UCF STIG Viewer Logo

The vCenter STS service default documentation must be removed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-258997 VCST-80-000143 SV-258997r960963_rule Medium
Description
Tomcat provides documentation and other directories in the default installation that do not serve a production use. These files must be deleted.
STIG Date
VMware vSphere 8.0 vCenter Appliance Secure Token Service (STS) Security Technical Implementation Guide 2024-07-11

Details

Check Text ( C-62737r934647_chk )
At the command prompt, run the following command:

# ls -l /var/opt/apache-tomcat/webapps/docs

If the "docs" folder exists or contains any content, this is a finding.
Fix Text (F-62646r934648_fix)
At the command prompt, run the following command:

# rm -rf /var/opt/apache-tomcat/webapps/docs