TCAT-AS-000010 - The number of allowed simultaneous sessions to the manager application must be limited.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The manager application provides configuration access to the Tomcat server. Access to the manager application must be limited and that includes the number of sessions allowed to access the management application. A balance must be struck between the number of simultaneous connections allowed to the management application and the number of authorized admins requiring access at any given time.

Determine the number of authorized admins requiring simultaneous access and increase the number of allowed simultaneous sessions by a small percentage in order to help prevent potential lockouts.

Document that value in the System Security Plan (SSP).

Solution

Determine the number of authorized admins requiring simultaneous access and increase the number of allowed simultaneous sessions by a small percentage in order to address potential lockout scenarios. Document that value in the System Security Plan.

Review the maxActiveSessions setting in the $CATALINA_BASE/webapps/manager/ META-INF/context.xml configuration file.

Configure maxActiveSessions setting according to admin access requirements defined in the SSP.

EXAMPLE:
<Manager ... maxActiveSessions='10' />

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apache_Tomcat_Application_Server_9_V2R4_STIG.zip

Item Details

References: CAT|III, CCI|CCI-000054, Rule-ID|SV-222926r615938_rule, STIG-ID|TCAT-AS-000010, STIG-Legacy|SV-111371, STIG-Legacy|V-102427, Vuln-ID|V-222926

Plugin: Unix

Control ID: a93db10c1f11ba3c14de104a4a6783545748ef7aaa6076ffc5d6e79b71a5de20