SV-239664r679064_rule
V-239664
SRG-APP-000141-WSR-000083
VCST-67-000013
CAT II
10
Navigate to and open /usr/lib/vmware-sso/vmware-sts/conf/web.xml.
Inside the <web-app> parent node, add the following:
<servlet-mapping>
<servlet-name>jsp</servlet-name>
<url-pattern>*.jsp</url-pattern>
<url-pattern>*.jspx</url-pattern>
</servlet-mapping>
At the command prompt, execute the following command:
# xmllint --format /usr/lib/vmware-sso/vmware-sts/conf/web.xml | sed '2 s/xmlns=".*"//g' | xmllint --xpath '/web-app/servlet-mapping/servlet-name[text()="jsp"]/parent::servlet-mapping' -
Expected result:
<servlet-mapping>
<servlet-name>jsp</servlet-name>
<url-pattern>*.jsp</url-pattern>
<url-pattern>*.jspx</url-pattern>
</servlet-mapping>
If the output of the command does not match the expected result, this is a finding.
V-239664
False
VCST-67-000013
At the command prompt, execute the following command:
# xmllint --format /usr/lib/vmware-sso/vmware-sts/conf/web.xml | sed '2 s/xmlns=".*"//g' | xmllint --xpath '/web-app/servlet-mapping/servlet-name[text()="jsp"]/parent::servlet-mapping' -
Expected result:
<servlet-mapping>
<servlet-name>jsp</servlet-name>
<url-pattern>*.jsp</url-pattern>
<url-pattern>*.jspx</url-pattern>
</servlet-mapping>
If the output of the command does not match the expected result, this is a finding.
M
5333