vSphere UI must be configured to limit access to internal packages.


Finding ID Version Rule ID IA Controls Severity
V-256788 VCUI-70-000011 SV-256788r889363_rule Medium
The "package.access" entry in the "catalina.properties" file implements access control at the package level. When properly configured, a Security Exception will be reported if an errant or malicious webapp attempts to access the listed internal classes directly or if a new class is defined under the protected packages. The vSphere UI comes preconfigured with the appropriate packages defined in "package.access", and this configuration must be maintained.
Check Text ( C-60463r889361_chk )
At the command prompt, run the following command:

# grep "package.access" /usr/lib/vmware-vsphere-ui/server/conf/catalina.properties

Expected result:


If the output of the command does not match the expected result, this is a finding.
Fix Text (F-60406r889362_fix)
Navigate to and open:


Ensure the "package.access" line is configured as follows:


Restart the service with the following command:

# vmon-cli --restart vsphere-ui