The WebSphere Application Server must remove JREs left by web server and plug-in installers for web servers and plugins running in the DMZ.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-81275WBSP-AS-000940SV-95989r1_ruleCCI-000381low
Description
When you install IBM HTTP Server, the installer leaves behind a JRE. Remove this JRE, as it provides functions that are not needed by the Web server or plug-in under normal conditions. Keep in mind that this will make it impossible to run some tools such as ikeyman on this Web server. When you install the WebSphere Application Server HTTP Server plug-in using the IBM installer, it also leaves behind a JRE. Also, remove this JRE post install. Having a functioning JRE in the DMZ provides attackers who have breached into the DMZ with additional tools to carry out further attacks.
STIGDate
IBM WebSphere Traditional V9.x Security Technical Implementation Guide2018-08-24

Related Frameworks

3 paths across 3 frameworks
NIST 800-531 mapping
CM-7
1.00
  • DISA · 1 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1711 mapping
3.4.6
1.00
  • DISA · 1 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000381
1.00
  • DISA · 1 · disa_xccdf · related

Details

Check Text (C-95989r1_chk)

This check needs to be run on the web server operating in the DMZ. Review system documentation. Identify web servers operating in DMZ. If there are no web servers configured for the DMZ, this is not applicable. From the administrative console, select Server Types >> Web Servers. Select each web server operating in the DMZ. Identify the "Web server installation location". Open a secured command shell to the web server in the DMZ. Change directory to the web server installation location. CD to the /plugins folder. If a /java directory exists in the plugins folder, this is a finding.

Fix Text (F-88055r1_fix)

For web servers provided with the WebSphere installation that are operating in the DMZ. Remove the /java directory from within the plugins folder.