SV-223006r615938_rule
V-223006
SRG-APP-000516-AS-000237
TCAT-AS-001700
CAT II
10
Document the users and the roles that have been defined for use with the Tomcat server.
Ensure that all users and roles with access to Tomcat management features and capabilities are approved by the ISSO.
Review the Tomcat servers System Security Plan/server documentation.
Ensure that user accounts and roles with access to Tomcat management features such as the "manager-script" role are documented and approved by the ISSO.
If the ISSO has not approved of documented roles and users who have management rights to the Tomcat server, this is a finding.
V-223006
False
TCAT-AS-001700
Review the Tomcat servers System Security Plan/server documentation.
Ensure that user accounts and roles with access to Tomcat management features such as the "manager-script" role are documented and approved by the ISSO.
If the ISSO has not approved of documented roles and users who have management rights to the Tomcat server, this is a finding.
M
4094