SV-223007r615938_rule
V-223007
SRG-APP-000516-AS-000237
TCAT-AS-001710
CAT III
10
Document the applications that have an ATO on the Tomcat server.
Retain the information in the SSP and present to the auditor in the event of a CCRI.
Review the Tomcat servers System Security Plan/server documentation.
Access the Tomcat server and review the $CATALINA_BASE/webapps folder.
Ensure that all webapps are documented in the SSP.
If the applications that are hosted on the Tomcat server are not documented in the SSP, this is a finding.
V-223007
False
TCAT-AS-001710
Review the Tomcat servers System Security Plan/server documentation.
Access the Tomcat server and review the $CATALINA_BASE/webapps folder.
Ensure that all webapps are documented in the SSP.
If the applications that are hosted on the Tomcat server are not documented in the SSP, this is a finding.
M
4094