The Security Token Service must disable the shutdown port.
An XCCDF Rule
Description
An attacker has at least two reasons to stop a web server. The first is to cause a denial of service, and the second is to put in place changes the attacker made to the web server configuration. If the Tomcat shutdown port feature is enabled, a shutdown signal can be sent to the Security Token Service through this port. To ensure availability, the shutdown port must be disabled.
- ID
- SV-256772r889286_rule
- Version
- VCST-70-000029
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Navigate to and open:
/usr/lib/vmware-sso/vmware-sts/conf/catalina.properties
Add or modify the following setting: