VCPF-80-000139 The vCenter Perfcharts service must have Autodeploy disabled.

Information

Tomcat allows auto-deployment of applications while it is running. This can allow untested or malicious applications to be automatically loaded into production. Autodeploy must be disabled in production.

Solution

Navigate to and open:

/usr/lib/vmware-perfcharts/tc-instance/conf/server.xml

Navigate to the <Host> node and configure with the value "autoDeploy="false"".

Restart the service with the following command:

# vmon-cli --restart perfcharts

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_8-0_Y24M08_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-259095r960963_rule, STIG-ID|VCPF-80-000139, Vuln-ID|V-259095

Plugin: Unix

Control ID: dabd597ff2cc934e9ea0cfa0f930f1e152f054a41805e4afda49aa66ab53361f