Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad0354946155b1752d3d21d2d4ae0f427c972dc43a0badb
Public Swagger UI/API detected at path: /swagger/index.html - sample paths: GET /ApprovalStatus GET /ServiceOrder GET /TeamsChat GET /api/Version POST /Login POST /ServiceOrder/StartGetServiceOrderListJob
Open service 2.16.204.95:443 · test.api.eapprove.us.abb.com
2026-01-09 11:09
HTTP/1.1 404 Not Found Content-Length: 0 Date: Fri, 09 Jan 2026 11:09:20 GMT Connection: close Alt-Svc: h3=":443"; ma=93600 Strict-Transport-Security: max-age=15768000 ; includeSubDomains ; preload
Open service 2.16.204.95:443 · test.api.eapprove.us.abb.com
2026-01-05 02:07
HTTP/1.1 404 Not Found Content-Length: 0 Date: Mon, 05 Jan 2026 02:07:55 GMT Connection: close Alt-Svc: h3=":443"; ma=93600 Strict-Transport-Security: max-age=15768000 ; includeSubDomains ; preload
Open service 2.16.204.80:443 · test.api.eapprove.us.abb.com
2026-01-05 02:07
HTTP/1.1 404 Not Found Content-Length: 0 Date: Mon, 05 Jan 2026 02:07:55 GMT Connection: close Alt-Svc: h3=":443"; ma=93600 Strict-Transport-Security: max-age=15768000 ; includeSubDomains ; preload
Open service 2.16.204.95:80 · test.api.eapprove.us.abb.com
2026-01-05 02:07
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://test.api.eapprove.us.abb.com/ Date: Mon, 05 Jan 2026 02:07:57 GMT Connection: close
Open service 2.16.204.80:80 · test.api.eapprove.us.abb.com
2026-01-05 02:07
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://test.api.eapprove.us.abb.com/ Date: Mon, 05 Jan 2026 02:07:57 GMT Connection: close
Open service 2.16.204.95:443 · test.api.eapprove.us.abb.com
2026-01-02 11:53
HTTP/1.1 404 Not Found Content-Length: 0 Date: Fri, 02 Jan 2026 11:53:35 GMT Connection: close Alt-Svc: h3=":443"; ma=93600 Strict-Transport-Security: max-age=15768000 ; includeSubDomains ; preload
Open service 2.16.204.95:443 · test.api.eapprove.us.abb.com
2025-12-22 20:04
HTTP/1.1 404 Not Found Content-Length: 0 Date: Mon, 22 Dec 2025 20:04:02 GMT Connection: close Alt-Svc: h3=":443"; ma=93600 Strict-Transport-Security: max-age=15768000 ; includeSubDomains ; preload
Open service 2.16.204.95:443 · test.api.eapprove.us.abb.com
2025-12-21 04:15
HTTP/1.1 404 Not Found Content-Length: 0 Date: Sun, 21 Dec 2025 04:15:17 GMT Connection: close Alt-Svc: h3=":443"; ma=93600 Strict-Transport-Security: max-age=15768000 ; includeSubDomains ; preload
Open service 2.16.204.95:443 · test.api.eapprove.us.abb.com
2025-12-19 04:36
HTTP/1.1 404 Not Found Content-Length: 0 Date: Fri, 19 Dec 2025 04:36:10 GMT Connection: close Alt-Svc: h3=":443"; ma=93600 Strict-Transport-Security: max-age=15768000 ; includeSubDomains ; preload