STIGQter STIGQter: STIG Summary: VMware vSphere 6.7 vCenter Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 09 Mar 2021:

The vCenter Server must not automatically refresh client sessions.

DISA Rule

SV-243073r719462_rule

Vulnerability Number

V-243073

Group Title

SRG-APP-000190

Rule Version

VCTR-67-000002

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Navigate to and open /etc/vmware/vsphere-ui/webclient.properties. Remove any existing "refresh.rate" line and add the following:

refresh.rate = -1

After editing the file, the vSphere Client service must be restarted.

# service-control --restart vsphere-client

Check Contents

Note: For vCenter Server Windows, this is not applicable.

On the vCenter Server, execute the following command:

# grep "^refresh\.rate" /etc/vmware/vsphere-client/webclient.properties

Expected result:

refresh.rate = -1

If the output does not match the expected result, this is a finding.

Vulnerability Number

V-243073

Documentable

False

Rule Version

VCTR-67-000002

Severity Override Guidance

Note: For vCenter Server Windows, this is not applicable.

On the vCenter Server, execute the following command:

# grep "^refresh\.rate" /etc/vmware/vsphere-client/webclient.properties

Expected result:

refresh.rate = -1

If the output does not match the expected result, this is a finding.

Check Content Reference

M

Target Key

5399

Comments