VCUI-80-000142 The vCenter UI service default ROOT web application must be removed.

Information

The default ROOT web application includes the version of Tomcat being used, links to Tomcat documentation, examples, FAQs, and mailing lists. The default ROOT web application must be removed from a publicly accessible instance and a more appropriate default page shown to users.

Solution

At the command prompt, run the following command:

# rm -rf /usr/lib/vmware-vsphere-ui/server/webapps/ROOT/*

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_8-0_Y24M08_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-259131r960963_rule, STIG-ID|VCUI-80-000142, Vuln-ID|V-259131

Plugin: Unix

Control ID: 02cc13b43d037ca07c4f20c3e57a8c4356b32427ffbb743b452505e29537e245