9.1 Disabling auto deployment of applications

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Tomcat allows auto deployment of applications while Tomcat is running. It is recommended that this capability be disabled.

This could allow malicious or untested applications to be deployed and should be disabled.

Solution

In the $CATALINA_HOME/conf/server.xml file, change autoDeploy to false

autoDeploy="false"

See Also

https://workbench.cisecurity.org/benchmarks/15137