Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-64623 | OH12-1X-000192 | SV-79113r1_rule | Medium |
Description |
---|
The Oracle Dynamic Monitoring Service (DMS) enables application developers, support analysts, system administrators, and others to measure application specific performance information. If OHS allows any machine to connect and monitor performance, an attacker could connect and gather information that could be used to cause a DoS for OHS. Information that is shared could also be used to further an attack to other servers and devices through trusted relationships. |
STIG | Date |
---|---|
Oracle HTTP Server 12.1.3 Security Technical Implementation Guide | 2019-01-04 |
Check Text ( C-65365r1_chk ) |
---|
1. Open $DOMAIN_HOME/config/fmwconfig/components/OHS/ 2. Search for the "Allow" directive within the " 3. If the "Allow" directive is set to "from all", this is a finding. |
Fix Text (F-70553r1_fix) |
---|
1. Open $DOMAIN_HOME/config/fmwconfig/components/OHS/ 2. Search for the "Allow" directive within the " 3. Set the "Allow" directive to "from 127.0.0.1". |