JBOS-AS-000025 - Java permissions must be set for hosted applications.

Information

The Java Security Manager is a java class that manages the external boundary of the Java Virtual Machine (JVM) sandbox, controlling how code executing within the JVM can interact with resources outside the JVM.

The JVM requires a security policy in order to restrict application access. A properly configured security policy will define what rights the application has to the underlying system. For example, rights to make changes to files on the host system or to initiate network sockets in order to connect to another system.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the Java security manager to enforce access restrictions to the host system resources in accordance with application design and resource requirements.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_JBoss_EAP_6-3_V2R3_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|I, CCI|CCI-000213, Rule-ID|SV-213496r615939_rule, STIG-ID|JBOS-AS-000025, STIG-Legacy|SV-76707, STIG-Legacy|V-62217, Vuln-ID|V-213496

Plugin: Unix

Control ID: ed52f21ebc42e122da5b9ae5418ecacfa8509bd8a1508fc6038e9dbc6bc99cd6