6.6 Ensure that JSONP access via an HTTP interface is disabled

Information

The net.http.JSONPEnabled parameter is used to enable or disable JSONP access via an HTTP interface. Enabling this parameter also enables the HTTP interface, even if the parameter for enabling the HTTP interface is set to disabled.

Please note that this function has been Deprecated since version 3.2.

Rationale:

Additional network interfaces expose the system to a greater extent. Running unnecessary services may allow an attacker to penetrate the system via an unknown vulnerability.

Solution

Set the parameter value to false to disable JSONP access.

Default Value:

false

See Also

https://workbench.cisecurity.org/files/168

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: 4289dfc4b652c30b82b184c4524d55246469959d52d04bdd05ee71b41e105bb3