VCST-67-000009 - The Security Token Service must only run one web app.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

VMware ships the Security Token Service on the VCSA with one web app, in ROOT.war. Any other .war file is potentially malicious and must be removed.

Solution

Connect to the PSC, whether external or embedded.

For each unexpected file returned in the check, run the following command:

# rm /usr/lib/vmware-sso/vmware-sts/webapps/<NAME>.war

Restart the service with the following command:

# service-control --restart vmware-stsd

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-7_Y22M10_STIG.zip

Item Details

References: CAT|II, CCI|CCI-001749, Rule-ID|SV-239660r816705_rule, STIG-ID|VCST-67-000009, Vuln-ID|V-239660

Plugin: Unix

Control ID: 0dd0f8e5bd09c91f9ba75e1ffcc3876e484e3498d11b4a82eda896ecbb311626