STIGQter STIGQter: STIG Summary: JBoss Enterprise Application Platform 6.3 Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

mgmt-users.properties file permissions must be set to allow access to authorized users only.

DISA Rule

SV-213517r615939_rule

Vulnerability Number

V-213517

Group Title

SRG-APP-000133-AS-000092

Rule Version

JBOS-AS-000210

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the file permissions to allow access to authorized users only.
Owner can be full access.
Group can be full access.
All others must have execute permissions only.

Check Contents

The mgmt-users.properties files are located in the standalone or domain configuration folder.

<JBOSS_HOME>/domain/configuration/mgmt-users.properties.
<JBOSS_HOME>/standalone/configuration/mgmt-users.properties.

Identify users who have access to the files using relevant OS commands.

Obtain documentation from system admin identifying authorized users.

Owner can be full access.
Group can be full access.
All others must have execute permissions only.

If the file permissions are not configured so as to restrict access to only authorized users, or if documentation that identifies authorized users is missing, this is a finding.

Vulnerability Number

V-213517

Documentable

False

Rule Version

JBOS-AS-000210

Severity Override Guidance

The mgmt-users.properties files are located in the standalone or domain configuration folder.

<JBOSS_HOME>/domain/configuration/mgmt-users.properties.
<JBOSS_HOME>/standalone/configuration/mgmt-users.properties.

Identify users who have access to the files using relevant OS commands.

Obtain documentation from system admin identifying authorized users.

Owner can be full access.
Group can be full access.
All others must have execute permissions only.

If the file permissions are not configured so as to restrict access to only authorized users, or if documentation that identifies authorized users is missing, this is a finding.

Check Content Reference

M

Target Key

3987

Comments