Skip to content

Any unapproved applications must be removed.

An XCCDF Rule

Description

Extraneous services and applications running on an application server expands the attack surface and increases risk to the application server. Securing any server involves identifying and removing any unnecessary services and, in the case of an application server, unnecessary and/or unapproved applications.

ID
SV-213524r960963_rule
Version
JBOS-AS-000250
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Identify, authorize, and document all applications that are deployed to the application server.  Remove unauthorized applications.