3.4 The JMXInvokerServlet servlet must be secured against web attacks

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The httpha-invoker.sar found in the deploy directory is a service that provides RMI/HTTP access for EJBs and the JNDI Naming service. By default older JBoss versions ship with a default set of <http-method> that allow attackers to bypass the security policy for JMX Invoker.

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|I

Plugin: Unix

Control ID: a1333d1542ae90db5b037fbd877bb9cb6ae52460aa99d0650162d8fa0d7c4c0e