TCAT-AS-001700 - Tomcat users in a management role must be approved by the ISSO.

Information

Deploying applications to Tomcat requires a Tomcat user account that is in the 'manager-script' role. Any user accounts in a Tomcat management role must be approved by the ISSO.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Document the users and the roles that have been defined for use with the Tomcat server.

Ensure that all users and roles with access to Tomcat management features and capabilities are approved by the ISSO.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apache_Tomcat_Application_Server_9_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-223006r961863_rule, STIG-ID|TCAT-AS-001700, STIG-Legacy|SV-111535, STIG-Legacy|V-102595, Vuln-ID|V-223006

Plugin: Unix

Control ID: db73a7408723d39cdd0488c599f90bcd5c6cc62be74f183bca5ee4bf68ee569e