JRE8-WN-000170 - Oracle JRE 8 must prompt the user for action prior to executing mobile code - deployment.insecure.jres

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Mobile code can cause damage to the system. It can execute without explicit action from, or notification to, a user.

Actions enforced before executing mobile code include, for example, prompting users prior to opening email attachments and disabling automatic execution.

This requirement applies to mobile code-enabled software, which is capable of executing one or more types of mobile code.

Solution

Navigate to the system-level 'deployment.properties' file for JRE.

Add the key 'deployment.insecure.jres=PROMPT' to the 'deployment.properties' file.

Add the key 'deployment.insecure.jres.locked' to the 'deployment.properties' file.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Oracle_JRE_8_Windows_V1R5_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4), CAT|II, CCI|CCI-002460, Rule-ID|SV-81453r2_rule, STIG-ID|JRE8-WN-000170, Vuln-ID|V-66963

Plugin: Windows

Control ID: 990b046afd1ab94efa573b943942a1b0e49cd6bb7364bf9f63a9ee558ef673b4