9.2 Disabling auto deployment of applications

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Tomcat allows auto deployment of applications while Tomcat is running. It is recommended that this capability be disabled.

Solution

In the $CATALINA_HOME/conf/server.xml file, change autoDeploy to false.

See Also

https://workbench.cisecurity.org/files/267

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Unix

Control ID: 66d00576e7c1c988e1b7cc8aec595bdade1f4ad45a4d8afe00a94e0eee2e0028