JBOS-AS-000680 - Production JBoss servers must be supported by the vendor.

Information

The JBoss product is available as Open Source; however, the Red Hat vendor provides updates, patches and support for the JBoss product. It is imperative that patches and updates be applied to JBoss in a timely manner as many attacks against JBoss focus on unpatched systems. It is critical that support be obtained and made available.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Obtain vendor support from Red Hat.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_JBoss_EAP_6-3_V1R4_STIG.zip

Item Details

References: CAT|I, CCI|CCI-002605, Rule-ID|SV-76815r1_rule, STIG-ID|JBOS-AS-000680, Vuln-ID|V-62325

Plugin: Unix

Control ID: f9c362781cf4ae3d1f09bc3425f48f0380de837ddb424c085f9ee6bd4424726c