UCF STIG Viewer Logo

DefaultServlet debug parameter must be disabled.


Overview

Finding ID Version Rule ID IA Controls Severity
V-222953 TCAT-AS-000510 SV-222953r615938_rule Low
Description
The DefaultServlet serves static resources as well as serves the directory listings (if directory listings are enabled). It is declared globally in $CATALINA_BASE/conf/web.xml and by default is configured with the "debug" parameter set to 0, which is disabled. Changing this to a value of 1 or higher sets the servlet to print debug level information. DefaultServlet debug setting must be set to 0 (disabled).
STIG Date
Apache Tomcat Application Sever 9 Security Technical Implementation Guide 2021-12-27

Details

Check Text ( C-24625r426303_chk )
From the Tomcat server run the following OS command:

sudo cat $CATALINA_BASE/conf/web.xml |grep -i -A10 -B2 defaultservlet

The above command will include ten lines after and two lines before the occurrence of "defaultservlet". Some systems may require that the user increase the after number (A10) in order to determine the "debug" param-value.

If the "debug" param-value for the "DefaultServlet" servlet class does not = 0, this is a finding.
Fix Text (F-24614r426304_fix)
From the Tomcat server as a privileged user:

Edit the $CATALINA_BASE/conf/web.xml file.

Examine the elements within the element, if the "debug" element is not "0"" change the "debug" to read "0".

sudo systemctl restart tomcat
sudo systemctl daemon-reload