3.6 - Web Server Process should not run as root - directory permissions

Information

Web Server used in conjunction with Weblogic should not be running under root

If the system is attacked while the Web Server is running under 'root', the malicious user could gain full administrative access to the system by inheriting root's privileges. Also, if the files and directory structure for the Web Server are available to unprivileged users, then malicious code could be inserted and potentially executed by the Web Server

Solution

Ensure that the Web Server used in conjunction with WebLogic Server is not run as 'root' and that its directory structure, including all files, is protected from access by unauthorized users.

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-6(7), 800-53|CM-6, CSCv6|3.1

Plugin: Windows

Control ID: a89ef9c4c9248ba3bb0fa34eec94eeb6c6a901a046840fd71619519df02bdabb