9.1 Disabling auto deployment of applications

Information

Tomcat allows auto deployment of applications while Tomcat is running. It is recommended that this capability be disabled.

This could allow malicious or untested applications to be deployed and should be disabled.

Solution

In the $CATALINA_HOME/conf/server.xml file, change autoDeploy to false

autoDeploy="false"

See Also

https://workbench.cisecurity.org/benchmarks/15137

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv7|5.1

Plugin: Unix

Control ID: e92380dbaa8a476d369407e0eed387748fd3a7f1b5c06731fdee567db092c647