3.10 - Anonymous Admin Lookup Disabled

Information

Ensure that the 'Anonymous Admin Lookup Enabled' is [disabled].

If the 'Anonymous Admin Lookup Enabled' option is enabled, users can see the value of any MBean attribute that is not explicitly marked as protected by the WebLogic Server MBean authorization process.

Solution

To disable Anonymous Admin Lookup perform the steps mentioned below:
1. Login to the Administration Console.
2. In the Change Center, click Lock & Edit.
3. In the left pane, select the Domain name.
4. Select the Security tab.
5. Ensure that the 'Anonymous Admin Lookup Enabled' checkbox is not checked.
6. If necessary, click Save

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Windows

Control ID: b27eeffd79a827b0083055e1bf6c997d2ce078b2c0e8ecd0f421db910bce1b52