9.2 Disable deploy on startup of applications

Information

Tomcat allows auto deployment of applications on startup. It is recommended that this capability be disabled.

This could allow malicious or untested applications to be deployed and should be disabled.

Solution

In the $CATALINA_HOME/conf/server.xml file, change deployOnStartup to false

deployOnStartup="false"

See Also

https://workbench.cisecurity.org/benchmarks/15137

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv7|5.1

Plugin: Unix

Control ID: 626af4655061c99986ccdb85d7c1e9ce0387c1c109bb5a0393847eb40c9d1839