STIGQter STIGQter: STIG Summary: VMware vSphere 6.7 UI Tomcat Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 09 Mar 2021:

vSphere UI must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the web server.

DISA Rule

SV-239707r679227_rule

Vulnerability Number

V-239707

Group Title

SRG-APP-000357-WSR-000150

Rule Version

VCUI-67-000026

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Reinstall the VCSA or roll back to a snapshot.

Modifying the vSphere UI installation files manually is not supported by VMware.

Check Contents

At the command prompt, execute the following command:

# rpm -V vsphere-ui|grep serviceability.xml|grep "^..5......"

If the above command returns any output, this is a finding.

Vulnerability Number

V-239707

Documentable

False

Rule Version

VCUI-67-000026

Severity Override Guidance

At the command prompt, execute the following command:

# rpm -V vsphere-ui|grep serviceability.xml|grep "^..5......"

If the above command returns any output, this is a finding.

Check Content Reference

M

Target Key

5334

Comments