8.1 Restrict runtime access to sensitive packages

Information

package.access grants or revokes access to listed packages during runtime. It is recommended that application access to certain packages be restricted.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Edit $CATALINA_BASE/conf/catalina.properties by adding allowed packages to the package.access list.

See Also

https://workbench.cisecurity.org/files/266

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Unix

Control ID: d62bdde67b97121fb702a34eda7af0d90eaf27a7a0d48c8cd20d97fad9471733