SV-250340r1043182_rule
V-250340
SRG-APP-000295-AS-000263
IBMW-LS-000720
CAT II
10
The ${server.config.dir}/server.xml file must be configured to update the invalidationTimeout attribute on the httpSession element to set the session timeout value in hours (h) or minutes (m). The server.xml file must define the following:
<httpSession invalidationTimeout="10m"/>
By default, httpSession invalidationTimeout is set to 30m.
As a user with access to the server xml file, review the contents and verify the httpSession time out setting is configured for 10 minutes.
If the ${server.config.dir}/server.xml does not define the timeout setting as 10 minutes, this is a finding.
<httpSession invalidationTimeout="10m"/>
V-250340
False
IBMW-LS-000720
As a user with access to the server xml file, review the contents and verify the httpSession time out setting is configured for 10 minutes.
If the ${server.config.dir}/server.xml does not define the timeout setting as 10 minutes, this is a finding.
<httpSession invalidationTimeout="10m"/>
M
5424