10.16 Do not allow cross context requests

Information

Setting crossContext to true allows for an application to call ServletConext.getContext to return a dispatcher for another application.

Solution

In all context.xml, set the crossContext attribute to false:
<Context ... crossContext="false" />

See Also

https://workbench.cisecurity.org/files/266

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 8cfd504c98ff1d5bd8336ef655ca89a4a18e5ce9dc0e92a2817e586510851808