UCF STIG Viewer Logo

The application server must define the maximum number of concurrent sessions for an application account globally, by account type, by account, or a combination thereof.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35070 SRG-APP-000001-AS-000001 SV-46335r1_rule Medium
Description
Application management includes the ability to control the number of sessions that utilize an application. Limiting the number of allowed sessions is helpful in limiting risks related to Denial of Service attacks. Application servers host and expose business logic and application processes. The application server must possess the capability to limit the maximum number of concurrent sessions in a manner that affects the entire application server or on an individual application basis. The maximum session number values must be configurable so as to meet future DoD requirements that define the maximum number of concurrent sessions.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43459r2_chk )
Review AS product documentation and configuration to determine if the number of concurrent sessions can be limited to an organization defined number of sessions.

If a feature to limit the number of concurrent sessions on a per hosted application basis is not configured, this is a finding.
Fix Text (F-39623r2_fix)
Configure the AS to limit the number of concurrent sessions per application or per server.