Skip to content

Lookup Service must disable the shutdown port.

An XCCDF Rule

Description

An attacker has at least two reasons to stop a web server. The first is to cause a denial of service, and the second is to put in place changes the attacker made to the web server configuration. If the Tomcat shutdown port feature is enabled, a shutdown signal can be sent to the Lookup Service through this port. To ensure availability, the shutdown port must be disabled.

ID
SV-256735r888796_rule
Version
VCLU-70-000030
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Navigate to and open:

/usr/lib/vmware-lookupsvc/conf/server.xml

Ensure the server port is set as follows: