SV-239384r674646_rule
V-239384
SRG-APP-000141-WSR-000083
VCEM-67-000013
CAT II
10
Navigate to and open:
/usr/lib/vmware-eam/web/webapps/eam/WEB-INF/web.xml
Navigate to and locate the mapping for the JSP servlet. The <servlet-mapping> node contains <servlet-name>JspServlet</servlet-name>.
Configure the <servlet-mapping> node to look like the code snippet below:
<servlet-mapping>
<servlet-name>JspServlet</servlet-name>
<url-pattern>*.jsp</url-pattern>
</servlet-mapping>
At the command prompt, execute the following command:
# xmllint --format /usr/lib/vmware-eam/web/webapps/eam/WEB-INF/web.xml | sed 's/xmlns=".*"//g' | xmllint --xpath '/web-app/servlet-mapping/servlet-name[text()="JspServlet"]/parent::servlet-mapping' -
Expected result:
<servlet-mapping>
<servlet-name>JspServlet</servlet-name>
<url-pattern>*.jsp</url-pattern>
</servlet-mapping>
If the output of the command does not match the expected result, this is a finding.
V-239384
False
VCEM-67-000013
At the command prompt, execute the following command:
# xmllint --format /usr/lib/vmware-eam/web/webapps/eam/WEB-INF/web.xml | sed 's/xmlns=".*"//g' | xmllint --xpath '/web-app/servlet-mapping/servlet-name[text()="JspServlet"]/parent::servlet-mapping' -
Expected result:
<servlet-mapping>
<servlet-name>JspServlet</servlet-name>
<url-pattern>*.jsp</url-pattern>
</servlet-mapping>
If the output of the command does not match the expected result, this is a finding.
M
5328