Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35376 | SRG-APP-000211-AS-000146 | SV-46663r1_rule | Medium |
Description |
---|
Application server management functionality includes functions necessary to administer the application server, and requires privileged access via one of the accounts assigned to a management role. The separation of AS administration functionality from hosted application functionality is either physical or logical and is accomplished by using different computers, different central processing units, different instances of the operating system, network addresses, network ports, or combinations of these methods, as appropriate. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43739r1_chk ) |
---|
Review the AS documentation and configuration to verify that the AS separates admin functionality from hosted application functionality. If the AS does not separate AS admin functionality from hosted application functionality, this is a finding. |
Fix Text (F-39923r1_fix) |
---|
Configure the AS so that admin management functionality and hosted applications are separated. |