WBLC-03-000129 - Oracle WebLogic must utilize automated mechanisms to prevent program execution on the information system.

Information

The application server must provide a capability to halt or otherwise disable the automatic execution of deployed applications until such time that the application is considered part of the established application server baseline. Deployment to the application server should not provide a means for automatic application start-up should the application server itself encounter a restart condition.

Solution

1. Access AC
2. From 'Domain Structure', select the top-level domain
3. Select 'Configuration' tab -> 'General' tab
4. Check 'Production Mode' checkbox. Click 'Save'
5. Restart all servers

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_WebLogic_Server_12c_V2R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-235963r628667_rule, STIG-ID|WBLC-03-000129, STIG-Legacy|SV-70529, STIG-Legacy|V-56275, Vuln-ID|V-235963

Plugin: Unix

Control ID: 926177dd9bc9cdf7af8a0a0c445aab095cf1295a65ef3a67ecb5bef3e2e3976c