2.2 - Weak permissions on Log files

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Only root or web administrators must be able to write to log files.

An attacker might be able to delete or alter logs and hence it would be difficult to track activities performed on the web server.

Solution

No other user, other than the Weblogic administrator account should have Read, Write and execute access to the Weblogic logs.

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: Unix

Control ID: 231b3e46c5094800f4cfb18000d4ccec7fa9637b75a394fdbf07ad0243b364ac