STIGQter STIGQter: STIG Summary: VMware vRealize Automation 7.x tc Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

tc Server VCAC must not use the tomcat-users XML database for user management.

DISA Rule

SV-100655r1_rule

Vulnerability Number

V-90005

Group Title

SRG-APP-000141-WSR-000015

Rule Version

VRAU-TC-000330

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Contact the ISSO and/or SA.

Determine why user data is being stored in "tomcat-users.xml".

If the user data is not required then it should be removed.

The vRA appliance does not maintain user data in this file by default.

Check Contents

At the command prompt, execute the following command:

cat /etc/vcac/tomcat-users.xml

If "tomcat-users.xml" file contains any user information, this is a finding.

Vulnerability Number

V-90005

Documentable

False

Rule Version

VRAU-TC-000330

Severity Override Guidance

At the command prompt, execute the following command:

cat /etc/vcac/tomcat-users.xml

If "tomcat-users.xml" file contains any user information, this is a finding.

Check Content Reference

M

Target Key

3439

Comments