Check: SRG-APP-000296-AS-000201
Application Server SRG:
SRG-APP-000296-AS-000201
(in versions v3 r4 through v2 r2)
Title
The application server management interface must provide a logout capability for user-initiated communication session. (Cat II impact)
Discussion
If a user cannot explicitly end an application server management interface session, the session may remain open and be exploited by an attacker; this is referred to as a zombie session. The attacker will then have access to the application server management functions without going through the user authentication process. To prevent this type of attack, the application server management interface must close user sessions when defined events are met and provide a logout function for users to explicitly close the session and free resources that were in use by the user.
Check Content
Review application server documentation and configuration settings to determine if the application server management interface provides a logout capability. If the application server management interface does not provide a logout capability, this is a finding.
Fix Text
Configure the application server management interface to provide a logout capability for the users.
Additional Identifiers
Rule ID: SV-204778r879674_rule
Vulnerability ID: V-204778
Group Title: SRG-APP-000296
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002363 |
The information system provides a logout capability for user-initiated communications sessions whenever authentication is used to gain access to organization-defined information resources. |
Controls
Number | Title |
---|---|
AC-12 (1) |
User-Initiated Logouts / Message Displays |