iProdData/GetUserByNfcCardId GET /iProdData/GetUserTimeSheets GET /iProdData/GetWarehouseIdForDeclaration GET /iProdData/GetWarehouses GET /iProdData/GetWorkOrder GET /iProdData/PiCheckTools GET /iProdData/ProductionDeclareList POST /iProdData/AddItemToCart POST /iProdData/CheckSalesOrderOpen POST /iProdData/CloseOpenAlarms POST /iProdData/CompleteSalesOrder POST /iProdData/CreateCart POST /iProdData/CreatePickingList POST /iProdData/CreateReturnList POST /iProdData/DownloadFileApp POST /iProdData/GetTherapyData POST /iProdData/GetUser POST /iProdData/GetUserApp POST /iProdData/MakePosPayment POST /iProdData/MakeUserTransaction POST /iProdData/ProductionDeclare POST /iProdData/RemoveMachine POST /iProdData/SaveDocument POST /iProdData/SaveItem POST /iProdData/SaveMachine POST /iProdData/SavePost POST /iProdData/SaveTrackSketch POST /iProdData/SaveTrackingData POST /iProdData/SaveUser POST /iProdData/SendTherapyResults POST /iProdData/SetAndGetCoupledMachine POST /iProdData/SetTelemetryData POST /iProdData/StartSalesOrder POST /iProdData/UpdateJourney POST /iProdData/UpdatePhaseInstance POST /iProdData/UpdatePhaseInstanceQty POST /iProdData/UpdateProductionDetail POST /iProdData/UploadFile
Open service 4.232.99.1:443 · devices.iprod.it
2026-01-10 02:33
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Sat, 10 Jan 2026 02:34:33 GMT Strict-Transport-Security: max-age=2592000 Request-Context: appId=cid-v1:8809c3f9-c8f3-4450-8aca-3ace4e5f6903
Open service 4.232.99.1:443 · devices.iprod.it
2026-01-02 22:57
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Fri, 02 Jan 2026 22:57:31 GMT Strict-Transport-Security: max-age=2592000 Request-Context: appId=cid-v1:8809c3f9-c8f3-4450-8aca-3ace4e5f6903
Open service 4.232.99.1:443 · devices.iprod.it
2025-12-23 08:25
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Tue, 23 Dec 2025 08:25:03 GMT Strict-Transport-Security: max-age=2592000 Request-Context: appId=cid-v1:8809c3f9-c8f3-4450-8aca-3ace4e5f6903
Open service 4.232.99.1:443 · devices.iprod.it
2025-12-21 06:54
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Sun, 21 Dec 2025 06:54:26 GMT Strict-Transport-Security: max-age=2592000 Request-Context: appId=cid-v1:8809c3f9-c8f3-4450-8aca-3ace4e5f6903
Open service 4.232.99.1:443 · devices.iprod.it
2025-12-19 01:35
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Fri, 19 Dec 2025 01:35:23 GMT Strict-Transport-Security: max-age=2592000 Request-Context: appId=cid-v1:8809c3f9-c8f3-4450-8aca-3ace4e5f6903