10.15 Do not allow cross context requests

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Setting crossContext to true allows for an application to call ServletConext.getContext to return a dispatcher for another application.

Solution

In all context.xml, set the crossContext attribute to false:
<Context ... crossContext="false" />

See Also

https://workbench.cisecurity.org/files/267

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Unix

Control ID: 0a344d99f0fc899ea759eed4b3beeaa6d701d1b55f96f5ecf02d26ac214ab4cb