JBOS-AS-000685 - The JRE installed on the JBoss server must be kept up to date.

Information

The JBoss product is available as Open Source; however, the Red Hat vendor provides updates, patches and support for the JBoss product. It is imperative that patches and updates be applied to JBoss in a timely manner as many attacks against JBoss focus on unpatched systems. It is critical that support be obtained and made available.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure the operating system and the application server to use a patch management system or process that ensures security-relevant updates are installed within the time period directed by the ISSM.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_JBoss_EAP_6-3_V2R4_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2c., CAT|I, CCI|CCI-002605, Rule-ID|SV-213550r955727_rule, STIG-ID|JBOS-AS-000685, STIG-Legacy|SV-76817, STIG-Legacy|V-62327, Vuln-ID|V-213550

Plugin: Unix

Control ID: 6f7793f695914a0ee64c2e5ca8e142f17ff9a81397f999761f5f16caf3aa825d