WG490 - Java software installed on the web server is not limited to class files and the JAVA virtual machine.

Information

Vulnerability Key: V0002265
IA Controls: ECSC-1 Security Configuration Compliance
Categories: 7.7 Code Validation
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 4.7
From source code in a .java or .jpp file, the Java compiler produces a binary file with an extension
of .class. The .java or .jpp file would therefore reveal sensitive information regarding an applications
logic and permissions to resources on the server. By contrast the .class file, because it is intended to
be machine independent, is referred to a bytecode. Bytecodes are run by the Java Virtual Machine,
JVM, or Java Runtime Environment, JRE, via a browser configured to permit Java code.
NOTE: This check only searches the 'C:' drive, if the system has multiple drives ensure each drive doesn't contain compilers.
NOTE: If there is nothing reported in the plugin output then Nessus did not find any backup files on the system.

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Windows

Control ID: 834f644d7c315b37a0763afcb302fad7c059ff3665e2e8c8a3017455af401d43