Skip to content

The vCenter Lookup service must enable "ENFORCE_ENCODING_IN_GET_WRITER".

An XCCDF Rule

Description

Some clients try to guess the character encoding of text media when the mandated default of ISO-8859-1 should be used. Some browsers will interpret as UTF-7 when the characters are safe for ISO-8859-1. This can create the potential for a XSS attack. To defend against this, enforce_encoding_in_get_writer must be set to true.

ID
SV-259068r934862_rule
Version
VCLU-80-000152
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Navigate to and open:

/usr/lib/vmware-lookupsvc/conf/catalina.properties

Update or remove the following line: