UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

VMware vSphere 6.7 UI Tomcat Security Technical Implementation Guide


Overview

Date Finding Count (32)
2022-01-03 CAT I (High): 0 CAT II (Med): 32 CAT III (Low): 0
STIG Description
This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Available Profiles



Findings (MAC III - Administrative Sensitive)

Finding ID Severity Title
V-239694 Medium vSphere UI must not have the Web Distributed Authoring (WebDAV) servlet installed.
V-239695 Medium vSphere UI must be configured with memory leak protection.
V-239696 Medium vSphere UI must not have any symbolic links in the web content directory tree.
V-239697 Medium vSphere UI directory tree must have permissions in an "out-of-the-box" state.
V-239690 Medium vSphere UI plugins must be authorized before use.
V-239691 Medium vSphere UI must be configured to limit access to internal packages.
V-239692 Medium vSphere UI must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.
V-239693 Medium vSphere UI must have mappings set for Java servlet pages.
V-239698 Medium vSphere UI must fail to a known safe state if system initialization fails, shutdown fails, or aborts fail.
V-239699 Medium vSphere UI must limit the number of allowed connections.
V-239706 Medium vSphere UI must have the debug option turned off.
V-239707 Medium vSphere UI must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the web server.
V-239704 Medium vSphere UI must be configured to show error pages with minimal information.
V-239705 Medium vSphere UI must not enable support for TRACE requests.
V-239702 Medium The vSphere UI must not show directory listings.
V-239703 Medium vSphere UI must be configured to hide the server version.
V-239700 Medium vSphere UI must set URIEncoding to UTF-8.
V-239701 Medium vSphere UI must set the welcome-file node to a default web page.
V-239708 Medium vSphere UI log files must be moved to a permanent repository in accordance with site policy.
V-239709 Medium vSphere UI must be configured with the appropriate ports.
V-239687 Medium vSphere UI must generate log records for system startup and shutdown.
V-239686 Medium vSphere UI must record user access in a format that enables monitoring of remote access.
V-239685 Medium vSphere UI must protect cookies from XSS.
V-239684 Medium vSphere UI must limit the maximum size of a POST request.
V-239683 Medium vSphere UI must limit the number of concurrent connections permitted.
V-239682 Medium vSphere UI must limit the amount of time that each TCP connection is kept alive.
V-239689 Medium vSphere UI application files must be verified for their integrity.
V-239688 Medium vSphere UI log files must only be accessible by privileged users.
V-239711 Medium vSphere UI must set the secure flag for cookies.
V-239710 Medium vSphere UI must disable the shutdown port.
V-239713 Medium vSphere UI must restrict its cookie path.
V-239712 Medium vSphere UI must not be configured with the "UserDatabaseRealm" enabled.