TCAT-AS-001250 - $CATALINA_BASE/logs/ folder must be owned by tomcat user, group tomcat.

Information

Tomcat file permissions must be restricted. The standard configuration is to have all Tomcat files owned by root with group Tomcat. While root has read/write privileges, group only has read permissions, and world has no permissions. The exceptions are the logs, temp, and work directories that are owned by the Tomcat user rather than root. This means that even if an attacker compromises the Tomcat process, they cannot change the Tomcat configuration, deploy new web applications, or modify existing web applications. The Tomcat process runs with a umask of 0027 to maintain these permissions.

Solution

If operational/application requirements specify different group file permissions, obtain ISSM risk acceptance and set permissions according to risk acceptance.

Run the following commands on the Tomcat server:

sudo find $CATALINA_BASE/logs -maxdepth 0 ( ! -user tomcat ) | sudo xargs chown tomcat

sudo find $CATALINA_BASE/logs -maxdepth 0 ( ! -group tomcat ) | sudo xargs chgrp tomcat

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apache_Tomcat_Application_Server_9_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-5(1), CAT|II, CCI|CCI-001813, Rule-ID|SV-222988r961461_rule, STIG-ID|TCAT-AS-001250, STIG-Legacy|SV-111499, STIG-Legacy|V-102559, Vuln-ID|V-222988

Plugin: Unix

Control ID: ecd8eb1e3ca2cb32dea3fef0e66b659d7660c06380694c4b38eb29e17ce470ba