Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-240873 | VRAU-TC-000905 | SV-240873r879810_rule | Medium |
Description |
---|
Cookies can be sent to a client using TLS/SSL to encrypt the cookies, but TLS/SSL is not used by every hosted application since the data being displayed does not require the encryption of the transmission. To safeguard against cookies, especially session cookies, being sent in plaintext, a cookie can be encrypted before transmission. To force a cookie to be encrypted before transmission, the cookie Secure property can be set. As a Tomcat derivative, tc Server is based in part on the Java Servlet specification. Servlet 3.0 (Java EE 6) introduced a standard way to configure secure attribute for the session cookie, this can be done by applying the correct configuration in web.xml. |
STIG | Date |
---|---|
VMware vRealize Automation 7.x tc Server Security Technical Implementation Guide | 2023-10-03 |
Check Text ( C-44106r674361_chk ) |
---|
At the command prompt, execute the following command: grep -E ' If the value of the |
Fix Text (F-44065r674362_fix) |
---|
Navigate to and open /etc/vco/app-server/web.xml. Navigate to the Add the Note: The |