Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35333 | SRG-APP-000186-AS-000132 | SV-46620r1_rule | Medium |
Description |
---|
Non-local maintenance and diagnostic activities are those activities conducted by individuals communicating through a network, either an external network (e.g., the Internet) or an internal network. Application servers will typically utilize an HTTP interface for providing both local and remote maintenance and diagnostic sessions. The application server needs to ensure all sessions and network connections are terminated when non-local maintenance is completed. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43701r1_chk ) |
---|
Review the AS configuration to determine if the system is configured to terminate all sessions and network connections when non-local maintenance is completed. If the AS is not set to terminate these sessions, this is a finding. |
Fix Text (F-39879r1_fix) |
---|
Configure the AS to terminate all sessions and network connections when non-local maintenance is completed. |