A suggestion, include custom error-page configuration, is rated as an important requirement, would be good to have an example included. Source: Seven Security (Mis)Configurations in Java web.xml Files https://software-security.sans.org/blog/2010/08/11/security-misconfigurations-java-webxml-files