Performance Charts must disable the shutdown port.
An XCCDF Rule
Description
An attacker has at least two reasons to stop a web server. The first is to cause a denial of service, and the second is to put in place changes the attacker made to the web server configuration. If the Tomcat shutdown port feature is enabled, a shutdown signal can be sent to Performance Charts through this port. To ensure availability, the shutdown port must be disabled.
- ID
- SV-256642r888417_rule
- Version
- VCPF-70-000032
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Navigate to and open:
/etc/vmware-eam/catalina.properties
Navigate to the ports specification section.