8.1 Restrict runtime access to sensitive packages

Information

package.access grants or revokes access to listed packages during runtime. It is recommended that application access to certain packages be restricted.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Edit $CATALINA_BASE/conf/catalina.properties by adding allowed packages to the package.access list.

See Also

https://workbench.cisecurity.org/files/266

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Unix

Control ID: 88c8bec890e5b40e40bfb819e804824c4f5d54c4357f525940998657a431f5b8