Check: SRG-APP-000133-AS-000093
Application Server SRG:
SRG-APP-000133-AS-000093
(in versions v3 r4 through v2 r2)
Title
The application server must be capable of reverting to the last known good configuration in the event of failed installations and upgrades. (Cat II impact)
Discussion
Any changes to the components of the application server can have significant effects on the overall security of the system. In order to ensure a prompt response to failed application installations and application server upgrades, the application server must provide an automated rollback capability that allows the system to be restored to a previous known good configuration state prior to the application installation or application server upgrade.
Check Content
Check the application server documentation and configuration to determine if the application server provides an automated rollback capability to a known good configuration in the event of a failed installation and upgrade. If the application server is not configured to meet this requirement, this is a finding.
Fix Text
Configure the application server to automatically rollback to a known good configuration in the event of failed application installations and application server upgrades.
Additional Identifiers
Rule ID: SV-204742r879586_rule
Vulnerability ID: V-204742
Group Title: SRG-APP-000133
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001190 |
The information system fails to an organization-defined known-state for organization-defined types of failures. |
CCI-001499 |
The organization limits privileges to change software resident within software libraries. |