UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

VMware vSphere 7.0 vCenter Appliance Perfcharts Security Technical Implementation Guide


Overview

Date Finding Count (34)
2023-02-21 CAT I (High): 0 CAT II (Med): 34 CAT III (Low): 0
STIG Description
This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Available Profiles



Findings (MAC I - Mission Critical Sensitive)

Finding ID Severity Title
V-256628 Medium Performance Charts must fail to a known safe state if system initialization fails, shutdown fails, or aborts fail.
V-256629 Medium Performance Charts must limit the number of allowed connections.
V-256622 Medium Performance Charts must have Multipurpose Internet Mail Extensions (MIMEs) that invoke operating system shell programs disabled.
V-256623 Medium Performance Charts must have mappings set for Java servlet pages.
V-256620 Medium Performance Charts must not be configured with unsupported realms.
V-256621 Medium Performance Charts must be configured to limit access to internal packages.
V-256626 Medium Performance Charts must not have any symbolic links in the web content directory tree.
V-256627 Medium Performance Charts directory tree must have permissions in an out-of-the-box state.
V-256624 Medium Performance Charts must not have the Web Distributed Authoring (WebDAV) servlet installed.
V-256625 Medium Performance Charts must be configured with memory leak protection.
V-256640 Medium Rsyslog must be configured to monitor and ship Performance Charts log files.
V-256641 Medium Performance Charts must be configured with the appropriate ports.
V-256642 Medium Performance Charts must disable the shutdown port.
V-256643 Medium Performance Charts must set the secure flag for cookies.
V-256644 Medium Performance Charts default servlet must be set to "readonly".
V-256639 Medium Performance Charts must properly configure log sizes and rotation.
V-256638 Medium Performance Charts must have the debug option turned off.
V-256635 Medium Performance Charts must be configured to not show error reports.
V-256634 Medium Performance Charts must be configured to show error pages with minimal information.
V-256637 Medium Performance Charts must not enable support for TRACE requests.
V-256636 Medium Performance Charts must hide the server version.
V-256631 Medium Performance Charts must use the "setCharacterEncodingFilter" filter.
V-256630 Medium Performance Charts must set "URIEncoding" to UTF-8.
V-256633 Medium Performance Charts must not show directory listings.
V-256632 Medium Performance Charts must set the welcome-file node to a default web page.
V-256617 Medium Performance Charts log files must only be modifiable by privileged users.
V-256616 Medium Performance Charts must generate log records for system startup and shutdown.
V-256615 Medium Performance Charts must record user access in a format that enables monitoring of remote access.
V-256614 Medium Performance Charts must protect cookies from cross-site scripting (XSS).
V-256613 Medium Performance Charts must limit the maximum size of a POST request.
V-256612 Medium Performance Charts must limit the number of concurrent connections permitted.
V-256611 Medium Performance Charts must limit the amount of time that each Transport Control Protocol (TCP) connection is kept alive.
V-256619 Medium Performance Charts must only run one webapp.
V-256618 Medium Performance Charts application files must be verified for their integrity.