STIGQter STIGQter: STIG Summary: ISEC7 Sphere Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The ISEC7 SPHERE must remove any unnecessary users or groups that have permissions to the server.xml file in Apache Tomcat.

DISA Rule

SV-224790r1013879_rule

Vulnerability Number

V-224790

Group Title

SRG-APP-000380

Rule Version

ISEC-06-551310

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the ISEC7 SPHERE server.
Browse to ProgramFiles\Isec7 SPHERE\Tomcat\Conf and select Server.xml.
Right-click and select "Properties".
Select the security tab and remove unnecessary accounts or groups that have been granted permissions to the Server.xml file.

Check Contents

Verify unnecessary users or groups that have permissions to the Server.xml file in Apache Tomcat have been removed.

Browse to ProgramFiles\Isec7 SPHERE\Tomcat\Conf and select "Server.xml".
Right-click and select "Properties".
Select the security tab and verify no unnecessary account or groups have been granted permissions to the file.
Verify no unnecessary users or groups have permissions to the file.

If unnecessary users or groups that have permissions to the Server.xml file in Apache Tomcat have not been removed, this is a finding.

Vulnerability Number

V-224790

Documentable

False

Rule Version

ISEC-06-551310

Severity Override Guidance

Verify unnecessary users or groups that have permissions to the Server.xml file in Apache Tomcat have been removed.

Browse to ProgramFiles\Isec7 SPHERE\Tomcat\Conf and select "Server.xml".
Right-click and select "Properties".
Select the security tab and verify no unnecessary account or groups have been granted permissions to the file.
Verify no unnecessary users or groups have permissions to the file.

If unnecessary users or groups that have permissions to the Server.xml file in Apache Tomcat have not been removed, this is a finding.

Check Content Reference

M

Target Key

4200