Skip to content

VMware vSphere 7.0 vCenter Appliance STS Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • The Security Token Service must set "URIEncoding" to UTF-8.

    Invalid user input occurs when a user inserts data or characters into a hosted application's data entry field and the hosted application is unprepared to process that data. This results in unantici...
    Rule Medium Severity
  • SRG-APP-000251-WSR-000157

    Group
  • SRG-APP-000266-WSR-000142

    Group
  • The Security Token Service must set the welcome-file node to a default web page.

    Enumeration techniques, such as Uniform Resource Locator (URL) parameter manipulation, rely on being able to obtain information about the web server's directory structure by locating directories wi...
    Rule Medium Severity
  • SRG-APP-000266-WSR-000142

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules