2.2 - Weak permissions on Log files

Information

Only root or web administrators must be able to write to log files.

An attacker might be able to delete or alter logs and hence it would be difficult to track activities performed on the web server.

Solution

No other user, other than the Weblogic administrator account should have Read, Write and execute access to the Weblogic logs.

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-6(7), 800-53|CM-6, CSCv6|3.1

Plugin: Windows

Control ID: 231b3e46c5094800f4cfb18000d4ccec7fa9637b75a394fdbf07ad0243b364ac