STIGQter STIGQter: STIG Summary: VMware vSphere 6.7 vCenter Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 09 Mar 2021:

The vCenter Server must enable all tasks to be shown to Administrators in the Web Client.

DISA Rule

SV-243093r719522_rule

Vulnerability Number

V-243093

Group Title

SRG-APP-000516

Rule Version

VCTR-67-000029

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Navigate to and open /etc/vmware/vsphere-client/webclient.properties. Remove any existing "show.allusers.tasks" line and add the following:

show.allusers.tasks = true

Check Contents

Note: For vCenter Server Windows, this is not applicable.

On the vCenter Server, execute the following command:

# grep "^show\.allusers\.tasks" /etc/vmware/vsphere-client/webclient.properties

Expected result:

show.allusers.tasks = true

If the output does not match the expected result, this is a finding.

Vulnerability Number

V-243093

Documentable

False

Rule Version

VCTR-67-000029

Severity Override Guidance

Note: For vCenter Server Windows, this is not applicable.

On the vCenter Server, execute the following command:

# grep "^show\.allusers\.tasks" /etc/vmware/vsphere-client/webclient.properties

Expected result:

show.allusers.tasks = true

If the output does not match the expected result, this is a finding.

Check Content Reference

M

Target Key

5399

Comments