The Security Token Service application files must be verified for their integrity.
DISA Rule
SV-239659r679049_rule
Vulnerability Number
V-239659
Group Title
SRG-APP-000131-WSR-000051
Rule Version
VCST-67-000008
Severity
CAT II
CCI(s)
- CCI-001749 - The information system prevents the installation of organization-defined software components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
- CCI-001849 - The organization allocates audit record storage capacity in accordance with organization-defined audit record storage requirements.
Weight
10
Fix Recommendation
Reinstall the VCSA or roll back to a snapshot.
Modifying the Security Token Service installation files manually is not supported by VMware.
Check Contents
At the command prompt, execute the following command:
# rpm -V vmware-identity-sts|grep "^..5......"|grep -E "\.war|\.jar|\.sh|\.py"
If there is any output, this is a finding.
Vulnerability Number
V-239659
Documentable
False
Rule Version
VCST-67-000008
Severity Override Guidance
At the command prompt, execute the following command:
# rpm -V vmware-identity-sts|grep "^..5......"|grep -E "\.war|\.jar|\.sh|\.py"
If there is any output, this is a finding.
Check Content Reference
M
Target Key
5333
Comments