The Mainframe Product must prevent the automatic execution of mobile code in, at a minimum, office applications, browsers, email clients, mobile code run-time environments, and mobile agent systems.
An XCCDF Rule
Description
<VulnDiscussion>Mobile code can cause damage to the system. It can execute without explicit action from, or notification to, a user. Preventing automatic execution of mobile code includes, for example, disabling auto execute features on information system components. This requirement applies to mobile code-enabled software, which is capable of executing one or more types of mobile code.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-205516r961092_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Configure the Mainframe Product to prevent the automatic execution of mobile code in all applications.