Skip to content

Oracle WebLogic must prohibit or restrict the use of unauthorized functions, ports, protocols, and/or services.

An XCCDF Rule

Description

<VulnDiscussion>Application servers provide numerous processes, features, and functionalities that utilize TCP/IP ports. Some of these processes may be deemed to be unnecessary or too insecure to run on a production system. The application server must provide the capability to disable or deactivate network-related services that are deemed to be non-essential to the server mission, for example, disabling a protocol or feature that opens a listening port that is prohibited by DoD ports and protocols. For a list of approved ports and protocols reference the DoD ports and protocols web site at https://cyber.mil/ppsm.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-235962r672376_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

1. Access AC
2. To change port or protocol values, from 'Domain Structure', select 'Environment' -> 'Servers' 
3. From the list of servers, select one which needs modification
4. Utilize 'Change Center' to create a new change session 
5. To modify port assignment, from 'Configuration' tab -> 'General' tab, reassign the port for this server by changing the 'SSL Listen Port' field and click 'Save'
6. To modify protocol configuration, select 'Protocols' tab