VCPF-67-000031 - Performance Charts must be configured to limit access to internal packages.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The 'package.access' entry in the 'catalina.properties' file implements access control at the package level. When this is properly configured, a Security Exception will be reported if an errant or malicious web app attempts to access the listed internal classes directly or if a new class is defined under the protected packages. Performance Charts comes preconfigured with the appropriate packages defined in 'package.access', and this configuration must be maintained.

Solution

Navigate to and open /usr/lib/vmware-sso/vmware-sts/conf/catalina.properties and ensure that the 'package.access' line is configured as follows:

package.access =
sun.,
org.apache.catalina.,
org.apache.coyote.,
org.apache.jasper.,
org.apache.naming.resources.,
org.apache.tomcat.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-7_Y22M10_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000381, Rule-ID|SV-239432r675019_rule, STIG-ID|VCPF-67-000031, Vuln-ID|V-239432

Plugin: Unix

Control ID: 58bba175da4dc8fb1786bc4b310d66fe71be5363fa6dc1c5645c450db5e6d8c7