Check: TOMCAT-000141-AS-000095
Apache Tomcat Application Server STIG - Xylok Custom:
TOMCAT-000141-AS-000095
(in version v1 r1.1)
Title
The Tomcat server must adhere to the principles of least functionality by providing only essential capabilities. (Cat II impact)
Discussion
Application servers provide a myriad of differing processes, features and functionalities. Some of these processes may be deemed to be unnecessary or too unsecure to run on a production DoD system. Application servers must provide the capability to disable or deactivate functionality and services that are deemed to be non-essential to the server mission or can adversely impact server performance, for example, disabling dynamic JSP reloading on production application servers as a best practice.
Check Content
Ask the SA, if there are any unnecessary modules installed in the Tomcat server. If any modules are present, but not documented, this is a finding.
Fix Text
Configure the application server to use only essential features and capabilities.
Additional Identifiers
Rule ID: SV-46521r3_rule
Vulnerability ID: V-35234
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000381 |
The organization configures the information system to provide only essential capabilities. |
Controls
Number | Title |
---|---|
CM-7 |
Least Functionality |