SV-223002r615938_rule
V-223002
SRG-APP-000516-AS-000237
TCAT-AS-001660
CAT III
10
From the Tomcat server as a privileged user:
Edit the /etc/systemd/system/tomcat.service file and either add or edit the org.apache.catalina.STRICT_SERVLET_COMPLIANCE setting.
Set the org.apache.catalina.STRICT_SERVLET_COMPLIANCE=true
EXAMPLE:
CATALINA_OPTS='-Dorg.apache.catalina.STRICT_SERVLET_COMPLIANCE=true'
Restart the Tomcat server:
sudo systemctl restart tomcat
sudo systemctl daemon-reload
If the system has an ISSM risk acceptance for operational issues that arise due to this setting, this is not a finding.
From the Tomcat server as a privileged user, run the following command:
sudo grep -i strict_servlet /etc/systemd/system/tomcat.service
If there are no results, or if the
-Dorg.apache.catalina.STRICT_SERVLET_COMPLIANCE is not set to true, this is a finding.
V-223002
False
TCAT-AS-001660
If the system has an ISSM risk acceptance for operational issues that arise due to this setting, this is not a finding.
From the Tomcat server as a privileged user, run the following command:
sudo grep -i strict_servlet /etc/systemd/system/tomcat.service
If there are no results, or if the
-Dorg.apache.catalina.STRICT_SERVLET_COMPLIANCE is not set to true, this is a finding.
M
4094