Check: VCEM-67-000030
VMware vSphere 6.7 EAM Tomcat STIG:
VCEM-67-000030
(in versions v1 r4 through v1 r1)
Title
ESX Agent Manager must disable the shutdown port. (Cat II impact)
Discussion
An attacker has at least two reasons to stop a web server. The first is to cause a denial of service, and the second is to put in place changes the attacker made to the web server configuration. If the Tomcat shutdown port feature is enabled, a shutdown signal can be sent to the ESX Agent Manager through this port. To ensure availability, the shutdown port must be disabled.
Check Content
At the command prompt, execute the following command: # grep 'base.shutdown.port' /etc/vmware-eam/catalina.properties Expected result: base.shutdown.port=-1 If the output of the command does not match the expected result, this is a finding.
Fix Text
Open /etc/vmware-eam/catalina.properties in a text editor. Add or modify the setting "base.shutdown.port=-1" in the "catalina.properties" file.
Additional Identifiers
Rule ID: SV-239401r879806_rule
Vulnerability ID: V-239401
Group Title: SRG-APP-000435-WSR-000147
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002385 |
The information system protects against or limits the effects of organization-defined types of denial of service attacks by employing organization-defined security safeguards. |
Controls
Number | Title |
---|---|
SC-5 |
Denial Of Service Protection |