WBSP-AS-000910 - The WebSphere Application Server process must not be started from the command line with the -password option.

Information

The use of the -password option to launch a WebSphere process from the command line can result in a security exposure. Password information may become visible to any user with the ability to view system processes. For example, on a Linux system the 'ps' command will display all running processes, which would include all of the command line flags used to start a WebSphere process.

Solution

When starting WebSphere commands, such as wsadmin, stopManager, stopNode, stopServer, or syncNode; do not use the '-password <password>' option.

Use the interactive mode instead; you will be prompted for user id and password.

For scripts, you may configure user id and password in the 'connector properties' files. These files are under 'Profile_Root/Properties' folder.

- soap.client.props: for default SOAP
- sas.client.props : for RMI and JSR160RMI connectors
- ipc.client.props: for IPC connector

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_WebSphere_Traditional_V9-x_V2R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-255856r960963_rule, STIG-ID|WBSP-AS-000910, STIG-Legacy|SV-95983, STIG-Legacy|V-81269, Vuln-ID|V-255856

Plugin: Unix

Control ID: b14d3af230e526dc11fd1589cc2100db3912f2be0027674562ed46364f979719