OH12-1X-000223 - The OHS document root directory must not be on a network share.

Information

Sharing of web server content is a security risk when a web server is involved. Users accessing the share anonymously could experience privileged access to the content of such directories. Network sharable directories expose those directories and their contents to unnecessary access. Any unnecessary exposure increases the risk that someone could exploit that access and either compromises the web content or cause web server performance problems.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

1. Open $DOMAIN_HOME/config/fmwconfig/components/OHS/<componentName>/httpd.conf and every .conf file (e.g., ssl.conf) included in it with an editor that contains a '<VirtualHost>' directive.

2. Search for the 'DocumentRoot' directive at the OHS server and virtual host configuration scopes.

3. Remove the shares that are associated with any directory specified as a value for the 'DocumentRoot' directives.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_HTTP_Server_12-1-3_V1R7_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-11, CAT|II, CCI|CCI-000366, Rule-ID|SV-79173r1_rule, STIG-ID|OH12-1X-000223, Vuln-ID|V-64683

Plugin: Unix

Control ID: 7a92b8e494382072cc79874e0f718813629519a47236925b839fad61968e4ee3