Skip to content

VMware vSphere 8.0 vCenter Appliance Lookup Service Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • The vCenter Lookup service must produce log records containing sufficient information regarding event details.

    Remote access can be exploited by an attacker to compromise the server. By recording all remote access activities, it will be possible to determine the attacker's location, intent, and degree of su...
    Rule Medium Severity
  • The vCenter Lookup service logs folder permissions must be set correctly.

    Log data is essential in the investigation of events. The accuracy of the information is always pertinent. One of the first steps an attacker will take is the modification or deletion of log record...
    Rule Medium Severity
  • The vCenter Lookup service must limit privileges for creating or modifying hosted application shared files.

    Application servers have the ability to specify that the hosted applications use shared libraries. The application server must have a capability to divide roles based upon duties wherein one projec...
    Rule Medium Severity
  • The vCenter Lookup service must set URIEncoding to UTF-8.

    Invalid user input occurs when a user inserts data or characters into a hosted application's data entry field and the hosted application is unprepared to process that data. This results in unantici...
    Rule Medium Severity
  • The vCenter Lookup service must enable "STRICT_SERVLET_COMPLIANCE".

    Strict Servlet Compliance forces Tomcat to adhere to standards specifications including but not limited to RFC2109. RFC2109 sets the standard for HTTP session management. This setting affects sever...
    Rule Medium Severity
  • The vCenter Lookup service must limit the number of times that each Transmission Control Protocol (TCP) connection is kept alive.

    KeepAlive provides long lived HTTP sessions that allow multiple requests to be sent over the same connection. Enabling KeepAlive mitigates the effects of several types of denial-of-service attacks....
    Rule Medium Severity
  • The vCenter Lookup service DefaultServlet must be set to "readonly" for "PUT" and "DELETE" commands.

    The default servlet (or DefaultServlet) is a special servlet provided with Tomcat that is called when no other suitable page is found in a particular folder. The DefaultServlet serves static resour...
    Rule Medium Severity
  • The vCenter Lookup service debug parameter must be disabled.

    Information needed by an attacker to begin looking for possible vulnerabilities in a web server includes any information about the web server and plug-ins or modules being used. When debugging or t...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules