JRE8-WN-000070 - Oracle JRE 8 must be set to allow Java Web Start (JWS) applications - deployment.webjava.enabled

Information

Java Web Start (JWS) applications are the most commonly used. Denying these applications could be detrimental to the user experience. Whitelisting, blacklisting, and signing of applications help mitigate the risk of running JWS applications.

Solution

Navigate to the system-level 'deployment.properties' file for JRE.

The location of the deployment.properties file is defined in <JRE Installation Directory>\Lib\deployment.config

Add the key 'deployment.webjava.enabled=true' to the deployment.properties file.

Add the key 'deployment.webjava.enabled.locked' to the deployment.properties file.

Note: If JWS is not enabled, this requirement is NA.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_JRE_Windows_V2R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-234687r617446_rule, STIG-ID|JRE8-WN-000070, STIG-Legacy|SV-81437, STIG-Legacy|V-66947, Vuln-ID|V-234687

Plugin: Windows

Control ID: 4984bc5b0aed9dcc0836dee4015f67c9e5c90724cf690f9bc4a253a00c7d3cdf