Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35070 | SRG-APP-000001-AS-000001 | SV-46335r1_rule | Medium |
Description |
---|
Application management includes the ability to control the number of sessions that utilize an application. Limiting the number of allowed sessions is helpful in limiting risks related to Denial of Service attacks. Application servers host and expose business logic and application processes. The application server must possess the capability to limit the maximum number of concurrent sessions in a manner that affects the entire application server or on an individual application basis. The maximum session number values must be configurable so as to meet future DoD requirements that define the maximum number of concurrent sessions. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43459r2_chk ) |
---|
Review AS product documentation and configuration to determine if the number of concurrent sessions can be limited to an organization defined number of sessions. If a feature to limit the number of concurrent sessions on a per hosted application basis is not configured, this is a finding. |
Fix Text (F-39623r2_fix) |
---|
Configure the AS to limit the number of concurrent sessions per application or per server. |