Skip to content

Apache Tomcat Application Server 9 Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000267-AS-000170

    <GroupDescription></GroupDescription>
    Group
  • ErrorReportValve showReport must be set to false.

    &lt;VulnDiscussion&gt;The Error Report Valve is a simple error handler for HTTP status codes that will generate and return HTML error pages. It can...
    Rule Medium Severity
  • SRG-APP-000295-AS-000263

    <GroupDescription></GroupDescription>
    Group
  • Idle timeout for management application must be set to 10 minutes.

    &lt;VulnDiscussion&gt;Tomcat can set idle session timeouts on a per application basis. The management application is provided with the Tomcat insta...
    Rule Medium Severity
  • SRG-APP-000315-AS-000094

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules