4.4.10 Ensure 'trustedHeaderOrigin' is set to trusted host names and IP addresses

Information

The web server plug-in uses private headers to provide information about the original request. These headers take precedence over the HTTP host header and are used to select a virtual host to service a request. To restrict private header processing to specific trusted sources, specify a comma-separated list of IP addresses and hostnames.

Solution

Add the settings below to ${server.config.dir}/configDropins/overrides/<any file name>.xml

<httpDispatcher ...
trustedHeaderOrigin="localhost, 127.0.0.1, 192.168.*.*, 0:0:0:0:0:ffff:*:*, *.ibm.com"/>

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6

Plugin: Unix

Control ID: 888d9375d52f288de21ccb86dde0faa3a4f8260ce60e344270bb2879a2c70992