BigIP
tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 20.55.76.246:443 · qelevate-sup.deloitte.com
2026-01-23 15:31
HTTP/1.1 302 Found Content-Length: 0 Connection: close Date: Fri, 23 Jan 2026 15:31:23 GMT Location: https://login.microsoftonline.com/36da45f1-dd2c-4d1f-af13-5abe46b99921/oauth2/authorize?client_id=0ef7cdd7-bd37-4cfa-9e97-2c807a63d47a&redirect_uri=https%3A%2F%2Fqelevate-sup.deloitte.com%2Fsignin-oidc&response_type=id_token&scope=openid%20profile&response_mode=form_post&nonce=639047790833459188.MWY1ZmRlYmYtMDE2NC00YWViLWIzOWItMWEyZDlkMmIyNjZhNmViZmZiNzctYzU4Zi00NjA3LTkzMmYtNGZhMzY1MDIwYjY4&state=CfDJ8J2YfXEx8clPrwHjOUxsWvf8-YbFKijrQfSGqp7WaLH8rMm6nk8k_ZEQI_5QZn_IumvZORg-lpWPXg_u8F-U0jSHf2VlNjsKxmqgq-etG8aD189nN3HD0C6xKCZ3xEguZZzXTzCFzOXnhny6rmPLruo2i2Gm_6cejidvjtoobnsO-0GK5q4WNkWt_S-XssRuLRACbGE3EGphjJXSKrBzjAegzToWi0yWcZIsVKwFYAB2udA5WAHs8RqXEHUVTaMVSJL6eTGoTFRekWPc4f39eqBE9kACAPIyd4odZGVSo-U9lT1q_7hpmZUSsxPH6iUMdw&x-client-SKU=ID_NET8_0&x-client-ver=7.1.2.0 Set-Cookie: .AspNetCore.OpenIdConnect.Nonce.CfDJ8J2YfXEx8clPrwHjOUxsWveK9Puq4rcJJveDUTTesvWJjMK-pGkPC3r_wWfw7-awy2nk3OnIYni216VgP5qO696TQS8XOJ1kj4ymGoiYg5wVluyHej0hFa0qurVyjPb-kf8jr-wVjuubXz4sTAlsxF8_9G1gvBimJ_gHmeLRQyDWlJXoEKH7FZ2T1IGXNa-z6ma5XdTfnFsIFPGFpGpBfvva-i1p8_uv2Bty22TiMYxx5X2yUBxaK_fcdR13rzkE8FoMf7BUiEGH1MW7USrUEPU=N; expires=Fri, 23 Jan 2026 15:46:23 GMT; path=/signin-oidc; secure; samesite=none; httponly Set-Cookie: .AspNetCore.Correlation.bOzXeRvJdRYYJlfp9XffCALAmpJQRp_MhP634UvJ6HM=N; expires=Fri, 23 Jan 2026 15:46:23 GMT; path=/signin-oidc; secure; samesite=none; httponly Request-Context: appId=cid-v1:f91eec4b-7437-4814-a733-87333843b9a8 Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 20.55.76.246:80 · qelevate-sup.deloitte.com
2026-01-21 23:25
HTTP/1.0 302 Moved Temporarily Location: https://qelevate-sup.deloitte.com/ Server: BigIP Connection: close Content-Length: 0
Open service 20.55.76.246:443 · qelevate-sup.deloitte.com
2026-01-21 23:25
HTTP/1.1 302 Found Content-Length: 0 Connection: close Date: Wed, 21 Jan 2026 23:25:50 GMT Location: https://login.microsoftonline.com/36da45f1-dd2c-4d1f-af13-5abe46b99921/oauth2/authorize?client_id=0ef7cdd7-bd37-4cfa-9e97-2c807a63d47a&redirect_uri=https%3A%2F%2Fqelevate-sup.deloitte.com%2Fsignin-oidc&response_type=id_token&scope=openid%20profile&response_mode=form_post&nonce=639046347507721513.NTE5NjFkNDMtYmM4OC00ODc3LThlNmYtZjhkMTE5NGMxZGRhZTU3OTJhYTAtODViNi00MmUzLTkwMjEtZDU1NWIxM2U5YjM0&state=CfDJ8J2YfXEx8clPrwHjOUxsWvcRbcmajQGxJTAJlVyYs5gMYg0mv288QjgUUVQNpJDVEhNNsQ3NF2TWnNQXHeFF-76GSABB8fDoT9uq9a361XzoCiGaKfHKTm8Wt2yElAE-AvGKZL0IieRkiAgHfUNp69bTUCnQ-4TRjbLCP6w35RJBpkowhVw6eZ7DHumvbYBbjP2mRGYF_GPffn88lOCqmqN-Q9RWTfZN8bD0iYSMC6rs14dpaqn484F8K40ZJH0sdAvpHUaInaZlFLDzV51pz85o8esyY2ooZcCIcHA-TTVQ3nFc_T_KZuXAsyw9egWXCA&x-client-SKU=ID_NET8_0&x-client-ver=7.1.2.0 Set-Cookie: .AspNetCore.OpenIdConnect.Nonce.CfDJ8J2YfXEx8clPrwHjOUxsWvfctbzDwWt6ioHPiNQ9uGwZOtulCycbUWVXuw28bPjMBeZSxGfRXLJV7ULvNFb9LRuKuPnFtF5DkS5SB8z-G9wISObuAdnTkSCKLWFYHnZqMcWMVzHHbq-y_M3E66hxHNsuEuntwwx7bs-7WJRBqwk6TGSogbQ462ZhbacMc2d2W6RB3pyeO6GLCOLNTRjiK7rP3oORHU5TpkIip0go-CK4RbN1NipsJpr1YbL2IuPtjSk_EjBBCFZPpR2OWtpfSZQ=N; expires=Wed, 21 Jan 2026 23:40:50 GMT; path=/signin-oidc; secure; samesite=none; httponly Set-Cookie: .AspNetCore.Correlation.PyrSTWOGmehkcKHIqrHM_nDdXenQSwBoOBA-HzA_T88=N; expires=Wed, 21 Jan 2026 23:40:50 GMT; path=/signin-oidc; secure; samesite=none; httponly Request-Context: appId=cid-v1:f91eec4b-7437-4814-a733-87333843b9a8 Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 20.55.76.246:443 · qelevate-sup.deloitte.com
2026-01-10 02:10
HTTP/1.1 302 Found Content-Length: 0 Connection: close Date: Sat, 10 Jan 2026 02:10:45 GMT Location: https://login.microsoftonline.com/36da45f1-dd2c-4d1f-af13-5abe46b99921/oauth2/authorize?client_id=0ef7cdd7-bd37-4cfa-9e97-2c807a63d47a&redirect_uri=https%3A%2F%2Fqelevate-sup.deloitte.com%2Fsignin-oidc&response_type=id_token&scope=openid%20profile&response_mode=form_post&nonce=639036078456651647.ZGM4OTNhN2UtNTU5Mi00YzZjLTgyYzUtYmUyMjc3MWIxYTQ5YWEzYTA2NTQtODVkMS00OGI2LThhNmUtZDI2ZWJiMjAyZGNl&state=CfDJ8J2YfXEx8clPrwHjOUxsWvdig1rlhQQuV3OfyEJ2KOc5FIpcyGeG-1CxlQ_UobOkEQS88U9eAbEtdjMtYsDJ0y20JEVvEc5glPJpL9F-GK-FrPk5swnPofig8Wr_M26g8Cv_IglLF5c9sAR5EL9xt6wdRYTwZMShNXaGyvB11gvpWbI5q5wPSEf7pT4ynzum7HeuRK6kp0iAousvxFxPzSf6687SlcsiOzHd5DX5Cjr8GxLlRq7U3hsrV5a06X0bJiyTJxlALqnLxYHW4775jUVdXSGJ9qyn3eViBg38uoh-87JMVXWiTNmG_OI4IGmMWQ&x-client-SKU=ID_NET8_0&x-client-ver=7.1.2.0 Set-Cookie: .AspNetCore.OpenIdConnect.Nonce.CfDJ8J2YfXEx8clPrwHjOUxsWvcLdfIGqk2Egug4QBIE-WRAlvHsW5h-h46S3i8v9X6uR56SlrnVKCTTwktR9dpUPME9htJN3b47_7sTS941hm7_R5m0HRZQ4JLExEaV9VmogQyYNn01Mo0C5kpa7njvZupU3DD45nMp2x_wBfAVhMnuLGbuzXvuc5K4xaH1p1gXHKaQtxizscaPVP3BR2riiDmt59XUMEJ3LqcPAeBPRtZAZwlTb0W9idSlniljeoCjVr52rfx-oeK2eDvOZNVZeUk=N; expires=Sat, 10 Jan 2026 02:25:45 GMT; path=/signin-oidc; secure; samesite=none; httponly Set-Cookie: .AspNetCore.Correlation.DmBQRgoJcepWcr5l_kCM0m4KBzCFiskA_DbZeUsY5CQ=N; expires=Sat, 10 Jan 2026 02:25:45 GMT; path=/signin-oidc; secure; samesite=none; httponly Request-Context: appId=cid-v1:f91eec4b-7437-4814-a733-87333843b9a8 Strict-Transport-Security: max-age=31536000; includeSubDomains