10.16 Do not allow cross context requests

Information

Setting crossContext to true allows for an application to call ServletConext.getContext to return a dispatcher for another application.

Solution

In all context.xml, set the crossContext attribute to false:
<Context ... crossContext="false" />

See Also

https://workbench.cisecurity.org/files/266

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: aa4ac4ff91fb5a5198b742633ef38f6db8f21dd6090c9276a07b895d4fc8bf8e