The application server must be capable of reverting to the last known good configuration in the event of failed installations and upgrades.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-204742 | SRG-APP-000133-AS-000093 | SV-204742r960960_rule | CCI-001190 | medium |
| Description | ||||
| Any changes to the components of the application server can have significant effects on the overall security of the system. In order to ensure a prompt response to failed application installations and application server upgrades, the application server must provide an automated rollback capability that allows the system to be restored to a previous known good configuration state prior to the application installation or application server upgrade. | ||||
| STIG | Date | |||
| Application Server Security Requirements Guide | 2025-02-11 | |||
Details
Check Text (C-204742r960960_chk)
Check the application server documentation and configuration to determine if the application server provides an automated rollback capability to a known good configuration in the event of a failed installation and upgrade.
If the application server is not configured to meet this requirement, this is a finding.
Fix Text (F-4862r282874_fix)
Configure the application server to automatically rollback to a known good configuration in the event of failed application installations and application server upgrades.