10.1 Ensure Unused Features are Removed

Information

The Websphere Liberty architecture provides developers with the option to tune their server to only the features that they need. For example, the JDBC feature only needs to be added if database access is required. If you did not want any remote administrative access to the REST interface, you would remove the REST feature.

Enabling only the necessary

Liberty features

minimizes the disk and memory footprint of the server as well as a faster start time. Having unused features could increase the chance of having a vulnerability due to the default settings of some features.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Removed any unneeded features listed under the featureManager element in the

Liberty configuration

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.2

Plugin: Unix

Control ID: 8e9b3ba8c8e8d6c64a85facc87e37d6297f9f2fe26901302be9c9ef1b868a6c1