Skip to content

JBoss application and management ports must be approved by the PPSM CAL.

An XCCDF Rule

Description

<VulnDiscussion>Some networking protocols may not meet organizational security requirements to protect data and components. Application servers natively host a number of various features, such as management interfaces, httpd servers and message queues. These features all run on TCPIP ports. This creates the potential that the vendor may choose to utilize port numbers or network services that have been deemed unusable by the organization. The application server must have the capability to both reconfigure and disable the assigned ports without adversely impacting application server operation capabilities. For a list of approved ports and protocols, reference the DoD ports and protocols website at https://powhatan.iiie.disa.mil/ports/cal.html.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-213525r615939_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

Open the EAP web console by pointing a web browser to HTTPS://<Servername>:9990

Log on to the admin console using admin credentials
Select the "Configuration" tab
Expand the "General Configuration" sub system by clicking on the +
Select "Socket Binding"