9 - Deployment Scanner

Information

The deployment scanner scans the file system where your AS instance is running to automatically deploy any new application copied in your deploy directory. If it is not needed, the deployment scanner must be disabled in order to prevent unauthorized files being deployed.

Solution

Configure the scan-interval parameter as -1 , this will configure the deployment scanner to only allow deployments from console or at instance startup.

See Also

https://docs.jboss.org/author/display/AS72/Hardening+Guidelines

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 04c7c88b2846604eb7c5177143d96f86f93009571347f1f6e1ab9c8cb8d8d3c2