UCF STIG Viewer Logo

VMware vSphere 7.0 vCenter Appliance Perfcharts Security Technical Implementation Guide


Overview

Date Finding Count (34)
2023-02-21 CAT I (High): 0 CAT II (Med): 34 CAT III (Low): 0
STIG Description
This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Available Profiles



Findings (MAC III - Administrative Sensitive)

Finding ID Severity Title
V-256628 Medium Performance Charts must fail to a known safe state if system initialization fails, shutdown fails, or aborts fail.
V-256629 Medium Performance Charts must limit the number of allowed connections.
V-256622 Medium Performance Charts must have Multipurpose Internet Mail Extensions (MIMEs) that invoke operating system shell programs disabled.
V-256623 Medium Performance Charts must have mappings set for Java servlet pages.
V-256620 Medium Performance Charts must not be configured with unsupported realms.
V-256621 Medium Performance Charts must be configured to limit access to internal packages.
V-256626 Medium Performance Charts must not have any symbolic links in the web content directory tree.
V-256627 Medium Performance Charts directory tree must have permissions in an out-of-the-box state.
V-256624 Medium Performance Charts must not have the Web Distributed Authoring (WebDAV) servlet installed.
V-256625 Medium Performance Charts must be configured with memory leak protection.
V-256640 Medium Rsyslog must be configured to monitor and ship Performance Charts log files.
V-256641 Medium Performance Charts must be configured with the appropriate ports.
V-256642 Medium Performance Charts must disable the shutdown port.
V-256643 Medium Performance Charts must set the secure flag for cookies.
V-256644 Medium Performance Charts default servlet must be set to "readonly".
V-256639 Medium Performance Charts must properly configure log sizes and rotation.
V-256638 Medium Performance Charts must have the debug option turned off.
V-256635 Medium Performance Charts must be configured to not show error reports.
V-256634 Medium Performance Charts must be configured to show error pages with minimal information.
V-256637 Medium Performance Charts must not enable support for TRACE requests.
V-256636 Medium Performance Charts must hide the server version.
V-256631 Medium Performance Charts must use the "setCharacterEncodingFilter" filter.
V-256630 Medium Performance Charts must set "URIEncoding" to UTF-8.
V-256633 Medium Performance Charts must not show directory listings.
V-256632 Medium Performance Charts must set the welcome-file node to a default web page.
V-256617 Medium Performance Charts log files must only be modifiable by privileged users.
V-256616 Medium Performance Charts must generate log records for system startup and shutdown.
V-256615 Medium Performance Charts must record user access in a format that enables monitoring of remote access.
V-256614 Medium Performance Charts must protect cookies from cross-site scripting (XSS).
V-256613 Medium Performance Charts must limit the maximum size of a POST request.
V-256612 Medium Performance Charts must limit the number of concurrent connections permitted.
V-256611 Medium Performance Charts must limit the amount of time that each Transport Control Protocol (TCP) connection is kept alive.
V-256619 Medium Performance Charts must only run one webapp.
V-256618 Medium Performance Charts application files must be verified for their integrity.