Microsoft-IIS 10.0
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035496f9cb0f55bdc64c953683594b73524d97555eaea
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /api/v1/imodels/{imodelId}
DELETE /api/v1/imodels/{imodelId}/correlations/{correlationId}
GET /api/v1/imodels/{imodelId}/correlations
POST /api/v1/imodels/{imodelId}/documents/validate
PUT /api/v1/imodels/{imodelId}/documents
Open service 20.90.134.10:443 · qa-imodeldocumentcorrelation-uks.bentley.com
2026-01-23 03:17
HTTP/1.1 404 Not Found
Connection: close
Content-Type: application/problem+json
Date: Fri, 23 Jan 2026 03:18:14 GMT
Server: Microsoft-IIS/10.0
Transfer-Encoding: chunked
Request-Context: appId=cid-v1:1ce99cee-519a-4947-af38-29e77123a1e0
X-Powered-By: ASP.NET
{"type":"https://tools.ietf.org/html/rfc9110#section-15.5.5","title":"Not Found","status":404}
Open service 20.90.134.10:443 · qa-imodeldocumentcorrelation-uks.bentley.com
2026-01-12 14:42
HTTP/1.1 404 Not Found
Connection: close
Content-Type: application/problem+json
Date: Mon, 12 Jan 2026 14:43:47 GMT
Server: Microsoft-IIS/10.0
Transfer-Encoding: chunked
Request-Context: appId=cid-v1:1ce99cee-519a-4947-af38-29e77123a1e0
X-Powered-By: ASP.NET
{"type":"https://tools.ietf.org/html/rfc9110#section-15.5.5","title":"Not Found","status":404}
Open service 20.90.134.10:80 · qa-imodeldocumentcorrelation-uks.bentley.com
2026-01-12 14:42
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Mon, 12 Jan 2026 14:43:46 GMT Location: https://qa-imodeldocumentcorrelation-uks.bentley.com/