Skip to content

Apache Tomcat Application Server 9 Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000033-AS-000024

    <GroupDescription></GroupDescription>
    Group
  • The Java Security Manager must be enabled.

    &lt;VulnDiscussion&gt;The Java Security Manager (JSM) is what protects the Tomcat server from trojan servlets, JSPs, JSP beans, tag libraries, or e...
    Rule Medium Severity
  • SRG-APP-000089-AS-000050

    <GroupDescription></GroupDescription>
    Group
  • Tomcat servers behind a proxy or load balancer must log client IP.

    &lt;VulnDiscussion&gt;When running Tomcat behind a load balancer or proxy, default behavior is for Tomcat to log the proxy or load balancer IP addr...
    Rule Medium Severity
  • SRG-APP-000090-AS-000051

    <GroupDescription></GroupDescription>
    Group
  • AccessLogValve must be configured per each virtual host.

    &lt;VulnDiscussion&gt;Application servers utilize role-based access controls in order to specify the individuals who are allowed to configure appli...
    Rule Medium Severity
  • SRG-APP-000096-AS-000059

    <GroupDescription></GroupDescription>
    Group
  • Date and time of events must be logged.

    &lt;VulnDiscussion&gt;The access logfile format is defined within a Valve that implements the org.apache.catalina.valves.AccessLogValve interface w...
    Rule Medium Severity
  • SRG-APP-000097-AS-000060

    <GroupDescription></GroupDescription>
    Group
  • Remote hostname must be logged.

    &lt;VulnDiscussion&gt;The access logfile format is defined within a Valve that implements the org.apache.catalina.valves.AccessLogValve interface w...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules