10.16 Do not allow cross context requests

Information

Setting crossContext to true allows for an application to call ServletConext.getContext to return a dispatcher for another application.

Solution

In all context.xml, set the crossContext attribute to false:
<Context ... crossContext="false" />

See Also

https://workbench.cisecurity.org/files/266

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 01700fed1f97716da0f845edc0f8af1a7f2cddda36e8d3fc82c67d7a44c2d9b9