The vCenter STS service default documentation must be removed.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-258997VCST-80-000143SV-258997r934649_ruleCCI-000381medium
Description
Tomcat provides documentation and other directories in the default installation that do not serve a production use. These files must be deleted.
STIGDate
VMware vSphere 8.0 vCenter Appliance Secure Token Service (STS) Security Technical Implementation Guide2023-10-29

Details

Check Text (C-258997r934649_chk)

At the command prompt, run the following command: # ls -l /var/opt/apache-tomcat/webapps/docs If the "docs" folder exists or contains any content, this is a finding.

Fix Text (F-62646r934648_fix)

At the command prompt, run the following command: # rm -rf /var/opt/apache-tomcat/webapps/docs