Information
By default, when updating WebSphere application server, the older version of binaries are saved in case a 'roll back' is necessary. Not keeping the older version makes it more difficult for attackers to 'revert' back to the older version.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Review System Security Plan and system documentation to locate the 'IBM InstallationManager' folder.
Default locations are:
UNIX:
/opt/InstallationManager
Windows:
C:\Program Files\InstallationManager
UNIX:
<IMHOME>/eclipse/tools/imcl -c
Select 'P' preferences.
Select '3' Files for rollback.
Enter '1' to deselect.
Enter 'A' for apply.
Enter 'R' to return to Main Menu.
Windows:
<IMHOME>\eclipse\tools\imcl.exe -c
Select 'P' preferences.
Select '3' Files for rollback.
Enter '1' to deselect.
Enter 'A' for apply.
Enter 'R' to return to Main Menu.