Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-240863 | VRAU-TC-000845 | SV-240863r879806_rule | Medium |
Description |
---|
An attacker has at least two reasons to stop a web server. The first is to cause a DoS, and the second is to put in place changes the attacker made to the web server configuration. As a Tomcat derivative, tc Server uses a port (defaults to 8005) as a shutdown port. If enabled, a shutdown signal can be sent to tc Server through this port. To ensure availability, the shutdown port should be disabled. |
STIG | Date |
---|---|
VMware vRealize Automation 7.x tc Server Security Technical Implementation Guide | 2023-10-03 |
Check Text ( C-44096r674331_chk ) |
---|
At the command prompt, execute the following command: grep shutdown /etc/vco/app-server/server.xml If the value of "shutdown" is not set to "-1" or is missing, this is a finding. |
Fix Text (F-44055r674332_fix) |
---|
Navigate to and open /etc/vco/app-server/server.xml. Navigate to the Add the attribute 'port="-1"' to the |