We are failing trustwave's PCI compliance scan on the following issue
Apache HTTP Server prior to version 2.2.22 contains a vulnerability that could allow an attacker to discover HTTP-only cookies by making a request with an extremely long cookie header field. This could be performed by...