Apache Tomcat Application Server 9 Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-APP-000033-AS-000024
<GroupDescription></GroupDescription>Group -
The Java Security Manager must be enabled.
<VulnDiscussion>The Java Security Manager (JSM) is what protects the Tomcat server from trojan servlets, JSPs, JSP beans, tag libraries, or e...Rule Medium Severity -
SRG-APP-000089-AS-000050
<GroupDescription></GroupDescription>Group -
Tomcat servers behind a proxy or load balancer must log client IP.
<VulnDiscussion>When running Tomcat behind a load balancer or proxy, default behavior is for Tomcat to log the proxy or load balancer IP addr...Rule Medium Severity -
SRG-APP-000090-AS-000051
<GroupDescription></GroupDescription>Group -
AccessLogValve must be configured per each virtual host.
<VulnDiscussion>Application servers utilize role-based access controls in order to specify the individuals who are allowed to configure appli...Rule Medium Severity -
SRG-APP-000096-AS-000059
<GroupDescription></GroupDescription>Group -
Date and time of events must be logged.
<VulnDiscussion>The access logfile format is defined within a Valve that implements the org.apache.catalina.valves.AccessLogValve interface w...Rule Medium Severity -
SRG-APP-000097-AS-000060
<GroupDescription></GroupDescription>Group -
Remote hostname must be logged.
<VulnDiscussion>The access logfile format is defined within a Valve that implements the org.apache.catalina.valves.AccessLogValve interface w...Rule Medium Severity -
SRG-APP-000097-AS-000060
<GroupDescription></GroupDescription>Group -
HTTP status code must be logged.
<VulnDiscussion>The access logfile format is defined within a Valve that implements the org.apache.catalina.valves.AccessLogValve interface w...Rule Low Severity -
SRG-APP-000097-AS-000060
<GroupDescription></GroupDescription>Group -
The first line of request must be logged.
<VulnDiscussion>The access logfile format is defined within a Valve that implements the org.apache.catalina.valves.AccessLogValve interface w...Rule Medium Severity -
SRG-APP-000118-AS-000078
<GroupDescription></GroupDescription>Group -
$CATALINA_BASE/logs folder permissions must be set to 750.
<VulnDiscussion>Tomcat file permissions must be restricted. The standard configuration is to have all Tomcat files owned by root with group T...Rule Medium Severity -
SRG-APP-000118-AS-000078
<GroupDescription></GroupDescription>Group -
Files in the $CATALINA_BASE/logs/ folder must have their permissions set to 640.
<VulnDiscussion>Tomcat file permissions must be restricted. The standard configuration is to have all Tomcat files owned by root with group T...Rule Medium Severity -
SRG-APP-000119-AS-000079
<GroupDescription></GroupDescription>Group -
Files in the $CATALINA_BASE/conf/ folder must have their permissions set to 640.
<VulnDiscussion>Tomcat file permissions must be restricted. The standard configuration is to have all Tomcat files owned by root with group T...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.