8.1 Restrict runtime access to sensitive packages

Information

package.access grants or revokes access to listed packages during runtime. It is recommended that application access to certain packages be restricted.

Prevent web applications from accessing restricted or unknown packages which may be malicious or dangerous to the application.

Solution

Edit $CATALINA_BASE/conf/catalina.properties by adding allowed packages to the package.access list:

package.access = sun.,org.apache.catalina.,org.apache.coyote.,org.apache.jasper.,org.apache.tomcat.

See Also

https://workbench.cisecurity.org/benchmarks/15137

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: 2d2cd9293e55128ae3565f18f079c97683dfcddf5167555f05dbbad019d92d10