The vCenter ESX Agent Manager service host-manager webapp must be removed.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-259036VCEM-80-000155SV-259036r1003619_ruleCCI-000381medium
Description
Tomcat provides host management functionality through either a default host-manager webapp or through local editing of the configuration files. The host-manager webapp files must be deleted, and administration must be performed through the local editing of the configuration files.
STIGDate
VMware vSphere 8.0 vCenter Appliance ESX Agent Manager (EAM) Security Technical Implementation Guide2024-12-16

Details

Check Text (C-259036r1003619_chk)

At the command prompt, run the following command: # ls -l /var/opt/apache-tomcat/webapps/host-manager If the host-manager folder exists or contains any content, this is a finding.

Fix Text (F-62685r934765_fix)

At the command prompt, run the following command: # rm -rf /var/opt/apache-tomcat/webapps/host-manager