Check: VCEM-67-000011
VMware vSphere 6.7 EAM Tomcat STIG:
VCEM-67-000011
(in versions v1 r4 through v1 r1)
Title
ESX Agent Manager must be configured to limit access to internal packages. (Cat II impact)
Discussion
The "package.access" entry in the "catalina.properties" file implements access control at the package level. When properly configured, a security exception will be reported if there is an errant or malicious webapp attempt to access the listed internal classes directly or if a new class is defined under the protected packages. The ESX Agent Manager comes preconfigured with the appropriate packages defined in "package.access", and this configuration must be maintained.
Check Content
At the command prompt, execute the following command: # grep "package.access" -A 5 /etc/vmware-eam/catalina.properties Expected result: package.access=\ sun.,\ org.apache.catalina.,\ org.apache.coyote.,\ org.apache.tomcat.,\ org.apache.jasper. If the output of the command does not match the expected result, this is a finding.
Fix Text
Navigate to and open: /etc/vmware-eam/catalina.properties Ensure that the "package.access" line is configured as follows: package.access=\ sun.,\ org.apache.catalina.,\ org.apache.coyote.,\ org.apache.tomcat.,\ org.apache.jasper.
Additional Identifiers
Rule ID: SV-239382r879587_rule
Vulnerability ID: V-239382
Group Title: SRG-APP-000141-WSR-000075
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000381 |
The organization configures the information system to provide only essential capabilities. |
Controls
Number | Title |
---|---|
CM-7 |
Least Functionality |