The vCenter STS service example applications must be removed.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-258995VCST-80-000141SV-258995r934643_ruleCCI-000381medium
Description
Tomcat provides example applications, documentation, and other directories in the default installation that do not serve a production use. These files must be deleted.
STIGDate
VMware vSphere 8.0 vCenter Appliance Secure Token Service (STS) Security Technical Implementation Guide2023-10-29

Details

Check Text (C-258995r934643_chk)

At the command prompt, run the following command: # ls -l /var/opt/apache-tomcat/webapps/examples If the examples folder exists or contains any content, this is a finding.

Fix Text (F-62644r934642_fix)

At the command prompt, run the following command: # rm -rf /var/opt/apache-tomcat/webapps/examples