UCF STIG Viewer Logo

The operating system must prevent the execution of prohibited mobile code.


Overview

Finding ID Version Rule ID IA Controls Severity
V-47969 SOL-11.1-090100 SV-60841r1_rule Medium
Description
Decisions regarding the employment of mobile code within operating systems are based on the potential for the code to cause damage to the system if used maliciously. Mobile code technologies include Java, JavaScript, ActiveX, PDF, Postscript, Shockwave movies, Flash animations, and VBScript. Usage restrictions and implementation guidance apply to both the selection and use of mobile code installed on organizational servers and mobile code downloaded and executed on individual workstations.
STIG Date
Solaris 11 SPARC Security Technical Implementation Guide 2017-03-02

Details

Check Text ( C-50405r2_chk )
The Firefox browser is included with Solaris. Ensure that Java and JavaScript access by Firefox are disabled.

Start Firefox. Access the Edit > Preferences menu item.
Access the Content tab.
If Enable JavaScript is checked, this is a finding.

Access the Tools > Add ons menu item
Choose the Plugins tab.
If Java is enabled, this is a finding.
Fix Text (F-51581r2_fix)
Start Firefox. Access the Edit > Preferences menu item.
Choose the Content tab.
Disable JavaScript using the check box.

Access the Tools > Add ons menu item.
Choose the Plugins tab.
Disable Java by clicking on the Disable button.