SV-239685r679161_rule
V-239685
SRG-APP-000001-WSR-000002
VCUI-67-000004
CAT II
10
Navigate to and open /usr/lib/vmware-vsphere-ui/server/conf/context.xml.
Add the following configuration to the <Context> node:
useHttpOnly="true"
Example:
<Context useHttpOnly="true" sessionCookieName="VSPHERE-UI-JSESSIONID" sessionCookiePath="/ui">
At the command prompt, execute the following command:
# xmllint --format /usr/lib/vmware-vsphere-ui/server/conf/context.xml | xmllint --xpath '/Context/@useHttpOnly' -
Expected result:
useHttpOnly="true"
If the output does not match the expected result, this is a finding.
V-239685
False
VCUI-67-000004
At the command prompt, execute the following command:
# xmllint --format /usr/lib/vmware-vsphere-ui/server/conf/context.xml | xmllint --xpath '/Context/@useHttpOnly' -
Expected result:
useHttpOnly="true"
If the output does not match the expected result, this is a finding.
M
5334