UCF STIG Viewer Logo

VMware vSphere 6.7 UI Tomcat Security Technical Implementation Guide


Overview

Date Finding Count (32)
2022-01-03 CAT I (High): 0 CAT II (Med): 32 CAT III (Low): 0
STIG Description
This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Available Profiles



Findings (MAC II - Mission Support Sensitive)

Finding ID Severity Title
V-239694 Medium vSphere UI must not have the Web Distributed Authoring (WebDAV) servlet installed.
V-239695 Medium vSphere UI must be configured with memory leak protection.
V-239696 Medium vSphere UI must not have any symbolic links in the web content directory tree.
V-239697 Medium vSphere UI directory tree must have permissions in an "out-of-the-box" state.
V-239690 Medium vSphere UI plugins must be authorized before use.
V-239691 Medium vSphere UI must be configured to limit access to internal packages.
V-239692 Medium vSphere UI must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.
V-239693 Medium vSphere UI must have mappings set for Java servlet pages.
V-239698 Medium vSphere UI must fail to a known safe state if system initialization fails, shutdown fails, or aborts fail.
V-239699 Medium vSphere UI must limit the number of allowed connections.
V-239706 Medium vSphere UI must have the debug option turned off.
V-239707 Medium vSphere UI must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the web server.
V-239704 Medium vSphere UI must be configured to show error pages with minimal information.
V-239705 Medium vSphere UI must not enable support for TRACE requests.
V-239702 Medium The vSphere UI must not show directory listings.
V-239703 Medium vSphere UI must be configured to hide the server version.
V-239700 Medium vSphere UI must set URIEncoding to UTF-8.
V-239701 Medium vSphere UI must set the welcome-file node to a default web page.
V-239708 Medium vSphere UI log files must be moved to a permanent repository in accordance with site policy.
V-239709 Medium vSphere UI must be configured with the appropriate ports.
V-239687 Medium vSphere UI must generate log records for system startup and shutdown.
V-239686 Medium vSphere UI must record user access in a format that enables monitoring of remote access.
V-239685 Medium vSphere UI must protect cookies from XSS.
V-239684 Medium vSphere UI must limit the maximum size of a POST request.
V-239683 Medium vSphere UI must limit the number of concurrent connections permitted.
V-239682 Medium vSphere UI must limit the amount of time that each TCP connection is kept alive.
V-239689 Medium vSphere UI application files must be verified for their integrity.
V-239688 Medium vSphere UI log files must only be accessible by privileged users.
V-239711 Medium vSphere UI must set the secure flag for cookies.
V-239710 Medium vSphere UI must disable the shutdown port.
V-239713 Medium vSphere UI must restrict its cookie path.
V-239712 Medium vSphere UI must not be configured with the "UserDatabaseRealm" enabled.